Jobs and Careers
TE

Senior Threat Detection Engineer

Tempur Sealy International
United Statesfull_timeVerifiedPosted 27 Mar 2026

About the role

ADP is hiring a Threat Detection Engineer – Cloud Security in either our Roseland, NJ, Alpharetta, GA or Norfolk, VA office. This is a HYBRID role.

In this role, you will work with Global Security teams from Critical Incident Response Center (CIRC), Threat Intelligence, Threat Hunting, Red Team, and AppDev, to create and drive threat detection to protect ADP assets. You will help lead efforts to design/define/create requirements to develop prevention, detection, and response capabilities within ADP Cyber security platforms. You will collaborate with other Detection Engineers to design, build & maintain cyber alert catalogs. You are keen on promoting the use of innovative new technology and best practices for evolving security objectives. You can present your ideas clearly, professionally on paper, in person, on video calls, and over the phone.

You have solid experience analyzing and defining solutions, maintaining and enhancing existing solutions, and participating in the delivery of projects. You enjoy brainstorming new concepts and collaborating with your team members. You can work with partners in IT, Ops, and Engineering to provide support for troubleshooting Production issues. Our best engineers are enthusiastic creators who stay current on new ways of optimizing threat detections and processes and enhancing business intelligence automation. They are always looking for new ways to improve detection quality. To thrive as a threat detection engineer, you'll need to enjoy SOAR Development and coding in Python and SQL. You'll need an understanding of leveraging APIs to pull and push data from different data sources to update records in the SOAR platform.

WHAT YOU'LL DO:

Here's what you can expect on a typical day in the life of a Threat Detection Engineer at ADP.

  • Develop advanced alerting capabilities based on threat intelligence, post-incident findings, new threats, and vulnerabilities
  • Maintain an expert-level understanding of attacks, vectors, and emergent threats
  • Develop new detection for our SOAR platform based on specific requests from stakeholders, threat intelligence, threat hunting, or purple exercise
  • Collaborate regularly with our CIRC and threat management to understand their requirements and needs
  • Experience with creating and implementing content in EDR, NDR, and SOAR
  • Stay updated with the latest threats and familiar with APT and common TTPs to integrate knowledge into new detections
  • Contribute to the development and updating of SOPs
  • Ability to provide content on deliverables, including written reports and technical documents, SOPs and configuration guides, and training and briefing materials
  • Work closely with the CIRC, Threat management team, and engineering teams to improve and build new tailored security detections
  • Analyze CIRC alert statistics and workflows to reduce false positives and properly focus engineering efforts
  • Provide design support on ways to improve detection and response capabilities
  • Provide backup support to the CIRC team when necessary
  • Help mature CIRC playbooks, workflow automation, and use cases to protect ADP assets
  • Build detection logic utilizing security logs to detect malicious activity with high fidelity across a broad set of detection cyber use cases
  • Act as a subject matter expert in multiple areas: security log signals from Linux, macOS, Windows, EDR, NDR, and cloud

Qualifications:

  • 3-5 years’ experience in threat detection, detection content development, cloud security or security operations
  • Hands-on experience with at least one major cloud platform (AWS, Azure, or GCP).            
  • Design, implement, and maintain detection use cases across cloud platforms (AWS, Azure, GCP).
  • Strong knowledge of cloud security concepts (IAM abuse, token theft, privilege escalation, container security, serverless threats).
  • Deep understanding of cloud-native attack vectors across AWS, Azure, and/or GCP.
  • Experience with cloud-native security tools (e.g., AWS GuardDuty, Azure Defender, Chronicle).
  • Strong analytical skills and cross-functional knowledge across multiple security disciplines
  • Strong interpersonal, verbal presentation, and written communication skills
  • Strong knowledge and working experience with databa

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Tempur Sealy International

View company profile →