Salary
$80k – $134k per year
Location
Remote (United States)
Seniority
Junior · 2+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Coalfire is a cybersecurity and compliance services company that secures the future of businesses by solving complex cybersecurity challenges and is trusted by leading organizations across various sectors.
Why Join Us
We are seeking a Detection and Response Engineer to join our Defensive Services team, supporting SIEM monitoring and alerting, threat hunting, and purple team activities that help our clients meet both federal compliance and commercial security requirements. If you're passionate about defending organizations against evolving threats, driven to innovate, and thrive in a collaborative, high-performing environment, we'd love to have you on our team. Join us in our mission to make the world a safer place through proactive cybersecurity and operational excellence.
What You'll Do
- Collect, analyze, and operationalize threat intelligence to inform proactive detection and threat-hunting activities, driving measurable security posture improvements across client environments.
- Develop, optimize, and maintain custom detection and threat-hunting queries across two or more SIEM platforms, tuning alerts for improved fidelity and building dashboards and saved searches that support repeatable, operational use cases.
- Plan and lead cyclical, hypothesis-driven threat hunts using threat intelligence and behavior-based analytics; identify detection gaps and telemetry blind spots, and translate hunt outcomes into detection improvements, alert tuning, and updated runbooks.
What You'll Bring
- 2-4 years of experience operating within large-scale enterprise security environments, including exposure to cloud-hosted or hybrid infrastructures.
- Foundational working knowledge of at least one major cloud platform (Azure, AWS, or GCP) and how cloud telemetry is leveraged for security monitoring and investigations.
- Hands-on experience with at least two SIEM platforms (e.g., Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic) in a production detection and response environment.
- Experience independently monitoring, validating, and escalating SIEM alerts in accordance with documented runbooks, SLAs, and severity thresholds.
- Proven ability to independently investigate and respond to security alerts, performing deep-dive analysis across multiple log sources to determine scope, root cause, and impact.
- Experience escalating confirmed or high-confidence incidents with clear timelines, evidence, and MITRE ATT&CK mapping to Incident Response teams or senior engineers.
- Experience conducting structured and cyclical threat-hunting activities using hypothesis-driven and behavior-based methodologies.
- Ability to leverage threat intelligence to understand threat actor tradecraft, attack chains, and expected telemetry, and apply that knowledge to investigations and hunts.
- Hands-on experience developing, optimizing, and maintaining custom detection and threat-hunting queries in at least two SIEM platforms, and translating investigative requirements into performant, reusable query logic.
- Experience identifying detection gaps, telemetry blind spots, and data quality issues, and translating findings into alert tuning, new detection logic, dashboards, and updated runbooks or SOPs.
- Excellent communication, organizational, and problem-solving skills, with the ability to convey complex technical information clearly.
- Strong documentation skills for creating technical diagrams, written descriptions, and other supporting materials.
- Demonstrated ability to work both independently and as a member of a team, maintaining a professional attitude and demeanor.
- Critical thinking skills to balance robust security requirements against mission objectives.
- Proven track record of adapting quickly and efficiently in fast-paced, dynamic environments.
- Experience utilizing a Detection-as-Code framework
- Experience working with NIST 800-53 environments
- Splunk Enterprise Certified Administrator
- Splunk Enterprise Security Certified Administrator
- SumoLogic Administrator
- Microsoft Security Operations Associate
- Elastic Stack Certified Administrator
REQUIRED CERTIFICATIONS:
At least one of the following:
Bonus Points
- Professional services background: Prior experience supporting external clients from within a consulting or professional services organization.
- Automation capabilities: Experience automating workflows in GitLab or GitHub with Terraform and Ansible.
- Compliance frameworks: Understanding of FedRAMP, FISMA, HIPAA, HITRUST, PCI, and similar regulatory standards.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Free forever. No card. Under a minute.
Your match
How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.
Recommended for you based on this role
Similar stack
Same company
In your city
Principal SRE Engineer
1 day ago
$105k – $252k per year • Remote • Full-Time • 18+ years exp • Bachelor's Degree
Python
Java
Java
Gradle
DevOps
Ansible
AWS
CI/CD
CloudFormation
Configuration Management
Docker
GitHub Actions
GitLab CI
Helm
Jenkins
Kubernetes
Platform Engineering
Terraform
GitHub
GitLab
Cybersecurity
Sonatype Nexus IQ
Management
Confluence
Jira
Apply
Senior Software Engineer (Frontend)
1 day ago
≈ $54k – $175k per year (Estimated) • Remote • Full-Time
JavaScript
Node JS
TypeScript
Frontend
React.js
Sass
DevOps
AWS
CI/CD
Docker
Kubernetes
Rest API
Apply
Senior Software Engineer (Frontend)
1 day ago
≈ $35k – $113k per year (Estimated) • Remote • Full-Time
JavaScript
Node JS
TypeScript
Frontend
React.js
Sass
DevOps
AWS
CI/CD
Docker
Kubernetes
Rest API
Apply
Senior Software Engineer (Frontend)
1 day ago
≈ $35k – $116k per year (Estimated) • Remote • Full-Time
JavaScript
Node JS
TypeScript
Frontend
React.js
Sass
DevOps
AWS
CI/CD
Docker
Kubernetes
Rest API
Apply
Senior Software Engineer (Frontend)
1 day ago
≈ $61k – $200k per year (Estimated) • Remote • Full-Time
JavaScript
Node JS
TypeScript
Frontend
React.js
Sass
DevOps
AWS
CI/CD
Docker
Kubernetes
Rest API
Apply
Principal Solutions Architect
4 days ago
$113k – $189k per year • Remote • Full-Time • 8+ years exp • Bachelor's Degree
Cybersecurity
FedRAMP
GDPR
ISO 27001
PCI DSS
Apply
$64k – $117k per year • Remote • Full-Time • 3+ years exp • Bachelor's Degree
PowerShell
Python
Ruby
Cybersecurity
FedRAMP
HIPAA
Apply
Principal Cloud Engineer
1 month ago
$109k – $182k per year • Remote • Full-Time • 10+ years exp
DevOps
AWS
Azure
CI/CD
GCP
Terraform
Cybersecurity
CIS Benchmarks
FedRAMP
NIST 800-53
Apply
Senior Google Cloud Security Consultant
2 months ago
$109k – $182k per year • Remote • Full-Time • 2+ years exp
AI/ML
Vertex AI
DevOps
GCP
Terraform
IAM
Cybersecurity
FedRAMP
Google SecOps
HIPAA
Wiz
Apply
Principal Google Cloud Security Consultant
2 months ago
$127k – $212k per year • Remote • Full-Time • 4+ years exp
AI/ML
Vertex AI
DevOps
GCP
Terraform
IAM
Cybersecurity
FedRAMP
Google SecOps
HIPAA
Wiz
Apply
This is one of many
368,530 more open roles from verified company boards, updated every day.

