Remotery

Detection and Response Engineer

atCoalfireRemoteUS flagUnited StatesFull-timeEngineerJuniorMid-level$80k – $134k/year

Posted 5 hours ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Gather, analyze, and implement threat intelligence to enhance proactive detection and threat-hunting initiatives, leading to measurable improvements in security posture within client environments.

• Create, refine, and sustain custom detection and threat-hunting queries across multiple SIEM platforms, fine-tuning alerts for enhanced accuracy and developing dashboards and saved searches that facilitate repeatable, operational use cases.

• Organize and oversee cyclical, hypothesis-driven threat hunts utilizing threat intelligence and behavior-based analytics; pinpoint detection deficiencies and telemetry blind spots, and convert hunt results into detection enhancements, alert adjustments, and revised runbooks.


⛳️ Requirements

• 2–4 years of experience in large-scale enterprise security environments, including familiarity with cloud-hosted or hybrid infrastructures.

• Fundamental working knowledge of at least one major cloud platform (Azure, AWS, or GCP) and the application of cloud telemetry for security monitoring and investigations.

• Practical experience with at least two SIEM platforms (e.g., Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic) in a production detection and response setting.

• Proven capability to independently monitor, validate, and escalate SIEM alerts according to established runbooks, SLAs, and severity thresholds.

• Demonstrated ability to autonomously investigate and address security alerts, conducting in-depth analysis across various log sources to assess scope, root cause, and impact.

• Experience in escalating confirmed or high-confidence incidents with clear timelines, evidence, and MITRE ATT&CK mapping to Incident Response teams or senior engineers.

• Background in conducting structured and cyclical threat-hunting activities using hypothesis-driven and behavior-based methodologies.

• Skill in leveraging threat intelligence to comprehend threat actor tactics, attack chains, and anticipated telemetry, applying this knowledge to investigations and hunts.

• Hands-on experience in developing, refining, and maintaining custom detection and threat-hunting queries across at least two SIEM platforms, translating investigative needs into efficient, reusable query logic.

• Experience in identifying detection gaps, telemetry blind spots, and data quality challenges, and converting findings into alert tuning, new detection logic, dashboards, and updated runbooks or SOPs.

• Excellent communication, organizational, and problem-solving abilities, with proficiency in articulating complex technical information clearly.

• Strong documentation skills for producing technical diagrams, written descriptions, and other supporting materials.

• Proven ability to work both independently and collaboratively within a team, maintaining a professional attitude and demeanor.

• Critical thinking skills to balance comprehensive security requirements with mission objectives.

• Established record of quickly and effectively adapting in fast-paced, dynamic environments.

• Experience utilizing a Detection-as-Code framework.

• Familiarity with NIST 800-53 environments.

**__REQUIRED CERTIFICATIONS:__**

• At least one of the following:

• Splunk Enterprise Certified Administrator

• Splunk Enterprise Security Certified Administrator

• SumoLogic Administrator

• Microsoft Security Operations Associate

• Elastic Stack Certified Administrator


🏝️ Benefits

• Paid parental leave

• Flexible time off

• Certification and training reimbursement

• Digital mental health and wellbeing support membership

• Comprehensive insurance options

People also viewed

Lumata Health5 hours ago

Principal Engineer

US flagOklahoma OnlyFull-timeEngineer$148k – $187k/year
ApplyView job
Interview Pen5 hours ago

Interview Engineer

BG flagBulgaria OnlyFreelanceEngineer
ApplyView job
Minuteman Security & Life Safety5 hours ago

CAD Engineer

US flagUnited States OnlyPart-timeEngineer$66.8k – $115.4k/year
ApplyView job
Samsara5 hours ago

Business Technology Engineer II

CA flagCanada OnlyFull-timeEngineer$101.6k – $131.4k/year
ApplyView job
Leidos5 hours ago

EPC Transmission Line Project Engineer

US flagUnited States OnlyFull-timeEngineer$92.3k – $166.8k/year
ApplyView job
FenX2 days ago

Factory Commissioning – Industrial Project Engineer

ES flagSpain OnlyFull-timeEngineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers