Summary
Coalfire is on a mission to make the world a safer place by solving clients’ hardest cybersecurity challenges. They are seeking a Detection and Response Engineer to join their Defensive Services team, focusing on SIEM monitoring, threat hunting, and improving security compliance for clients.
Responsibilities
- Collect, analyze, and operationalize threat intelligence to inform proactive detection and threat‑hunting activities, driving measurable security posture improvements across client environments
- Develop, optimize, and maintain custom detection and threat‑hunting queries across two or more SIEM platforms, tuning alerts for improved fidelity and building dashboards and saved searches that support repeatable, operational use cases
- Plan and lead cyclical, hypothesis‑driven threat hunts using threat intelligence and behavior‑based analytics; identify detection gaps and telemetry blind spots, and translate hunt outcomes into detection improvements, alert tuning, and updated runbooks
Skills
- 2–4 years of experience operating within large‑scale enterprise security environments, including exposure to cloud‑hosted or hybrid infrastructures
- Foundational working knowledge of at least one major cloud platform (Azure, AWS, or GCP) and how cloud telemetry is leveraged for security monitoring and investigations
- Hands‑on experience with at least two SIEM platforms (e.g., Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic) in a production detection and response environment
- Experience independently monitoring, validating, and escalating SIEM alerts in accordance with documented runbooks, SLAs, and severity thresholds
- Proven ability to independently investigate and respond to security alerts, performing deep‑dive analysis across multiple log sources to determine scope, root cause, and impact
- Experience escalating confirmed or high‑confidence incidents with clear timelines, evidence, and MITRE ATT&CK mapping to Incident Response teams or senior engineers
- Experience conducting structured and cyclical threat‑hunting activities using hypothesis‑driven and behavior‑based methodologies
- Ability to leverage threat intelligence to understand threat actor tradecraft, attack chains, and expected telemetry, and apply that knowledge to investigations and hunts
- Hands‑on experience developing, optimizing, and maintaining custom detection and threat‑hunting queries in at least two SIEM platforms, and translating investigative requirements into performant, reusable query logic
- Experience identifying detection gaps, telemetry blind spots, and data quality issues, and translating findings into alert tuning, new detection logic, dashboards, and updated runbooks or SOPs
- Excellent communication, organizational, and problem-solving skills, with the ability to convey complex technical information clearly
- Strong documentation skills for creating technical diagrams, written descriptions, and other supporting materials
- Demonstrated ability to work both independently and as a member of a team, maintaining a professional attitude and demeanor
- Critical thinking skills to balance robust security requirements against mission objectives
- Proven track record of adapting quickly and efficiently in fast-paced, dynamic environments
- Experience utilizing a Detection-as-Code framework
- Experience working with NIST 800-53 environments
- At least one of the following certifications: Splunk Enterprise Certified Administrator, Splunk Enterprise Security Certified Administrator, SumoLogic Administrator, Microsoft Security Operations Associate, Elastic Stack Certified Administrator
- Professional services background: Prior experience supporting external clients from within a consulting or professional services organization
- Automation capabilities: Experience automating workflows in GitLab or GitHub with Terraform and Ansible
- Compliance frameworks: Understanding of FedRAMP, FISMA, HIPAA, HITRUST, PCI, and similar regulatory standards
Qualifications
Must Haves
- 2–4 years of experience operating within large‑scale enterprise security environments, including exposure to cloud‑hosted or hybrid infrastructures
- Foundational working knowledge of at least one major cloud platform (Azure, AWS, or GCP) and how cloud telemetry is leveraged for security monitoring and investigations
- Hands‑on experience with at least two SIEM platforms (e.g., Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic) in a production detection and response environment
- Experience independently monitoring, validating, and escalating SIEM alerts in accordance with documented runbooks, SLAs, and severity thresholds
- Proven ability to independently investigate and respond to security alerts, performing deep‑dive analysis across multiple log sources to determine scope, root cause, and impact
- Experience escalating confirmed or high‑confidence incidents with clear timelines, evidence, and MITRE ATT&CK mapping to Incident Response teams or senior engineers
- Experience conducting structured and cyclical threat‑hunting activities using hypothesis‑driven and behavior‑based methodologies
- Ability to leverage threat intelligence to understand threat actor tradecraft, attack chains, and expected telemetry, and apply that knowledge to investigations and hunts
- Hands‑on experience developing, optimizing, and maintaining custom detection and threat‑hunting queries in at least two SIEM platforms, and translating investigative requirements into performant, reusable query logic
- Experience identifying detection gaps, telemetry blind spots, and data quality issues, and translating findings into alert tuning, new detection logic, dashboards, and updated runbooks or SOPs
- Excellent communication, organizational, and problem-solving skills, with the ability to convey complex technical information clearly
- Strong documentation skills for creating technical diagrams, written descriptions, and other supporting materials
- Demonstrated ability to work both independently and as a member of a team, maintaining a professional attitude and demeanor
- Critical thinking skills to balance robust security requirements against mission objectives
- Proven track record of adapting quickly and efficiently in fast-paced, dynamic environments
- Experience utilizing a Detection-as-Code framework
- Experience working with NIST 800-53 environments
- At least one of the following certifications: Splunk Enterprise Certified Administrator, Splunk Enterprise Security Certified Administrator, SumoLogic Administrator, Microsoft Security Operations Associate, Elastic Stack Certified Administrator
Nice to Haves
- Professional services background: Prior experience supporting external clients from within a consulting or professional services organization
- Automation capabilities: Experience automating workflows in GitLab or GitHub with Terraform and Ansible
- Compliance frameworks: Understanding of FedRAMP, FISMA, HIPAA, HITRUST, PCI, and similar regulatory standards
Benefits
- Flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office
- Opportunities to join employee resource groups
- Participate in in-person and virtual events
- Paid parental leave
- Flexible time off
- Certification and training reimbursement
- Digital mental health and wellbeing support membership
- Comprehensive insurance options