Cybersecurity Threat Engineer - Remote
Job Details
- Job Ref:
- 178285
- Location:
- Providence, RI 02903
- Location Flexibility:
- Remote
- Category:
- IT
- Job Type:
- Full-time
- Job Status:
- Exempt
- Anticipated Closing Date:
- Sept. 25, 2026
- Pay Basis
- Yearly
- Pay Range
- $84300.00 - $153100.00 Annually ($40.53 - $73.61 Hourly)
- Brand
- UNFI
Job Overview:
This Cybersecurity Engineer – Threat Engineer is responsible for supporting the creation, tuning, and optimization of security detections that enable timely identification of potential threats. Under the mentorship of senior engineers, the role assists with alert analysis, threat research, detection validation, and security monitoring activities. The position contributes to improving detection quality, reducing false positives, identifying visibility gaps, and enhancing security operations through the development and maintenance of SOAR playbooks and automated response workflows. This role provides an opportunity to develop hands-on experience with SIEM and SOAR platforms, threat intelligence, and detection engineering principles while helping defend against evolving cyber threats.
The role functions as part of the Cybersecurity Engineering team and collaborates cross-functionally with Threat Intelligence, Threat Emulation, GRC, Cybersecurity Architecture and Incident Response teams to help secure and defend against existing and emerging threats to the organization. The role is expected to execute assigned activities with direction, document findings clearly, communicate technical details to team members and business partners, escalate issues appropriately, and develop technical depth through hands-on participation in threat operations.
Job Responsibilities:
Detection Engineering
Develop, tune, and maintain threat detection use cases, correlation rules, and analytics across SIEM, EDR, and cloud security platforms
Perform detection validation, gap analysis, and continuous optimization to improve detection coverage, reduce false positives, and enhance security monitoring effectiveness
Partner with internal Threat Intelligence team to research emerging threats, adversary tactics, techniques, and procedures (TTPs), and translate intelligence into actionable detections aligned with the MITRE ATT&CK framework
Participate in purple team exercises with offensive (red) and defensive (blue) teams to simulate real-world adversary TTPs, validate detection effectiveness, identify monitoring and response gaps, and support improvements to security controls and processes
Automation & Integration Development
Design, develop, and maintain SOAR playbooks to automate incident response, threat enrichment, alert triage, and remediation workflows
Build and maintain integrations between security technologies, cloud services, ticketing systems, and enterprise platforms using APIs and custom automation
Develop scalable automation solutions that improve operational efficiency, reduce manual effort, and support end-to-end security operations processes
Collaboration & Knowledge Sharing
Share learnings and contribute to SOC knowledge articles, job aids, and peer discussions on hunt methodology, adversary TTP analysis, detection tuning, and related techniques
Collaborate with Threat Intelligence, Threat Emulation, GRC, Cybersecurity Architecture, Security Operations, and Engineering teams
Stay current with industry trends through research, training, certifications, knowledge sharing, and conferences where applicable
Additional Responsibilities
Support threat assessment and modeling activities by documenting threats and contributing to resiliency initiatives that require broader non-SOC business partner awareness
Support security tooling assessments as assigned
Monitor and evaluate third-party hunt activities and summarize findings or recommendations for review by senior team members
Maintain a shared library of threat research integrated with threat intelligence and detection libraries
Perform analysis on specific threats, such as tracking ransomware group activity, with guidance from senior team members
Correlate internal telemetry, including SIEM, logs, and EDR data, with external threat intelligence
Apply intelligence to support use case development and detection rule creation through collaboration across teams
Participate in tabletop exercises or simulations based on current threat actor behavior
Participate in intelligence-sharing collaborations, such as with ISACs, government, or vendors, as appropriate for the role
Develop and maintain basic security tools, scripts, and automation to support threat hunting and incident response
Create and update security documentation, procedures, and threat models as needed
Compile and analyze data for management reporting and metrics as directed
Performs other duties as assigned
Job Requirements:
Education/ Certifications:
Bachelor’s Degree in Computer Science, Cybersecurity, Information Technology, or a related discipline desired; equivalent education, training, certifications, or relevant IT/cybersecurity experience may be considered
Industry cybersecurity certifications such as Security+, GSEC, GISF, GCIH; certifications are preferred but not required
Experience:
0-3 years of professional experience in cybersecurity, security operations, infrastructure, systems administration, networking, software engineering, or related technology fields
0-3 years of experience or demonstrated exposure to threat monitoring, threat hunting, threat intelligence, incident response, vulnerability management, or security operations
0-3 years of working experience with Powershell, Python or other object-oriented scripting languages
Comfortable interacting with APIs and performing data transformation, enrichment, and analysis to support business and security objectives
Working knowledge of Windows and Linux/Unix platforms
Able to manage assigned work, follow priorities, and escalate when timelines or risks require attention
Strong written and verbal communication skills. Communicates clearly, accurately, and in a timely manner, adapting technical information for technical and non-technical audiences with guidance as needed
Collaborative and respectful of diverse people, thinking, and styles
Preferred Experience
Preferred exposure to SIEM, EDR, web proxy, email security, and security testing platforms or frameworks
Preferred entry-level or practitioner cybersecurity certifications such as Security+, CEH, GSEC, GCIH, GCIA, or equivalent
Familiarity with testing, validating, or documenting detection rules in SIEM platforms
Foundational understanding of MITRE ATT&CK, Cyber Kill Chain, Pyramid of Pain, and Detection as code principles
Foundational understanding of cloud infrastructure and cloud security
Foundational understanding of software development tools and methodologies, ex. SDLC, Version Control (Git)
Knowledge/Skills/Abilities
Developing technical and investigative skills, strong attention to detail, and a genuine interest in cybersecurity are essential for this role
Ability to multitask and prioritize work effectively
Highly motivated and willing to learn
Demonstrates ownership of assigned work and follows tasks through to completion
Developing critical thinking and security analysis skills
Clear written and verbal communication skills for technical and non-technical audiences
Ability to translate technical risk details into understandable language with guidance as needed
Foundational knowledge of threat research and adversary tactics and techniques frameworks, such as MITRE ATT&CK matrices, Cyber Kill Chain
Ability to contribute to briefings, presentations, and reports that convey analysis, threat trends, threat actor profiles, indicator bulletins, vulnerability details, and defensive strategies to varied audiences
Awareness of current and emerging cyber adversaries and their techniques, tactics, and procedures (TTPs)
Good judgment, sound escalation practices, and adherence to established procedures are required; the role generally operates with close supervision by management and senior team members
Work Environment:
Remote Role:
This position is classified as remote where the associate will perform remote work from their primary residence. Remote associates are welcome to work from the office but are not required to do so. While remote associates are not required to work from an office on a regular basis, they may be required to come to the office or other UNFI locations for necessary business reasons or if directed to do so by their manager.
Travel (minor):
This position may require the associate to travel to company offices, distribution centers, or other locations for specific meetings or other business reasons.
Physical Environment/Demands:
Office Roles:
Most work is performed in a temperature-controlled office environment.
Incumbent may sit for long periods of time at a desk or computer terminal.
While performing the duties of this job, the employee is regularly required to sit; use hands to finger, handle, or feel; reach with hands and arms; and talk or hear.
Incumbent may use calculators, keyboards, telephones, and other office equipment in the course of a normal workday.
Stooping, bending, twisting, and reaching may be required in the completion of job duties.
The above statements are intended to describe the general nature of the work performed by the employees assigned to this job. All employees must comply with Company policy and applicable laws. The responsibilities, duties and skills required of personnel so classified may vary within each department and/or location.
UNFI is an Equal Opportunity employer committed to creating an inclusive and respectful environment for all. All qualified applicants will receive equal consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity or expression, national origin, disability, protected veteran status, or other protected ground. Accommodation is available upon request for candidates taking part in all aspects of the job selection process. - M/F/Veteran/Disability. VEVRAA Federal Contractor.
- Company:
- United Natural Foods Inc.
Compensation:
UNFI anticipates paying the above-referenced pay rate (or within the above-referenced pay range) for this position. Actual Pay, where applicable, will depend on a number of factors, including, but not limited to, education, experience, training, and any requirements under applicable collective bargaining agreements. UNFI is committed to transparency in pay in compliance with applicable state/provincial and local laws.
Benefits:
For Washington positions (or positions that may be performed remotely from Washington), Click HERE for Washington-specific paid time off details.
Candidates hired into this position will also be eligible to participate in the following benefits programs: Paid Time Off; Sick Time; paid holidays and parental leave; 401K Program (or retirement savings plan if in Canada); medical, dental, vision, life, and accidental death/dismemberment insurance; short-term and long-term disability insurance program, Flexible Spending Account and/or Health Savings Account (U.S. only), subject to meeting the eligibility requirements and the terms and conditions of these programs, and subject to any requirements under applicable collective bargaining agreements.
Sales Positions Only: For sales positions that are commission-based, the above range is an estimate of total potential commission-based compensation during an associate’s first year, but UNFI offers an introductory period minimum of $680 per week. After the introductory period, as a 100% commission-based role, there is no set salary. UNFI’s commission plans are uncapped and average earnings vary depending on territory and sales achieved, among other factors.
UNFI’s compensation, benefits, and paid time off policies are subject to change in the Company’s sole discretion, consistent with applicable law. This job posting should not be construed as an offer of employment with certain terms, nor should it be construed as a guaranteed minimum.
Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act or for Canadian applicants in accordance with provincial human rights legislation.
Learn more about our brands:
Featured Jobs
Cybersecurity Threat Engineer - Remote
Providence, RIJob Overview: This Cybersecurity Engineer – Threat Engineer is responsible for supporting the creation, tuning, and optimization of security detections that enable timely identification of potential threats. Under the mentorship of senior engineers, the role assists with alert analysis, threat research, detection validation, and security monitoring activities. The position contributes …
Warehouse Order Selector
West Sacramento, CAWhy work for NorCal Produce – UNFI? Union UNFI 401K Incentive pays – earn more money for exceeding productivity goals (130 cases per hour quota goal) Incentives start at $0.25 all the way up to $7.50 per hour! Medical, dental and vision benefits after 30days of employment (on first of …
Warehouse Maintenance Mechanic
Lancaster, TXJob Overview: Responsible for the prompt repair and ongoing maintenance of facilities, equipment, and company vehicles. Identify, monitor and troubleshoot problems. Keep records of work performed and complete maintenance history logs. Control and account for equipment. Ensure operation of safe and functional equipment. Maintain grounds and clears parking lots. Maintain …
