Staff Security Engineer – Threat Detection
Posted 45ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Staff Security Engineer building AI-powered threat detections and response workflows at Snowflake, a cloud data platform. Improving detection coverage, automation, and security analytics at global scale.
Responsibilities:
- Develop and deploy rules-based and AI-assisted threat detections using testing, validation, CI/CD pipelines, detections-as-code, and a full detection development lifecycle
- Analyze threat-detection coverage gaps and mitigate risks through detective controls
- Experiment with AI/ML approaches to improve signal-to-noise ratio and analyst efficiency
- Make data-driven recommendations for detective and preventative controls based on threat models, proactive threat hunts, and exploration of logs and telemetry
- Design and build automations and AI-driven workflows to strengthen security posture and reduce mean time to detect and respond
- Build stakeholder partnerships to deliver detection as a service, including self-service patterns, reusable components, and AI-enhanced detections
- Measure and improve detection quality across coverage, precision and recall, false positive rate, and latency
Requirements:
- 8+ years of security engineering experience across threat detection, incident response, threat hunting, product security, or corporate security, or equivalent experience
- Strong coding ability in Python or Go, with experience building software, data tooling, or automations
- Experience applying coding skills to AI/ML-powered detection and response
- Programmatic data handling using SQL and Python, ideally with large-scale log and telemetry datasets
- Production coding experience, including unit tests, version control, and CI/CD integration
- Experience developing and operating agent-based or agentic workflows, such as LangGraph or similar orchestration frameworks
- Hands-on experience with AWS, Azure, or GCP and understanding of native logging, monitoring, and security services
- Familiarity with SaaS and workstation risks including account compromise, data exfiltration, phishing, and supply chain attacks
- Risk-based approach to prioritizing security initiatives and evaluating AI versus traditional rules and heuristics
- Computer Science degree or equivalent practical experience is listed as a bonus
- Bonus experience with GenAI and LLM-based security workflows
- Bonus experience with Terraform, CloudFormation, or detections-as-code frameworks
- Bonus experience building production platforms processing high-volume logs, metrics, or traces
- Bonus experience deploying detections at global scale
- Bonus experience with Snowflake or equivalent cloud data platforms and security analytics pipelines



















