Coalfire

Coalfire

Coalfire is a cybersecurity advisor that helps organizations avert threats, reduce risk, and turn security into a competitive advantage, fueling their success.

Internet Software & Services
251-1K
Founded 2001
$9M raised

Description

  • Collect, analyze, and operationalize threat intelligence to support proactive detection and threat hunting.
  • Develop, optimize, and maintain custom detection and threat-hunting queries across multiple SIEM platforms.
  • Tune alerts, build dashboards, and create saved searches for repeatable operational use cases.
  • Plan and lead cyclical, hypothesis-driven threat hunts using threat intelligence and behavior-based analytics.
  • Identify detection gaps, telemetry blind spots, and data quality issues.
  • Translate hunt and investigation outcomes into improved detections, alert tuning, dashboards, and runbooks.
  • Monitor, validate, and escalate SIEM alerts according to documented runbooks, SLAs, and severity thresholds.
  • Investigate and respond to security alerts across multiple log sources to determine scope, root cause, and impact.
  • Escalate confirmed incidents with timelines, evidence, and MITRE ATT&CK mapping to incident response teams or senior engineers.

Requirements

  • 2–4 years of experience in large-scale enterprise security environments, including cloud-hosted or hybrid infrastructures.
  • Working knowledge of at least one major cloud platform: Azure, AWS, or GCP.
  • Hands-on experience with at least two SIEM platforms such as Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic.
  • Experience operating in a production detection and response environment.
  • Experience independently monitoring, validating, and escalating SIEM alerts using runbooks, SLAs, and severity thresholds.
  • Experience conducting structured, cyclical threat hunting using hypothesis-driven and behavior-based methods.
  • Ability to leverage threat intelligence to understand attack chains, threat actor tradecraft, and expected telemetry.
  • Experience developing and maintaining custom detection and threat-hunting queries in at least two SIEM platforms.
  • Experience identifying detection gaps, telemetry blind spots, and data quality issues and turning them into improved detections and documentation.
  • Strong communication, organizational, problem-solving, and documentation skills.
  • Ability to work independently and as part of a team in fast-paced environments.
  • Experience with a Detection-as-Code framework.
  • Experience working in NIST 800-53 environments.
  • At least one required certification: Splunk Enterprise Certified Administrator, Splunk Enterprise Security Certified Administrator, SumoLogic Administrator, Microsoft Security Operations Associate, or Elastic Stack Certified Administrator.
  • Preferred: consulting or professional services background.
  • Preferred: automation experience with GitLab or GitHub using Terraform and Ansible.
  • Preferred: familiarity with FedRAMP, FISMA, HIPAA, HITRUST, PCI, and similar regulatory standards.

Benefits

  • Flexible work model with the ability to work from home or the office.
  • Paid parental leave.
  • Flexible time off.
  • Certification and training reimbursement.
  • Digital mental health and wellbeing support membership.
  • Comprehensive insurance options.
  • Employee resource groups and in-person and virtual events.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Risk Control Analyst, Card & ATO Risk

Binance 5K-10K Capital Markets

Binance is hiring a Risk Control Analyst to manage card issuer-side fraud and account takeover risk strategies across payment and risk operations.

Blockchain SQL
5 hours, 53 minutes ago

Vulnerability Management Analyst

Copper River Management 11-50 Internet Software & Services

Copper River Cyber Solutions is hiring a Vulnerability Management Analyst to support the NIH cybersecurity program by identifying, prioritizing, tracking, and reporting vulnerabilities across enterprise systems and infrastructure.

Cybersecurity
1 day, 4 hours ago

SOC Supervisor

Central Transportation Services, Inc. 11-50 transportation/trucking/railroad

CTS is seeking a remote SOC Supervisor to lead daily security operations, incident response, and team performance within its managed services environment.

SIEM
1 day, 5 hours ago

Senior Governance, Risk, and Compliance (GRC) Analyst (Remote)

RainFocus 251-1K IT Services

RainFocus is hiring a Senior Governance, Risk, and Compliance (GRC) Analyst to own and advance its security and privacy compliance program for a fast-growing event software platform serving enterprise customers.

2 days, 5 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers