Detection & Automation Engineer III

Northwestern MutualMilwaukee, WisconsinOn-siteFull-timeSenior, 5–8 yearsListed 3 hours ago

Apply now

About this role

About the Job:

At Northwestern Mutual, our cybersecurity team is focused on protecting our clients, advisors, and business platforms through innovative detection and automation capabilities. As a Detection & Automation Engineer III, you will play a key role in enhancing our ability to identify, investigate, and respond to cybersecurity threats across cloud, identity, endpoint, database, and application environments.

This position blends DevOps, detection engineering, SIEM administration, telemetry engineering, and data integration to improve security visibility and strengthen our threat detection program. You'll work closely with cybersecurity, infrastructure, cloud, and application teams to build scalable detection capabilities, onboard critical security telemetry, and drive continuous improvements across our security operations ecosystem.

What You'll Do:

- Design, develop, test, and maintain advanced threat detections across a variety of security platforms and data sources.
- Enhance detection coverage by identifying telemetry gaps and partnering with stakeholders to improve visibility across the environment.
- Administer and optimize Splunk Enterprise Security, including ES frameworks, data models, reporting, dashboards, and search performance.
- Troubleshoot and resolve security data ingestion, field extraction, parsing, normalization, and performance issues.
- Partner with technology teams to onboard new security data sources and validate telemetry quality.
- Develop and maintain security logging standards, monitoring controls, and data quality processes.
- Design monitoring capabilities for enterprise databases and business-critical applications, focusing on privileged access, authentication activity, anomalous behavior, and sensitive data access.
- Contribute to Detection-as-Code initiatives through version control, automated testing, CI/CD pipelines, and reusable detection frameworks.
- Track and improve key metrics including detection coverage, alert fidelity, telemetry health, and operational effectiveness.
- Drive continuous improvement efforts that reduce false positives, improve detection accuracy, and streamline security operations.
- Provide technical leadership, mentor junior engineers, and contribute to architectural and engineering best practices.

What You'll Bring to the Role:

- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field, or equivalent professional experience.
- 2+ years of experience in cybersecurity, detection engineering, security operations, SIEM engineering, or related disciplines.
- Hands-on experience developing and maintaining threat detections within Splunk Enterprise Security or comparable SIEM platforms.
- Strong understanding of security monitoring, log management, telemetry engineering, and threat detection methodologies.
- Experience working with cloud platforms, identity systems, endpoint security technologies, applications, databases, and enterprise infrastructure.
- Knowledge of security frameworks, including MITRE ATT&CK, and their application to threat detection strategies.
- Experience onboarding, normalizing, and validating security data from multiple sources.
- Familiarity with scripting or automation technologies such as Python, PowerShell, or similar languages.
- Experience with source control platforms, automated testing, and CI/CD pipelines.
- Strong troubleshooting, analytical, and problem-solving skills with the ability to identify complex security issues and implement scalable solutions.
- Excellent communication and collaboration skills with the ability to work effectively across technical and business teams.

Preferred Qualifications

- Experience with Splunk Enterprise and/or Cribl Stream.
- Experience supporting cybersecurity monitoring and logging requirements within regulated environments.
- Background in database administration, enterprise data engineering, or large-scale telemetry architectures.
- Experience implementing Detection-as-Code methodologies and security automation solutions.
- Knowledge of audit logging standards, security monitoring controls, and modern security observability practices.
- Relevant industry certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Administrator, GIAC, CISSP, GCIA, GCIH, or equivalent.

#LI-Hybrid

Compensation Range:

Pay Range - Start:
$108,160.00

Pay Range - End:
$162,240.00

Geographic Specific Pay Structure:

Structure 110:
$118,960.00 USD - $178,440.00 USD
###

Structure 115:

$124,400.00 USD - $186,600.00 USD

We believe in fairness and transparency. It’s why we share the salary range for most of our roles. However, final salaries are based on a number of factors, including the skills and experience of the candidate; the current market; location of the candidate; and other factors uncovered in the hiring process. The standard pay structure is listed but if you’re living in California, New York City or other eligible location, geographic specific pay structures, compensation and benefits could be applicable, click here to learn more.

Grow your career with a best-in-class company that puts our clients' interests at the center of all we do. Get started now!

Northwestern Mutual is an equal opportunity employer that welcomes talented individuals of all backgrounds. We are committed to creating and maintaining an environment in which each employee can contribute creative ideas, seek challenges, assume leadership and continue to focus on meeting and exceeding business and personal objectives.