Detection and Response Engineer (SPLUNK)

Posted 22 Days Ago
Hiring Remotely in United States
Remote
80K-134K Annually
Mid level
Cloud • Security • Cybersecurity
The Role
Operate SIEM monitoring and alerting, perform hypothesis-driven threat hunts, develop and tune detections across multiple SIEMs, translate intelligence into detection logic, escalate incidents with MITRE ATT&CK mapping, and produce runbooks, dashboards, and documentation to improve client security posture.
Summary Generated by Built In
About Coalfire
 
Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Chicago, Illinois with offices across the U.S. and U.K., and we support clients around the world.
 
But that’s not who we are – that’s just what we do.
 
We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.

Why Join Us    

We are seeking a Detection and Response Engineer to join our Defensive Services team, supporting SIEM monitoring and alerting, threat hunting, and purple team activities that help our clients meet both federal compliance and commercial security requirements. If you're passionate about defending organizations against evolving threats, driven to innovate, and thrive in a collaborative, high-performing environment, we'd love to have you on our team. Join us in our mission to make the world a safer place through proactive cybersecurity and operational excellence.

What You'll Do

  • Collect, analyze, and operationalize threat intelligence to inform proactive detection and threat‑hunting activities, driving measurable security posture improvements across client environments.
  • Develop, optimize, and maintain custom detection and threat‑hunting queries across two or more SIEM platforms, tuning alerts for improved fidelity and building dashboards and saved searches that support repeatable, operational use cases.
  • Plan and lead cyclical, hypothesis‑driven threat hunts using threat intelligence and behavior‑based analytics; identify detection gaps and telemetry blind spots, and translate hunt outcomes into detection improvements, alert tuning, and updated runbooks. 

What You'll Bring

  • 2–4 years of experience operating within large‑scale enterprise security environments, including exposure to cloud‑hosted or hybrid infrastructures.
  • Foundational working knowledge of at least one major cloud platform (Azure, AWS, or GCP) and how cloud telemetry is leveraged for security monitoring and investigations.
  • Hands‑on experience with at least two SIEM platforms (e.g., Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic) in a production detection and response environment.
  • Experience independently monitoring, validating, and escalating SIEM alerts in accordance with documented runbooks, SLAs, and severity thresholds.
  • Proven ability to independently investigate and respond to security alerts, performing deep‑dive analysis across multiple log sources to determine scope, root cause, and impact.
  • Experience escalating confirmed or high‑confidence incidents with clear timelines, evidence, and MITRE ATT&CK mapping to Incident Response teams or senior engineers.
  • Experience conducting structured and cyclical threat‑hunting activities using hypothesis‑driven and behavior‑based methodologies.
  • Ability to leverage threat intelligence to understand threat actor tradecraft, attack chains, and expected telemetry, and apply that knowledge to investigations and hunts.
  • Hands‑on experience developing, optimizing, and maintaining custom detection and threat‑hunting queries in at least two SIEM platforms, and translating investigative requirements into performant, reusable query logic.
  • Experience identifying detection gaps, telemetry blind spots, and data quality issues, and translating findings into alert tuning, new detection logic, dashboards, and updated runbooks or SOPs.
  • Excellent communication, organizational, and problem-solving skills, with the ability to convey complex technical information clearly.
  • Strong documentation skills for creating technical diagrams, written descriptions, and other supporting materials.
  • Demonstrated ability to work both independently and as a member of a team, maintaining a professional attitude and demeanor.
  • Critical thinking skills to balance robust security requirements against mission objectives.
  • Proven track record of adapting quickly and efficiently in fast-paced, dynamic environments.
  • Experience utilizing a Detection-as-Code framework
  • Experience working with NIST 800-53 environments 
  • REQUIRED CERTIFICATIONS: 

    At least one of the following:  

  • Splunk Enterprise Certified Administrator 
  • Splunk Enterprise Security Certified Administrator 
  • SumoLogic Administrator 
  • Microsoft Security Operations Associate 
  • Elastic Stack Certified Administrator 

Bonus Points

  • Professional services background: Prior experience supporting external clients from within a consulting or professional services organization. 
  • Automation capabilities: Experience automating workflows in GitLab or GitHub with Terraform and Ansible. 
  • Compliance frameworks: Understanding of FedRAMP, FISMA, HIPAA, HITRUST, PCI, and similar regulatory standards.

Why You’ll Want to Join Us
 
At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office.
 
Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.
 
At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, contact our Human Resources team at [email protected].

Skills Required

  • 2-4 years operating within large-scale enterprise security environments (including cloud-hosted or hybrid infrastructures)
  • Foundational working knowledge of at least one major cloud platform (Azure, AWS, or GCP)
  • Hands-on experience with at least two SIEM platforms (e.g., Splunk, Microsoft Sentinel, ELK, LogRhythm, Sumo Logic) in production detection and response
  • Experience independently monitoring, validating, and escalating SIEM alerts per runbooks, SLAs, and severity thresholds
  • Proven ability to investigate and respond to security alerts with deep-dive analysis across multiple log sources to determine scope, root cause, and impact
  • Experience escalating confirmed or high-confidence incidents with timelines, evidence, and MITRE ATT&CK mapping to Incident Response teams or senior engineers
  • Experience conducting structured, cyclical, hypothesis-driven threat-hunting activities using behavior-based methodologies
  • Ability to leverage threat intelligence to understand threat actor tradecraft and apply it to investigations and hunts
  • Hands-on experience developing, optimizing, and maintaining custom detection and threat-hunting queries in at least two SIEM platforms
  • Experience identifying detection gaps, telemetry blind spots, and data quality issues and translating findings into alert tuning, new detection logic, dashboards, and updated runbooks/SOPs
  • Excellent communication, organizational, and problem-solving skills with ability to convey complex technical information clearly
  • Strong documentation skills for technical diagrams, written descriptions, and supporting materials
  • Demonstrated ability to work independently and as part of a team with professional attitude and demeanor
  • Critical thinking skills to balance robust security requirements against mission objectives
  • Proven track record of adapting quickly and efficiently in fast-paced, dynamic environments
  • Experience utilizing a Detection-as-Code framework
  • Experience working with NIST 800-53 environments
  • At least one required certification: Splunk Enterprise Certified Administrator OR Splunk Enterprise Security Certified Administrator OR SumoLogic Administrator OR Microsoft Security Operations Associate OR Elastic Stack Certified Administrator
  • Prior professional services consulting experience supporting external clients
  • Experience automating workflows in GitLab or GitHub with Terraform and Ansible
  • Understanding of compliance frameworks such as FedRAMP, FISMA, HIPAA, HITRUST, PCI

Coalfire Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Coalfire and has not been reviewed or approved by Coalfire.

  • Leave & Time Off Breadth Flexible paid time off and paid parental leave are prominently offered, with remote/WFH support enabling time away when workload allows.
  • Healthcare Strength Comprehensive medical, dental, vision, wellness resources, and an EAP are part of the core package. Carrier coverage and plan options are regularly highlighted across employer materials.
  • Retirement Support A company‑matched 401(k) is included alongside other financial and development perks. This retirement benefit is consistently featured across benefits overviews.

Coalfire Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
1,062 Employees
Year Founded: 2001

What We Do

Coalfire is the cybersecurity advisor that helps private and public sector organizations avert threats, close gaps, and effectively manage risk. By providing independent and tailored advice, assessments, technical testing, and cyber engineering services, we help clients develop scalable programs that improve their security posture, achieve their business objectives, and fuel their continued success. Coalfire has been a cybersecurity thought leader for more than 20 years and has offices throughout the United States and Europe.

Similar Jobs

MongoDB Logo MongoDB

Chief Product Officer

Big Data • Cloud • Software • Database
Easy Apply
Remote or Hybrid
5 Locations
5550 Employees
129K-253K Annually

Enova Logo Enova

NetCredit Application Support Representative (Remote)

Fintech • Information Technology • Machine Learning • Software • Analytics • Financial Services
Easy Apply
In-Office or Remote
Chicago, IL, USA
1848 Employees
17-17 Hourly

Datadog Logo Datadog

Enterprise Security Sales Specialist

Artificial Intelligence • Cloud • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
2 Locations
6500 Employees
113K-150K Annually

Pie Insurance Logo Pie Insurance

Senior Claims Adjuster, Workers Compensation

Fintech • Insurance • Machine Learning • Analytics • Financial Services • Automation
Easy Apply
Remote
United States
350 Employees
85K-110K Annually

Similar Companies Hiring

Credal.ai Thumbnail
Software • Security • Productivity • Machine Learning • Artificial Intelligence
Brooklyn, NY
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account