✦ Luna Orbit — Cybersecurity

Threat Engineer

at Reinsurance Group of America

Remote 💰 $78K – $110K USD / year Posted April 17, 2026
Salary $78K – $110K USD / year
Type Not Specified
Experience entry
Exp. Years 1+ Years of experience - Required; 2+ Years of relevant experience - Preferred
Education Associate's Degree (AA) or equivalent experience - Required
Category Cybersecurity

This remote role supports and matures cyber risk management through proactive threat hunting and detection engineering. You will author, tune, and maintain detections, conduct hypothesis-driven threat hunts, and translate adversary behavior into actionable alerts and telemetry improvements.

  • Support threat detection and detection engineering activities
  • Author, tune, and maintain detections and improve telemetry
  • Conduct hypothesis-driven threat hunts and translate adversary behavior into actionable alerts
  • Contribute to purple team (risk hunting, telemetry validation, detection efficacy)
  • Support automations/orchestrations and define logging requirements for better detection

Responsibilities include operational monitoring and (if required) 24/7 on-call alert triage and investigation. You will also contribute to purple team activities, improve telemetry and logging requirements, develop cybersecurity metrics for security operations, and assist with security tool and automation/workflow improvements across network, host, cloud, and identity platforms.

The ideal candidate is an entry-level threat engineer with 1+ years in incident response, security engineering, offensive security, threat emulation, penetration testing, or security operations. They have hands-on experience with telemetry gap identification, purple team contributions (risk hunting, telemetry validation, detection efficacy), and developing cybersecurity metrics to support security operations in a globally distributed environment.

Associate's Degree (AA) or equivalent experience - Required1+ Years of experience in one or more areas; incident responsesecurity engineeringoffensive securitythreat emulationpenetration testingor security operations - RequiredExperience identifying and addressing telemetry gaps in security monitoring - RequiredExperience contributing to purple teamincluding supporting risk huntingtelemetry validationdetection efficacy - RequiredExperience developing and supporting cybersecurity metrics and reporting to support security operations - RequiredAbility to support complex incidents and evolve strategies based on new information - RequiredJunior level analytical skills with the ability to investigate networkhostcloud and identity platforms - Requiredglobally distributed environment - RequiredAbility to work independently within a globally distributed environment - RequiredStrong written and verbal communications skills - Assist in creating automation/workflows to scale security operations - RequiredAbility to quickly adapt to new methodswork under tight deadlines and stressful conditions - RequiredJunior level investigativeanalytical and problem solving skills requiredJunior level ability to set goals and handle multiple tasks
Not specified
Threat huntingdetection engineeringoperational monitoringauthoring/tuning/maintaining detectionshypothesis-driven threat huntsactionable alertstelemetry improvementsalert triageincident responsesecurity engineeringoffensive securitythreat emulationpenetration testingsecurity operationsorchestrationsautomationsintrusion and/or defensive analysisaudit/compliance/risk-reduction effortstool development/procurement/managementlogging requirementsprojects that drive down riskpurple teamrisk huntingtelemetry validationdetection efficacycybersecurity metrics and reportingnetwork investigationhost investigationcloud investigationidentity platforms investigationautomation/workflowsglobally distributed environmentwork independentlywritten and verbal communications
threat huntingthreat detectiondetection engineeringoffensive securitydefensive analysisintrusion and/or defensive analysisincident responsesecurity engineeringthreat emulationpenetration testingsecurity operationsoperational monitoringauthoring detectionstuning detectionsmaintaining detectionshypothesis-driven threat huntstranslating adversary behavior into actionable alertstelemetry improvementsorchestrationsautomationsintrusion investigationlogging requirementssecurity monitoringlogging and telemetrypurple teamrisk huntingtelemetry validationdetection efficacycybersecurity metricssecurity operations reportingnetwork investigationhost investigationcloud investigationidentity platforms investigationaudit/compliance/risk-reduction efforts (junior level)offensive and/or defensive security tool developmentsecurity tool procurementsecurity tool management
24/7 on-call rotation (if required)alert triageinvestigationSupport security audit/compliance/risk-reduction efforts at a junior levelglobally distributed environment collaborationwork independently within a globally distributed environmentStrong written and verbal communications skillsability to quickly adapt to new methodswork under tight deadlines and stressful conditionsability to investigate and solve problemsability to set goals and handle multiple tasks
Industry Insurance
Job Function Engineer and operate threat detection capabilities to mitigate cyber risk through threat hunting and telemetry improvements
Role Subtype Security Engineer
Tech Domains Cybersecurity
Threat Engineercyber riskthreat huntingdetection engineeringoperational monitoringauthoringtuningmaintaining detectionshypothesis-driven threat huntsactionable alertstelemetry improvements24/7 on-call rotationalert triageincident responsesecurity engineeringoffensive securitydefensive analysisorchestrationsautomationsintrusion analysissecurity auditcompliancerisk reductionoffensive tool developmentdefensive tool developmenttool procurementtool managementlogging requirementspurple teamrisk huntingtelemetry validationdetection efficacycybersecurity metricssecurity operations reportingnetworkhostcloudidentity platformsautomationworkflowsnetwork host cloud identity platforms

Associate's Degree (AA) or equivalent experience - Required, 1+ Years of experience in incident response, security engineering, offensive security, threat emulation, penetration testing, or security operations, Experience identifying and addressing telemetry gaps in security monitoring, Experience contributing to purple team, including supporting risk hunting, telemetry validation, detection efficacy

Apply for this Position →

Get matched to jobs like this

Luna finds roles that fit your skills and career goals — no endless scrolling required.

Create a Free Profile