Detection and Response Engineer (SPLUNK)
Coalfire - United States
Hiring: Detection and Response Engineer (SPLUNK) Company: Coalfire Location: United States Job Posted Time: 2026-09-10 13:30:22 Employment Type: Hybrid Target Skills & Keywords : AWS, Ansible, Azure, ELK Stack, FedRAMP, GCP, GitHub, GitLab, HIPAA, SIEM, Splunk, Terraform About the job Experience: •4 years of experience operating within large‑scale enterprise security environments, including exposure to cloud‑hosted or hybrid infrastructures Required Skills: •Collect, analyze, and operationalize threat intelligence to inform proactive detection and threat‑hunting activities, driving measurable security posture improvements across client environments •Develop, optimize, and maintain custom detection and threat‑hunting queries across two or more SIEM platforms, tuning alerts for improved fidelity and building dashboards and saved searches that support repeatable, operational use cases •Plan and lead cyclical, hypothesis‑driven threat hunts using threat intelligence and behavior‑based analytics; identify detection gaps and telemetry blind spots, and translate hunt outcomes into detection improvements, alert tuning, and updated runbooks. Qualifications: •2–4 years of experience operating within large‑scale enterprise security environments, including exposure to cloud‑hosted or hybrid infrastructures •Foundational working knowledge of at least one major cloud platform (Azure, AWS, or GCP) and how cloud telemetry is leveraged for security monitoring and investigations •Hands‑on experience with at least two SIEM platforms (e.g., Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic) in a production detection and response environment •Proven ability to independently investigate and respond to security alerts, performing deep‑dive analysis across multiple log sources to determine scope, root cause, and impact •Demonstrated capacity to leverage threat intelligence to understand threat actor tradecraft, attack chains, and expected telemetry, and apply that knowledge to investigations and hunts •Hands‑on experience developing, optimizing, and maintaining custom detection and threat‑hunting queries in at least two SIEM platforms, and translating investigative requirements into performant, reusable query logic •Excellent communication, organizational, and problem-solving skills, with the ability to convey complex technical information clearly •Strong documentation skills for creating technical diagrams, written descriptions, and other supporting materials •Demonstrated ability to work both independently and as a member of a team, maintaining a professional attitude and demeanor •Critical thinking skills to balance robust security requirements against mission objectives Compensation: •$80,000 - $134,000 / year Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!