Coalfire logo
Coalfire
Posted 75 days agoVerified live 2d ago

Detection and Response Engineer

Brief overview

Remote
2+ yrsMinimum
10 H-1B approvalsDept. of Labor
3 green cardsCertified filings
SIEM platformsSplunkMicrosoft SentinelELKLogRhythmSumo LogicCloud platformsAzureAWSGCPThreat intelligenceThreat huntingDetection-as-Code frameworkNIST 800-53Splunk Enterprise Certified AdministratorSplunk Enterprise Security Certified AdministratorSumoLogic Administrator

About the company

Coalfire is the premier Cybersecurity and Compliance Services leader for the tech, healthcare, and finance industries.

Visa sponsorship history

4 years sponsoring, last filed FY2026

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
10H-1B approved
100%approval rate
3new H-1B hires
3PERM certified
$129,791median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20232
20244
20254
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20231
20241
20251
20261
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
20241
20252
Top sponsored roles
ConsultantInformation Security AnalystPrincipal Consultant, Application Security
Sponsored employees from
India

Job description

Summary

Coalfire is on a mission to make the world a safer place by solving clients’ hardest cybersecurity challenges. They are seeking a Detection and Response Engineer to join their Defensive Services team, focusing on SIEM monitoring, threat hunting, and improving security compliance for clients.

Responsibilities

  • Collect, analyze, and operationalize threat intelligence to inform proactive detection and threat‑hunting activities, driving measurable security posture improvements across client environments
  • Develop, optimize, and maintain custom detection and threat‑hunting queries across two or more SIEM platforms, tuning alerts for improved fidelity and building dashboards and saved searches that support repeatable, operational use cases
  • Plan and lead cyclical, hypothesis‑driven threat hunts using threat intelligence and behavior‑based analytics; identify detection gaps and telemetry blind spots, and translate hunt outcomes into detection improvements, alert tuning, and updated runbooks

Skills

  • 2–4 years of experience operating within large‑scale enterprise security environments, including exposure to cloud‑hosted or hybrid infrastructures
  • Foundational working knowledge of at least one major cloud platform (Azure, AWS, or GCP) and how cloud telemetry is leveraged for security monitoring and investigations
  • Hands‑on experience with at least two SIEM platforms (e.g., Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic) in a production detection and response environment
  • Experience independently monitoring, validating, and escalating SIEM alerts in accordance with documented runbooks, SLAs, and severity thresholds
  • Proven ability to independently investigate and respond to security alerts, performing deep‑dive analysis across multiple log sources to determine scope, root cause, and impact
  • Experience escalating confirmed or high‑confidence incidents with clear timelines, evidence, and MITRE ATT&CK mapping to Incident Response teams or senior engineers
  • Experience conducting structured and cyclical threat‑hunting activities using hypothesis‑driven and behavior‑based methodologies
  • Ability to leverage threat intelligence to understand threat actor tradecraft, attack chains, and expected telemetry, and apply that knowledge to investigations and hunts
  • Hands‑on experience developing, optimizing, and maintaining custom detection and threat‑hunting queries in at least two SIEM platforms, and translating investigative requirements into performant, reusable query logic
  • Experience identifying detection gaps, telemetry blind spots, and data quality issues, and translating findings into alert tuning, new detection logic, dashboards, and updated runbooks or SOPs
  • Excellent communication, organizational, and problem-solving skills, with the ability to convey complex technical information clearly
  • Strong documentation skills for creating technical diagrams, written descriptions, and other supporting materials
  • Demonstrated ability to work both independently and as a member of a team, maintaining a professional attitude and demeanor
  • Critical thinking skills to balance robust security requirements against mission objectives
  • Proven track record of adapting quickly and efficiently in fast-paced, dynamic environments
  • Experience utilizing a Detection-as-Code framework
  • Experience working with NIST 800-53 environments
  • At least one of the following certifications: Splunk Enterprise Certified Administrator, Splunk Enterprise Security Certified Administrator, SumoLogic Administrator, Microsoft Security Operations Associate, Elastic Stack Certified Administrator
  • Professional services background: Prior experience supporting external clients from within a consulting or professional services organization
  • Automation capabilities: Experience automating workflows in GitLab or GitHub with Terraform and Ansible
  • Compliance frameworks: Understanding of FedRAMP, FISMA, HIPAA, HITRUST, PCI, and similar regulatory standards

Qualifications

Must Haves

  • 2–4 years of experience operating within large‑scale enterprise security environments, including exposure to cloud‑hosted or hybrid infrastructures
  • Foundational working knowledge of at least one major cloud platform (Azure, AWS, or GCP) and how cloud telemetry is leveraged for security monitoring and investigations
  • Hands‑on experience with at least two SIEM platforms (e.g., Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic) in a production detection and response environment
  • Experience independently monitoring, validating, and escalating SIEM alerts in accordance with documented runbooks, SLAs, and severity thresholds
  • Proven ability to independently investigate and respond to security alerts, performing deep‑dive analysis across multiple log sources to determine scope, root cause, and impact
  • Experience escalating confirmed or high‑confidence incidents with clear timelines, evidence, and MITRE ATT&CK mapping to Incident Response teams or senior engineers
  • Experience conducting structured and cyclical threat‑hunting activities using hypothesis‑driven and behavior‑based methodologies
  • Ability to leverage threat intelligence to understand threat actor tradecraft, attack chains, and expected telemetry, and apply that knowledge to investigations and hunts
  • Hands‑on experience developing, optimizing, and maintaining custom detection and threat‑hunting queries in at least two SIEM platforms, and translating investigative requirements into performant, reusable query logic
  • Experience identifying detection gaps, telemetry blind spots, and data quality issues, and translating findings into alert tuning, new detection logic, dashboards, and updated runbooks or SOPs
  • Excellent communication, organizational, and problem-solving skills, with the ability to convey complex technical information clearly
  • Strong documentation skills for creating technical diagrams, written descriptions, and other supporting materials
  • Demonstrated ability to work both independently and as a member of a team, maintaining a professional attitude and demeanor
  • Critical thinking skills to balance robust security requirements against mission objectives
  • Proven track record of adapting quickly and efficiently in fast-paced, dynamic environments
  • Experience utilizing a Detection-as-Code framework
  • Experience working with NIST 800-53 environments
  • At least one of the following certifications: Splunk Enterprise Certified Administrator, Splunk Enterprise Security Certified Administrator, SumoLogic Administrator, Microsoft Security Operations Associate, Elastic Stack Certified Administrator

Nice to Haves

  • Professional services background: Prior experience supporting external clients from within a consulting or professional services organization
  • Automation capabilities: Experience automating workflows in GitLab or GitHub with Terraform and Ansible
  • Compliance frameworks: Understanding of FedRAMP, FISMA, HIPAA, HITRUST, PCI, and similar regulatory standards

Benefits

  • Flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office
  • Opportunities to join employee resource groups
  • Participate in in-person and virtual events
  • Paid parental leave
  • Flexible time off
  • Certification and training reimbursement
  • Digital mental health and wellbeing support membership
  • Comprehensive insurance options

More jobs like this