Staff Security Engineer – Threat Detection

Posted 45ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Staff Security Engineer building AI-powered threat detections and response workflows at Snowflake, a cloud data platform. Improving detection coverage, automation, and security analytics at global scale.

Responsibilities:

  • Develop and deploy rules-based and AI-assisted threat detections using testing, validation, CI/CD pipelines, detections-as-code, and a full detection development lifecycle
  • Analyze threat-detection coverage gaps and mitigate risks through detective controls
  • Experiment with AI/ML approaches to improve signal-to-noise ratio and analyst efficiency
  • Make data-driven recommendations for detective and preventative controls based on threat models, proactive threat hunts, and exploration of logs and telemetry
  • Design and build automations and AI-driven workflows to strengthen security posture and reduce mean time to detect and respond
  • Build stakeholder partnerships to deliver detection as a service, including self-service patterns, reusable components, and AI-enhanced detections
  • Measure and improve detection quality across coverage, precision and recall, false positive rate, and latency

Requirements:

  • 8+ years of security engineering experience across threat detection, incident response, threat hunting, product security, or corporate security, or equivalent experience
  • Strong coding ability in Python or Go, with experience building software, data tooling, or automations
  • Experience applying coding skills to AI/ML-powered detection and response
  • Programmatic data handling using SQL and Python, ideally with large-scale log and telemetry datasets
  • Production coding experience, including unit tests, version control, and CI/CD integration
  • Experience developing and operating agent-based or agentic workflows, such as LangGraph or similar orchestration frameworks
  • Hands-on experience with AWS, Azure, or GCP and understanding of native logging, monitoring, and security services
  • Familiarity with SaaS and workstation risks including account compromise, data exfiltration, phishing, and supply chain attacks
  • Risk-based approach to prioritizing security initiatives and evaluating AI versus traditional rules and heuristics
  • Computer Science degree or equivalent practical experience is listed as a bonus
  • Bonus experience with GenAI and LLM-based security workflows
  • Bonus experience with Terraform, CloudFormation, or detections-as-code frameworks
  • Bonus experience building production platforms processing high-volume logs, metrics, or traces
  • Bonus experience deploying detections at global scale
  • Bonus experience with Snowflake or equivalent cloud data platforms and security analytics pipelines