Senior Threat Detection Engineer
U.S. BankAbout the role
At U.S. Bank, we’re on a journey to do our best. Helping the customers and businesses we serve to make better and smarter financial decisions and enabling the communities we support to grow and succeed. We believe it takes all of us to bring our shared ambition to life, and each person is unique in their potential. A career with U.S. Bank gives you a wide, ever-growing range of opportunities to discover what makes you thrive at every stage of your career. Try new things, learn new skills and discover what you excel at—all from Day One.
Job Description
About the Role
We’re seeking a Senior Threat Detection Engineer with deep expertise in writing detection logic to defend against advanced threats, In this role, you will play a key part in fortifying our defenses against sophisticated cyber threats targeting the financial services sector.
You will develop and maintain detection logic, simulate real-world attack scenarios, and work closely with our threat intelligence, SOC, and red/blue teams to ensure our detection capabilities are proactive, precise, and resilient.
Preferred Skills/Experience
Design, implement, and continuously enhance advanced detection logic for financial threat scenarios (e.g., insider threats, APTs, Ransomware Actors).
Leverage offensive security techniques (e.g., MITRE ATT&CK, red team findings, threat emulation tools) to simulate and validate detection coverage.
Integrate and utilize Breach and Attack Simulation (BAS) platforms to identify detection gaps and improve threat visibility.
Collaborate with threat intelligence teams to operationalize IOCs, TTPs, and emerging threat trends specific to financial services.
Tune and optimize SIEM, EDR, and XDR rules and analytics for signal-to-noise ratio.
Attack Simulation: Develop and execute sophisticated attack simulations to test and evaluate the effectiveness of security measures.
Continuous Improvement: Stay updated with the latest cybersecurity trends and technologies, continually enhancing detection capabilities.
Collaboration: Work closely with other security team members and departments to ensure comprehensive protection across all systems.
Assist with investigations of advanced threats and provide expert-level guidance on detection and response strategies.
Partner with security operations, red team, and incident response for end-to-end threat lifecycle coverage.
5+ years of experience in cybersecurity with a focus on detection engineering or threat detection.
Strong knowledge of offensive security tactics, including familiarity with adversary emulation frameworks and red team methodologies.
Demonstrate in depth knowledge of operating system internals and network communications
Strong experience with cloud platforms (AWS, Azure, GCP) and their security services (e.g., AWS GuardDuty, Azure Sentinel, GCP Security Command Center).
Proficiency in writing detection rules using SIEMs or cloud-native tools (e.g., Splunk, Sentinel, Chronicle, Panther).
Familiarity with cloud attack frameworks (e.g., MITRE ATT&CK for Cloud, Cloud Security Alliance’s Cloud Controls Matrix).
Experience with Infrastructure as Code (IaC) security and cloud configuration monitoring.
<
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s