See all roles

Threat Hunting & Detection Engineer (US Federal)

Work from home Full-time role Hiring

About the position This role will support one or more direct or indirect contracts with the U.S. Federal Government which, due to federal government security requirements, mandates that all Workday personnel working on the contracts be United States citizens (naturalized or native). Workday’s Cyber Defense Directorate protects enterprise and U.S. Government SaaS environments operating under multiple authorization boundaries, including air-gapped regions (AGR). Our Cyber Defense capability provides advanced monitoring, detection, threat hunting, and response across regulated cloud environments supporting federal customers. We operate in partnership with SOC, Red Team, Blue Team, Purple Team, and Threat Intelligence to ensure continuous validation of detection coverage and operational readiness. The Detection Engineering and Threat Hunting function is foundational to maintaining compliance, reducing adversary dwell time, and ensuring resilient security posture across high-security SaaS environments. The Threat Hunting & Detection Engineer is responsible for engineering, validating, and continuously improving detection capabilities across FedRAMP High and IL5 cloud-native SaaS environments, including air-gapped regions. This role develops high-fidelity detection logic leveraging: Splunk (correlation searches, data models, CIM alignment, SPL optimization) Cloud-native telemetry (AWS CloudTrail, GuardDuty, Inspector, VPC Flow Logs, SaaS application logs) Identity and access telemetry Endpoint and container telemetry Vulnerability intelligence sources You will translate adversary behaviors into actionable detection analytics aligned to MITRE ATT&CK and NIST SP 800-61r3 incident response lifecycle principles. You will support continuous monitoring requirements under FedRAMP and DoD IL5 frameworks, ensuring detection content aligns to compliance mandates, audit traceability, and evidentiary standards. In air-gapped environments, you will design detection strategies that account for: Limited telemetry pathways Constrained automation capabilities Reduced external enrichment access Secure data transfer controls You will collaborate closely with: SOC Analysts to improve alert quality and reduce false positives Security Engineers to ensure log integrity and coverage Red/Purple Teams to validate detection effectiveness Threat Intelligence to operationalize adversary reporting Compliance stakeholders to support audit and continuous monitoring requirements As the program matures, this role will help define detection engineering standards, lifecycle governance, and detection coverage metrics across the Cyber Defense Directorate.

Responsibilities

  • Engineering, validating, and continuously improving detection capabilities across FedRAMP High and IL5 cloud-native SaaS environments, including air-gapped regions.
  • Develop high-fidelity detection logic leveraging: Splunk (correlation searches, data models, CIM alignment, SPL optimization) Cloud-native telemetry (AWS CloudTrail, GuardDuty, Inspector, VPC Flow Logs, SaaS application logs) Identity and access telemetry Endpoint and container telemetry Vulnerability intelligence sources
  • Translate adversary behaviors into actionable detection analytics aligned to MITRE ATT&CK and NIST SP 800-61r3 incident response lifecycle principles.
  • Support continuous monitoring requirements under FedRAMP and DoD IL5 frameworks, ensuring detection content aligns to compliance mandates, audit traceability, and evidentiary standards.
  • Design detection strategies that account for: Limited telemetry pathways Constrained automation capabilities Reduced external enrichment access Secure data transfer controls
  • Collaborate closely with: SOC Analysts to improve alert quality and reduce false positives Security Engineers to ensure log integrity and coverage Red/Purple Teams to validate detection effectiveness Threat Intelligence to operationalize adversary reporting Compliance stakeholders to support audit and continuous monitoring requirements
  • Help define detection engineering standards, lifecycle governance, and detection coverage metrics across the Cyber Defense Directorate.

Requirements

  • 6+ years of experience in cybersecurity operations, detection engineering, or threat hunting
  • Hands-on experience building detections in Splunk, including correlation searches and SPL development
  • Experience operating in FedRAMP, DoD IL4/IL5, or similarly regulated cloud environments
  • Experience working with AWS security services (CloudTrail, GuardDuty, Inspector, VPC Flow Logs)
  • Strong understanding of MITRE ATT&CK mapping and adversary tradecraft
  • Familiarity with NIST SP 800-61r3 incident response lifecycle
  • Bachelor’s degree in Cybersecurity, Computer Science, Engineering, or equivalent experience
  • Applicants must have the ability to obtain and maintain a U.S. government issued security clearance. An active TS/SCI w/CI Poly is preferred
  • You understand the intersection of detection engineering, cloud security, and regulatory frameworks.
  • You can balance operational effectiveness with compliance rigor.
  • You are comfortable operating in high-assurance, controlled, and sometimes disconnected environments where precision and auditability matter.

Nice-to-haves

  • Experience conducting hypothesis-driven threat hunting within SaaS and cloud-native architectures
  • Strong understanding of identity-based attack vectors (IAM abuse, token theft, federation misuse)
  • Experience detecting container and workload-level attacks
  • Familiarity with secure logging architectures in air-gapped environments
  • Experience leveraging SOAR platforms (e.g., Tines) within constrained or controlled automation boundaries

Apply tot his job Apply To this Job

You might like

Hearing Officer (Remote) -- Temporary

Work from home Full-time role

Accounting Assistant - Temporary

Work from home Full-time role

Document Control Analyst - Temporary

Work from home Full-time role

Stocker, Retail

Work from home Full-time role

Merchandiser​/Cashier

Work from home Full-time role

Part-Time Tjmaxx Merchandise Associate

Work from home Full-time role

Staff Program Manager - Development Ecosystem

Work from home Full-time role

Postdoctoral Research Scientist, Investigative Toxicology

Work from home Full-time role

[Hiring] Drug Discovery Scientists & Toxicology Experts @24-MAG

Work from home Full-time role

Director, Project Toxicologist, BioPharma Safety in Clinical Pharmacology & Safety Sciences (CPSS)

Work from home Full-time role

Software Engineer (Remote)

Work from home Full-time role

Experienced Data Entry Assistant / Typing Professional – Remote Opportunity at arenaflex

Work from home Full-time role

Bilingual Customer Care Advocate

Work from home Full-time role

Sr Investigator - Trade Compliance/Anti Money Laundering

Work from home Full-time role

[Remote] Mortgage Loan Officer - Remote

Work from home Full-time role

Experienced Customer Service Representative – Delivering Exceptional Experiences from Home

Work from home Full-time role

Sr. Recruiter - Remote in US

Work from home Full-time role

Experienced Part-Time Remote Data Entry Clerk – Join blithequark's Dynamic Team and Thrive in a Flexible Work Environment

Work from home Full-time role

Experienced Data Entry Specialist – Remote Opportunity with blithequark

Work from home Full-time role

Urgently Hiring: Virtual Assistant

Work from home Full-time role