Coalfire

Coalfire

Coalfire is a cybersecurity advisor that helps organizations avert threats, reduce risk, and turn security into a competitive advantage, fueling their success.

Internet Software & Services
251-1K
Founded 2001
$9M raised

Description

  • Collect, analyze, and operationalize threat intelligence to support proactive detection and threat hunting.
  • Develop, optimize, and maintain custom detection and threat-hunting queries across multiple SIEM platforms.
  • Tune alerts, build dashboards, and create saved searches for repeatable operational use cases.
  • Plan and lead cyclical, hypothesis-driven threat hunts using threat intelligence and behavior-based analytics.
  • Identify detection gaps, telemetry blind spots, and data quality issues.
  • Translate hunt and investigation outcomes into improved detections, alert tuning, dashboards, and runbooks.
  • Monitor, validate, and escalate SIEM alerts according to documented runbooks, SLAs, and severity thresholds.
  • Investigate and respond to security alerts across multiple log sources to determine scope, root cause, and impact.
  • Escalate confirmed incidents with timelines, evidence, and MITRE ATT&CK mapping to incident response teams or senior engineers.

Requirements

  • 2–4 years of experience in large-scale enterprise security environments, including cloud-hosted or hybrid infrastructures.
  • Working knowledge of at least one major cloud platform: Azure, AWS, or GCP.
  • Hands-on experience with at least two SIEM platforms such as Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic.
  • Experience operating in a production detection and response environment.
  • Experience independently monitoring, validating, and escalating SIEM alerts using runbooks, SLAs, and severity thresholds.
  • Experience conducting structured, cyclical threat hunting using hypothesis-driven and behavior-based methods.
  • Ability to leverage threat intelligence to understand attack chains, threat actor tradecraft, and expected telemetry.
  • Experience developing and maintaining custom detection and threat-hunting queries in at least two SIEM platforms.
  • Experience identifying detection gaps, telemetry blind spots, and data quality issues and turning them into improved detections and documentation.
  • Strong communication, organizational, problem-solving, and documentation skills.
  • Ability to work independently and as part of a team in fast-paced environments.
  • Experience with a Detection-as-Code framework.
  • Experience working in NIST 800-53 environments.
  • At least one required certification: Splunk Enterprise Certified Administrator, Splunk Enterprise Security Certified Administrator, SumoLogic Administrator, Microsoft Security Operations Associate, or Elastic Stack Certified Administrator.
  • Preferred: consulting or professional services background.
  • Preferred: automation experience with GitLab or GitHub using Terraform and Ansible.
  • Preferred: familiarity with FedRAMP, FISMA, HIPAA, HITRUST, PCI, and similar regulatory standards.

Benefits

  • Flexible work model with the ability to work from home or the office.
  • Paid parental leave.
  • Flexible time off.
  • Certification and training reimbursement.
  • Digital mental health and wellbeing support membership.
  • Comprehensive insurance options.
  • Employee resource groups and in-person and virtual events.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security GRC Specialist

SAP Fioneer 1K-5K Internet Software & Services

SAP Fioneer is seeking a Security GRC Specialist to strengthen and scale security governance, risk, and compliance practices across its financial services software products and operations.

16 hours, 32 minutes ago

CyberSecurity Analyst

Avertium 251-1K IT Services

Avertium is seeking a Cybersecurity Analyst to support clients through proactive security monitoring, incident response, security administration, and alignment of business and IT security objectives.

Active Directory Cybersecurity HIPAA Juniper Linux Network Security Penetration Testing SQL Unix Windows Server
1 day, 16 hours ago

CyberSecurity Analyst

Avertium 251-1K IT Services

Avertium is seeking a Cybersecurity Analyst to support clients through proactive monitoring, security event response, technical guidance, and administration of application, web, and infrastructure security measures.

Cybersecurity HIPAA Juniper Linux Network Security Penetration Testing SQL Unix Windows Server
1 day, 16 hours ago

Sr. GRC Analyst

Aya Healthcare 10K-50K Professional Services

Aya Healthcare is seeking a remote Senior GRC Analyst working PST hours to operate and mature its enterprise GRC program through scalable compliance processes, automation, and cross-functional risk management.

HIPAA
2 days, 15 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers