RemoteWLBRemote only
Back to all jobs
Snowflake logo
Remote role · sr-threa

Sr. Threat Detection Engineer

Snowflake

threat huntingsecuritycloud securitypythonsql
Role brief

Build the future of the AI Data Cloud. Join the Snowflake team.

There is only one Data Cloud. Snowflake’s founders started from scratch and designed a data platform built for the cloud that is effective, affordable, and accessible to all data users. But it didn’t stop there. They engineered Snowflake to power the Data Cloud, where thousands of organizations unlock the value of their data with near-unlimited scale, concurrency, and performance. This is our vision: a world with endless insights to tackle the challenges and opportunities of today and reveal the possibilities of tomorrow.

WHAT YOU NEED:

  • Experience in writing detections, threat hunting, or responding to incidents across various platforms 

  • Experience collaborating  with various security teams and stakeholders to build and maintain detections 

  • Ability to review and analyze logging and observability requirements to support detection and response capabilities

  • A risk based approach to security in order to assist with prioritizing key security initiatives

  • Knowledge of the current security landscape with domain knowledge in a number of areas

  • Be a humble, team player prioritizing team success in a zero-ego environment

WHAT YOU WILL DO:

  • Develop and deploy detections using engineering practices (testing/validation, CI/CD pipelines, detections as code, detection development lifecycle,  etc.)

  • Mature our threat detection program by analyzing gaps and mitigating risks via detective controls

  • Build and maintain  strong partnerships with our Corporate Security Team and other stakeholders to provide detection as a service

  • Provide thought leadership to help our team establish best practices to alert on malicious activity 

  • Improve our team by building the next generation of detection engineering capabilities (graph-based monitoring, in-house SIEM development, etc)

MINIMUM QUALIFICATIONS:

  • Experience writing detections as code for organization specific risks 

  • Experience with one of the major cloud providers (AWS, Azure, GCP)

  • Experience in the security of SaaS products as well as securing and monitoring user workstations

  • Experience with development in a high level programming language (Go, Python, etc)

  • Experience with handling data programmatically (SQL, Python or equivalent)

PREFERRED QUALIFICATIONS:

  • You’ve published or presented at conferences showcasing your thought leadership in the security space

  • Developed and worked with systems that utilize infrastructure-as-a-code

  • Experience deploying detections at a global scale accounting for different  geographical requirements

  • Experience with Snowflake

WHY YOU SHOULD WORK WITH US:

  • We are laser focused on doing security better, and we do not tolerate the status quo

  • We have strong demand from our customers, and support from the business for security

  • We are a great team that has a diverse set of backgrounds and skills

  • Did we mention we are one of the fastest-growing software companies, ever? The opportunity for impact is enormous

Every Snowflake employee is expected to follow the company’s confidentiality and security standards for handling sensitive data. Snowflake employees must abide by the company’s data security plan as an essential part of their duties. It is every employee's duty to keep customer information secure and confidential.

The application window is expected to be open until December 18th, 2024. This opportunity will remain posted based on business needs, which may be before or after the specified date.

Snowflake is growing fast, and we’re scaling our team to help enable and accelerate our growth. We are looking for people who share our values, challenge ordinary thinking, and push the pace of innovation while building a future for themselves and Snowflake.

How do you want to make your impact?