Coalfire

Coalfire

Coalfire is a cybersecurity advisor that helps organizations avert threats, reduce risk, and turn security into a competitive advantage, fueling their success.

Internet Software & Services
251-1K
Founded 2001
$9M raised

Description

  • Collect, analyze, and operationalize threat intelligence to support proactive detection and threat hunting.
  • Develop, optimize, and maintain custom detection and threat-hunting queries across multiple SIEM platforms.
  • Tune alerts, build dashboards, and create saved searches for repeatable operational use cases.
  • Plan and lead cyclical, hypothesis-driven threat hunts using threat intelligence and behavior-based analytics.
  • Identify detection gaps, telemetry blind spots, and data quality issues.
  • Translate hunt and investigation outcomes into improved detections, alert tuning, dashboards, and runbooks.
  • Monitor, validate, and escalate SIEM alerts according to documented runbooks, SLAs, and severity thresholds.
  • Investigate and respond to security alerts across multiple log sources to determine scope, root cause, and impact.
  • Escalate confirmed incidents with timelines, evidence, and MITRE ATT&CK mapping to incident response teams or senior engineers.

Requirements

  • 2–4 years of experience in large-scale enterprise security environments, including cloud-hosted or hybrid infrastructures.
  • Working knowledge of at least one major cloud platform: Azure, AWS, or GCP.
  • Hands-on experience with at least two SIEM platforms such as Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic.
  • Experience operating in a production detection and response environment.
  • Experience independently monitoring, validating, and escalating SIEM alerts using runbooks, SLAs, and severity thresholds.
  • Experience conducting structured, cyclical threat hunting using hypothesis-driven and behavior-based methods.
  • Ability to leverage threat intelligence to understand attack chains, threat actor tradecraft, and expected telemetry.
  • Experience developing and maintaining custom detection and threat-hunting queries in at least two SIEM platforms.
  • Experience identifying detection gaps, telemetry blind spots, and data quality issues and turning them into improved detections and documentation.
  • Strong communication, organizational, problem-solving, and documentation skills.
  • Ability to work independently and as part of a team in fast-paced environments.
  • Experience with a Detection-as-Code framework.
  • Experience working in NIST 800-53 environments.
  • At least one required certification: Splunk Enterprise Certified Administrator, Splunk Enterprise Security Certified Administrator, SumoLogic Administrator, Microsoft Security Operations Associate, or Elastic Stack Certified Administrator.
  • Preferred: consulting or professional services background.
  • Preferred: automation experience with GitLab or GitHub using Terraform and Ansible.
  • Preferred: familiarity with FedRAMP, FISMA, HIPAA, HITRUST, PCI, and similar regulatory standards.

Benefits

  • Flexible work model with the ability to work from home or the office.
  • Paid parental leave.
  • Flexible time off.
  • Certification and training reimbursement.
  • Digital mental health and wellbeing support membership.
  • Comprehensive insurance options.
  • Employee resource groups and in-person and virtual events.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Screening Analyst

Qonto 1K-5K Banks

Qonto is hiring a Screening Analyst to support its Financial Crime team in protecting customers and ensuring compliant operations across European markets.

Swift
52 minutes ago

Senior Detection & Response Analyst

Toyota Tsusho Systems 51-250 IT Services

Toyota Tsusho Systems US, Inc. is hiring a Senior Detection and Response Analyst to support its Regional Security Operations program by providing 24x7 security monitoring, incident handling, and threat response.

Active Directory Cybersecurity DNS HTTP Sentinel Splunk
1 hour, 22 minutes ago

Risk Investigator - Third Party/ATO Fraud

Mercury 251-1K Banks

Mercury is hiring a Fraud Investigator to lead account takeover investigations within its Account Fraud team, coordinating response and recovery for high-risk customer security incidents.

1 hour, 52 minutes ago

SOC Analyst

ClearCapital.com, 1-10 Real Estate

Clear Capital is hiring a SOC Analyst to protect its on-premises and cloud environments through security monitoring, incident response, threat hunting, and vulnerability advisory work.

Active Directory DNS Linux macOS OAuth SAML SIEM
2 hours, 7 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers