xelys jobs xelys jobs

Security Engineer (Threat Detection)

Snowflake

full-remotemidpermanentsecuritybackend Full remote 66 days ago via WTTJ

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Threat DetectionSecurity EngineeringIncident ResponseThreat HuntingAI/MLAutomationCI/CDInfrastructure as CodePythonAWS

About the role

Role Overview

Join Snowflake as a Security Engineer (Threat Detection) to enhance Snowflake’s Threat Detection Program. You’ll use AI and automation to improve threat detection, triage, and response—making detections more effective and scalable across the organization.

Key Missions

  • Enhance Snowflake’s Threat Detection Program and expand detection coverage across teams.
  • Develop and deploy detections using modern engineering practices, including:
    • Rules-based detections
    • AI-assisted detections
  • Build “detection as a service” partnerships with stakeholders via:
    • self-service patterns
    • reusable components
    • AI-enhanced detections

Responsibilities

  • Collaborate with security and cross-functional stakeholders to improve detection strategy.
  • Make data-driven decisions to continuously improve detection quality.
  • Analyze logging/observability needs that enable detection and response.
  • Deploy detections globally and support production systems processing high-volume telemetry.

Requirements

  • Strong knowledge of the security landscape, particularly in one or more areas:
    • cloud security, identity & access, SaaS security, endpoint security, data security, insider risk
  • Risk-based security mindset to prioritize initiatives and determine where AI adds value over rules/heuristics.
  • Automation-first approach with comfort in:
    • CI/CD
    • infrastructure as code
    • detections as code
  • Solid coding experience (e.g., Python or Go) and desire to apply it to AI/ML-powered detection and response.
  • Experience writing production code with unit tests, version control, and CI/CD.
  • Experience with at least one major cloud provider (AWS, Azure, or GCP) and its native security/logging/monitoring services.
  • Ability to handle data programmatically (e.g., SQL and Python) and work with large-scale logs/telemetry.
  • Familiarity with SaaS and workstation risk themes (e.g., account compromise, data exfiltration, phishing, supply chain attacks).
  • CS degree or equivalent practical experience.
  • Experience developing and deploying systems using infrastructure as code (e.g., Terraform, CloudFormation) and/or detections as code frameworks.

Nice-to-Haves / Additional Signals

  • Experience developing detections at global scale.
  • Experience building platforms that process logging/metrics/traces for security analytics.
  • Experience with Snowflake or equivalent cloud data platforms supporting security workloads (pipelines/analytics).

About Snowflake

Snowflake is a cloud data platform company that enables organizations to store, process, and analyze data at scale. It provides data infrastructure and services used for analytics and data-driven workloads across industries.

Scraped 5/20/2026