Threat Hunting & Detection Engineer (us Federal)

Workday Workday · Enterprise · McLean, VA +1

This role is for a Threat Hunting & Detection Engineer at Workday Government, focusing on cybersecurity for U.S. federal agencies. The engineer will develop and improve detection capabilities in FedRAMP High and IL5 cloud-native SaaS environments, including air-gapped regions. Responsibilities include engineering detection logic using various telemetry sources, translating adversary behaviors into analytics aligned with MITRE ATT&CK and NIST frameworks, and collaborating with internal teams and compliance stakeholders. The role requires experience in cybersecurity operations, detection engineering, or threat hunting, with a strong understanding of cloud security and regulatory frameworks. U.S. citizenship and the ability to obtain a security clearance are mandatory.

What you'd actually do

  1. The Threat Hunting & Detection Engineer is responsible for engineering, validating, and continuously improving detection capabilities across FedRAMP High and IL5 cloud-native SaaS environments, including air-gapped regions.
  2. This role develops high-fidelity detection logic leveraging:
  3. You will translate adversary behaviors into actionable detection analytics aligned to MITRE ATT&CK and NIST SP 800-61r3 incident response lifecycle principles.
  4. You will support continuous monitoring requirements under FedRAMP and DoD IL5 frameworks, ensuring detection content aligns to compliance mandates, audit traceability, and evidentiary standards.
  5. In air-gapped environments, you will design detection strategies that account for: Limited telemetry pathways, Constrained automation capabilities, Reduced external enrichment access, Secure data transfer controls

Skills

Required

  • Splunk (correlation searches, data models, CIM alignment, SPL optimization)
  • Cloud-native telemetry (AWS CloudTrail, GuardDuty, Inspector, VPC Flow Logs, SaaS application logs)
  • Identity and access telemetry
  • Endpoint and container telemetry
  • Vulnerability intelligence sources
  • MITRE ATT&CK
  • NIST SP 800-61r3
  • FedRAMP
  • DoD IL5
  • 6+ years of experience in cybersecurity operations, detection engineering, or threat hunting
  • Hands-on experience building detections

Nice to have

  • TS/SCI w/CI Poly security clearance

What the JD emphasized

  • mandates that all Workday personnel working on the contracts be United States citizens
  • This role may require a security clearance at the TS/SCI w/CI Poly level.
  • Applicants must have the ability to obtain and maintain a U.S. government issued security clearance.
  • An active TS/SCI w/CI Poly is preferred