We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.
Position Summary
The Staff Threat Detection Engineer plays a key role in helping the organization stay ahead of evolving cyber threats. This position combines threat hunting, detection engineering, and offensive security expertise to identify suspicious activity, uncover emerging risks, and strengthen the organization's overall security posture. By leveraging security telemetry, threat intelligence, and adversary-focused analysis, this role helps ensure threats are identified and addressed before they can impact the business.
Working closely with Security Operations, Incident Response, and other cybersecurity teams, this role develops and improves detections, supports investigations, and helps validate security controls through purple team exercises and adversary emulation activities. The position also contributes to the adoption of new tools, techniques, and automation capabilities that improve visibility and response effectiveness. Success in this role requires curiosity, strong analytical skills, and a passion for continuously improving how the organization detects and defends against cyber threats.
Role Responsibilities:
Detection Engineering & Threat Hunting
- Develop, deploy, and optimize detection rules across SIEM platforms such as Microsoft Sentinel and Splunk
- Conduct threat hunting activities using Microsoft Defender, CrowdStrike, and other SOC tools to identify and respond to advanced threats.
- Leverage KQL and SPL (Search Processing Language) to create custom detections and automate responses.
- Continuously refine detection capabilities based on emerging threats and intelligence.
Penetration Testing & Adversary Emulation
- Assist with internal and external penetration tests to identify vulnerabilities.
- Design and execute adversary emulation scenarios to assess detection and response effectiveness.
- Utilize penetration testing tools and custom scripts to simulate real-world attack scenarios.
- Produce detailed reports with findings and actionable recommendations.
Purple Team Operations
- Work closely with blue teams to conduct purple team exercises, bridging offensive and defensive security efforts.
- Provide actionable insights to improve monitoring, alerting, and incident response based on adversary tactics.
- Facilitate knowledge-sharing sessions to upskill internal teams on TTPs (Tactics, Techniques, and Procedures).
Threat Intelligence Integration
- Integrate threat intelligence into detection strategies to prioritize threats and adapt detection rules.
- Analyze threat intelligence feeds and translate them into actionable detection and response measures.
Incident Response Support
- Collaborate with the incident response team during investigations by providing adversary tactics insights.
- Assist in developing threat-hunting use cases and refining detection capabilities.
Security Strategy & Risk Management
- Contribute to the development of a comprehensive detection strategy aligned with risk management goals.
- Provide leadership with reports on security gaps, risks, and detection effectiveness.
Required Qualifications
- 7+ years of experience in threat detection, hunting, penetration testing, and/or offensive security.
- 5+ years of experience in Microsoft Security tools (Defender for Endpoint, Sentinel), CrowdStrike, and Splunk.
- 3+ years of experience with KQL, SPL, Python, PowerShell, or Bash scripting for automation and detection logic.
Preferred Qualifications
- Relevant certifications such as OSCP, GCIH, GCIA, CISSP, CEH, or Microsoft Azure Certification.
- Experience in managing or participating in purple team exercises.
- Familiarity with compliance standards like PCI-DSS, HIPAA, or ISO 27001.
- Strong understanding of the MITRE ATT&CK framework and security standards (NIST, CIS).
- Strong communication skills to convey complex security issues to non-technical stakeholders.
Education
- Bachelor’s degree or equivalent experience (High School Diploma and 4 years relevant experience)
Pay Range
The typical pay range for this role is:
$106,605.00 - $284,280.00
This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company’s equity award program.
Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.
Great benefits for great people
We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.
Additional details about available benefits are provided during the application process and on Benefits Moments.
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.
CVS Health Edison, New Jersey, USA Office
Edison, United States
CVS Health Elizabeth, New Jersey, USA Office
Elizabeth, United States
CVS Health Florham Park, New Jersey, USA Office
Florham Park, United States
CVS Health Hoboken, New Jersey, USA Office
Hoboken, United States
CVS Health Jersey City, New Jersey, USA Office
Jersey City, United States
CVS Health Montclair, New Jersey, USA Office
Montclair, United States
CVS Health New Brunswick, New Jersey, USA Office
New Brunswick, United States
CVS Health New Rochelle, New York, USA Office
New Rochelle, United States
CVS Health New York, New York, USA Office
New York, United States
CVS Health New York, New York, USA Office
New York, United States
CVS Health New York, New York, USA Office
New York, United States
CVS Health New York, New York, USA Office
New York, United States
CVS Health Newark, New Jersey, USA Office
Newark, United States
CVS Health North Brunswick, New Jersey, USA Office
North Brunswick, United States
CVS Health Paterson, New Jersey, USA Office
Paterson, United States
CVS Health Teaneck, New Jersey, USA Office
Teaneck, United States
CVS Health Yonkers, New York, USA Office
Yonkers, United States
Similar Jobs
What you need to know about the NYC Tech Scene
Key Facts About NYC Tech
- Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
- Key Industries: Artificial intelligence, Fintech
- Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
- Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory



