Coalfire

Coalfire

Coalfire is a cybersecurity advisor that helps organizations avert threats, reduce risk, and turn security into a competitive advantage, fueling their success.

Internet Software & Services
251-1K
Founded 2001
$9M raised

Description

  • Collect, analyze, and operationalize threat intelligence to support proactive detection and threat hunting.
  • Develop, optimize, and maintain custom detection and threat-hunting queries across multiple SIEM platforms.
  • Tune alerts, build dashboards, and create saved searches for repeatable operational use cases.
  • Plan and lead cyclical, hypothesis-driven threat hunts using threat intelligence and behavior-based analytics.
  • Identify detection gaps, telemetry blind spots, and data quality issues.
  • Translate hunt and investigation outcomes into improved detections, alert tuning, dashboards, and runbooks.
  • Monitor, validate, and escalate SIEM alerts according to documented runbooks, SLAs, and severity thresholds.
  • Investigate and respond to security alerts across multiple log sources to determine scope, root cause, and impact.
  • Escalate confirmed incidents with timelines, evidence, and MITRE ATT&CK mapping to incident response teams or senior engineers.

Requirements

  • 2–4 years of experience in large-scale enterprise security environments, including cloud-hosted or hybrid infrastructures.
  • Working knowledge of at least one major cloud platform: Azure, AWS, or GCP.
  • Hands-on experience with at least two SIEM platforms such as Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic.
  • Experience operating in a production detection and response environment.
  • Experience independently monitoring, validating, and escalating SIEM alerts using runbooks, SLAs, and severity thresholds.
  • Experience conducting structured, cyclical threat hunting using hypothesis-driven and behavior-based methods.
  • Ability to leverage threat intelligence to understand attack chains, threat actor tradecraft, and expected telemetry.
  • Experience developing and maintaining custom detection and threat-hunting queries in at least two SIEM platforms.
  • Experience identifying detection gaps, telemetry blind spots, and data quality issues and turning them into improved detections and documentation.
  • Strong communication, organizational, problem-solving, and documentation skills.
  • Ability to work independently and as part of a team in fast-paced environments.
  • Experience with a Detection-as-Code framework.
  • Experience working in NIST 800-53 environments.
  • At least one required certification: Splunk Enterprise Certified Administrator, Splunk Enterprise Security Certified Administrator, SumoLogic Administrator, Microsoft Security Operations Associate, or Elastic Stack Certified Administrator.
  • Preferred: consulting or professional services background.
  • Preferred: automation experience with GitLab or GitHub using Terraform and Ansible.
  • Preferred: familiarity with FedRAMP, FISMA, HIPAA, HITRUST, PCI, and similar regulatory standards.

Benefits

  • Flexible work model with the ability to work from home or the office.
  • Paid parental leave.
  • Flexible time off.
  • Certification and training reimbursement.
  • Digital mental health and wellbeing support membership.
  • Comprehensive insurance options.
  • Employee resource groups and in-person and virtual events.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Website Security Support - Remediation Analyst

GoDaddy 5001-10000 Technology, Information and Internet

GoDaddy is hiring a remote Remediation Support Analyst in India to manage website security incidents by identifying, removing, and preventing malware while restoring customer site functionality.

DNS Drupal JavaScript Linux Magento .NET PHP Shell Scripting SQL Server TCP/IP Unix WordPress
3 hours, 29 minutes ago

IT SOX Admin

CareDx 251-1K Pharmaceuticals

CareDx is seeking an IT compliance and systems documentation professional to strengthen system governance, access controls, audit readiness, and operational integrity in its regulated precision-medicine diagnostics environment.

Active Directory Git NetSuite
4 hours, 44 minutes ago

Information Systems Security Officer (ISSO), Senior

Lever 251-1K Professional Services

AnaVation is seeking a senior Information Systems Security Officer (ISSO) to lead the Risk Management Framework (RMF) and accreditation of a new digital evidence platform supporting a U.S. Federal Government client, working remotely with occasional travel to Washington, DC.

AWS Azure DevSecOps Penetration Testing
2 days, 4 hours ago

Senior Detection Engineering & Threat Hunting Analyst

Huntress 251-1K Professional Services

Huntress is hiring a remote US Senior Detection Engineering and Threat Hunting Analyst to develop scalable detections and proactively identify stealthy threats across millions of endpoints and identities supporting its 24/7 SOC.

Azure Cybersecurity Git Linux macOS
3 days, 3 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers