Detection and Response Engineer
Job description
About the role
Coalfire is seeking a technical professional to join our Defensive Services team to manage SIEM monitoring, threat hunting, and purple team operations. You will support our clients in meeting federal and commercial security standards by proactively identifying and mitigating emerging threats. In this capacity, you will serve as a technical specialist responsible for ensuring that detection mechanisms are current, effective, and aligned with evolving adversary behaviors. The role requires a balance of independent execution and collaboration with client stakeholders to deliver measurable security outcomes. You will translate complex technical findings into clear recommendations that enhance the overall security posture of the organization. This position is integral to maintaining the integrity and responsiveness of defensive programs in demanding environments. Your work will directly influence the detection maturity and incident readiness of clients across regulated industries.
Key facts
What you'll do
- Convert threat intelligence into prioritized detection logic and hunting hypotheses that proactively surface hidden risks.
- Architect and sustain tailored queries on at least two SIEM platforms, including the design of intuitive dashboards and reusable saved searches.
- Conduct structured hypothesis-driven threat hunts to surface coverage gaps and telemetry deficiencies, documenting improvements in updated runbooks.
- Analyze security alerts in depth, determine root causes, and articulate how findings align with the MITRE ATT&CK framework in support of incident response.
- Collaborate with clients to define requirements for monitoring scenarios, ensuring that use cases are practical and aligned with business risk.
- Maintain operational runbooks and detection playbooks, incorporating lessons learned from investigations and red team exercises.
- Partner with engineering and operations teams to close gaps in log sources, data quality, and alert fidelity across hybrid infrastructures.
- Validate detection rules through testing and tuning, measuring effectiveness using metrics that demonstrate reduced risk and improved time to detection.
- Leverage version-controlled workflows to manage changes to queries and configurations, supporting peer review and change accountability.
- Support the implementation of Detection-as-Code practices, integrating detection logic into automated pipelines where feasible.
- Interpret complex regulatory requirements and translate them into technical monitoring objectives for cloud and on-premises assets.
- Coordinate with incident responders to ensure that investigations benefit from optimized detection content and enriched telemetry.
- Document investigative procedures, analytic signatures, and threat patterns to build institutional knowledge within the team.
- Contribute to internal research on emerging techniques, ensuring that the portfolio of detections remains current and effective.
Requirements
- Bring 2 to 4 years of hands-on experience in large-scale enterprise security operations, with exposure to hybrid or cloud-hosted environments.
- Demonstrate proficiency in at least one major cloud platform, such as AWS, Azure, or GCP, specifically regarding security telemetry and log sources.
- Show hands-on experience with at least two SIEM platforms, examples of which include Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic.
- Have practical experience with Detection-as-Code frameworks and working within NIST 800-53 control environments.
- Hold at least one of the following certifications: Splunk Enterprise Certified Administrator, Splunk Enterprise Security Certified Administrator, SumoLogic Administrator, Microsoft Security Operations Associate, or Elastic Stack Certified Administrator.
- Exhibit strong analytical skills and the ability to work methodically through complex security issues under minimal direct supervision.
- Communicate effectively with both technical and non-technical audiences, translating technical concepts into actionable guidance.
- Maintain a strong attention to detail, ensuring that detection rules and investigations are thorough and accurate.
Nice to have
- Bring a background in professional services or consulting engagements that involved direct interaction with external clients.
- Apply skills in workflow automation using GitLab or GitHub, Terraform, and Ansible to manage and deploy detection content.
- Show familiarity with regulatory frameworks such as FedRAMP, FISMA, HIPAA, HITRUST, and PCI, and how they shape monitoring strategies.
Practical notes
This role operates within the United States in a Regular Full Time engagement model. Coalfire maintains a flexible work model that allows for remote or office-based work arrangements based on role requirements and team needs. The position may require participation in shift-based or after-hours coverage depending on client demands and incident response requirements. Compensation details are not specified in this posting. Candidates requiring reasonable accommodations during the application or interview process are asked to contact HumanResourcesMB@coalfire.com for assistance. Benefits for eligible team members may include paid parental leave, flexible time off, certification and training reimbursement, and digital mental health support, though specific details are not outlined in this description. Travel is not indicated as a routine requirement for this role. No specific visa sponsorship information is provided in this source document.