Skip to content

Open nowPosted today

Detection & Automation Engineer III

Northwestern Mutual19 open roles

Where
Milwaukee, WI Corporate
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowDetection & Automation Engineer IIINorthwestern Mutual · Milwaukee, WI Corporate
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Northwestern Mutual's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Northwestern Mutual postings stay open a median of 5 days.

Share of postings closed within
  1. 1.9%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.1%30 days
This job: posted today

Northwestern Mutual median: 5 days open

The posting

About the Job:

At Northwestern Mutual, our cybersecurity team is focused on protecting our clients, advisors, and business platforms through innovative detection and automation capabilities. As a Detection & Automation Engineer III, you will play a key role in enhancing our ability to identify, investigate, and respond to cybersecurity threats across cloud, identity, endpoint, database, and application environments.

This position blends DevOps, detection engineering, SIEM administration, telemetry engineering, and data integration to improve security visibility and strengthen our threat detection program. You'll work closely with cybersecurity, infrastructure, cloud, and application teams to build scalable detection capabilities, onboard critical security telemetry, and drive continuous improvements across our security operations ecosystem.

What You'll Do:

  • Design, develop, test, and maintain advanced threat detections across a variety of security platforms and data sources.
  • Enhance detection coverage by identifying telemetry gaps and partnering with stakeholders to improve visibility across the environment.
  • Administer and optimize Splunk Enterprise Security, including ES frameworks, data models, reporting, dashboards, and search performance.
  • Troubleshoot and resolve security data ingestion, field extraction, parsing, normalization, and performance issues.
  • Partner with technology teams to onboard new security data sources and validate telemetry quality.
  • Develop and maintain security logging standards, monitoring controls, and data quality processes.
  • Design monitoring capabilities for enterprise databases and business-critical applications, focusing on privileged access, authentication activity, anomalous behavior, and sensitive data access.
  • Contribute to Detection-as-Code initiatives through version control, automated testing, CI/CD pipelines, and reusable detection frameworks.
  • Track and improve key metrics including detection coverage, alert fidelity, telemetry health, and operational effectiveness.
  • Drive continuous improvement efforts that reduce false positives, improve detection accuracy, and streamline security operations.
  • Provide technical leadership, mentor junior engineers, and contribute to architectural and engineering best practices.

What You'll Bring to the Role:

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field, or equivalent professional experience.
  • 2+ years of experience in cybersecurity, detection engineering, security operations, SIEM engineering, or related disciplines.
  • Hands-on experience developing and maintaining threat detections within Splunk Enterprise Security or comparable SIEM platforms.
  • Strong understanding of security monitoring, log management, telemetry engineering, and threat detection methodologies.
  • Experience working with cloud platforms, identity systems, endpoint security technologies, applications, databases, and enterprise infrastructure.
  • Knowledge of security frameworks, including MITRE ATT&CK, and their application to threat detection strategies.
  • Experience onboarding, normalizing, and validating security data from multiple sources.
  • Familiarity with scripting or automation technologies such as Python, PowerShell, or similar languages.
  • Experience with source control platforms, automated testing, and CI/CD pipelines.
  • Strong troubleshooting, analytical, and problem-solving skills with the ability to identify complex security issues and implement scalable solutions.
  • Excellent communication and collaboration skills with the ability to work effectively across technical and business teams.

Preferred Qualifications

  • Experience with Splunk Enterprise and/or Cribl Stream.
  • Experience supporting cybersecurity monitoring and logging requirements within regulated environments.
  • Background in database administration, enterprise data engineering, or large-scale telemetry architectures.
  • Experience implementing Detection-as-Code methodologies and security automation solutions.
  • Knowledge of audit logging standards, security monitoring controls, and modern security observability practices.
  • Relevant industry certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Administrator, GIAC, CISSP, GCIA, GCIH, or equivalent.

#LI-Hybrid

Compensation Range:

Pay Range - Start:

$108,160.00

Pay Range - End:

$162,240.00

Geographic Specific Pay Structure:

Structure 110:

$118,960.00 USD - $178,440.00 USD

Structure 115:

$124,400.00 USD - $186,600.00 USD

We believe in fairness and transparency. It’s why we share the salary range for most of our roles. However, final salaries are based on a number of factors, including the skills and experience of the candidate; the current market; location of the candidate; and other factors uncovered in the hiring process. The standard pay structure is listed but if you’re living in California, New York City or other eligible location, geographic specific pay structures, compensation and benefits could be applicable, click here to learn more.

Grow your career with a best-in-class company that puts our clients' interests at the center of all we do. Get started now!

Northwestern Mutual is an equal opportunity employer that welcomes talented individuals of all backgrounds. We are committed to creating and maintaining an environment in which each employee can contribute creative ideas, seek challenges, assume leadership and continue to focus on meeting and exceeding business and personal objectives.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Northwestern Mutual's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Northwestern Mutual's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Northwestern Mutual's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.