检测与响应工程师
Detection and Response Engineer
关于Coalfire
Coalfire致力于通过解决客户最困难的网络安全挑战,使世界变得更安全。我们处于技术的最前沿,为客户提供咨询、评估、自动化,并最终帮助公司应对不断变化的网络安全环境。我们总部位于伊利诺伊州芝加哥,美国和英国各地都有办公室,我们为全球客户提供支持。
但这只是我们的工作——这并不是我们是谁。
我们是思想领袖、顾问和网络安全专家,但最重要的是,我们是一支充满热情的问题解决者团队,他们渴望学习、成长并带来改变。
为什么加入我们
我们正在寻找一名检测与响应工程师加入我们的防御服务团队,支持SIEM监控和警报、威胁狩猎以及紫色团队活动,帮助我们的客户满足联邦合规性和商业安全要求。如果你热衷于防御不断演变的威胁,有创新动力,并且在协作、高绩效的环境中茁壮成长,我们希望你加入我们的团队。加入我们,通过主动的网络安全和卓越的运营,让世界变得更安全。
你将负责
- 收集、分析并操作威胁情报,以指导主动检测和威胁狩猎活动,推动客户环境中的可衡量安全态势改进。
- 开发、优化和维护跨两个或更多SIEM平台的定制检测和威胁狩猎查询,调整警报以提高准确性,并构建仪表板和保存的搜索,以支持可重复的操作用例。
- 计划并领导周期性、基于假设的威胁狩猎,使用威胁情报和基于行为的分析;识别检测盲点和遥测盲区,并将狩猎结果转化为检测改进、警报调优和更新的运行手册。
你将带来的能力
- 在大型企业安全环境中工作的2–4年经验,包括对云托管或混合基础设施的接触。
- 至少一个主要云平台(Azure、AWS或GCP)的基础知识,以及如何利用云遥测进行安全监控和调查。
- 在生产环境的检测与响应中,至少使用过两个SIEM平台(如Splunk、Microsoft Sentinel、ELK、LogRhythm或Sumo Logic)的实际经验。
- 独立监控、验证和分析安全事件的经验,能够快速识别潜在威胁并采取行动。
查看英文原文
About Coalfire
Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Chicago, Illinois with offices across the U.S. and U.K., and we support clients around the world.
But that’s not who we are – that’s just what we do.
We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.
Why Join Us
We are seeking a Detection and Response Engineer to join our Defensive Services team, supporting SIEM monitoring and alerting, threat hunting, and purple team activities that help our clients meet both federal compliance and commercial security requirements. If you're passionate about defending organizations against evolving threats, driven to innovate, and thrive in a collaborative, high-performing environment, we'd love to have you on our team. Join us in our mission to make the world a safer place through proactive cybersecurity and operational excellence.
What You'll Do
- Collect, analyze, and operationalize threat intelligence to inform proactive detection and threat‑hunting activities, driving measurable security posture improvements across client environments.
- Develop, optimize, and maintain custom detection and threat‑hunting queries across two or more SIEM platforms, tuning alerts for improved fidelity and building dashboards and saved searches that support repeatable, operational use cases.
- Plan and lead cyclical, hypothesis‑driven threat hunts using threat intelligence and behavior‑based analytics; identify detection gaps and telemetry blind spots, and translate hunt outcomes into detection improvements, alert tuning, and updated runbooks.
What You'll Bring
- 2–4 years of experience operating within large‑scale enterprise security environments, including exposure to cloud‑hosted or hybrid infrastructures.
- Foundational working knowledge of at least one major cloud platform (Azure, AWS, or GCP) and how cloud telemetry is leveraged for security monitoring and investigations.
- Hands‑on experience with at least two SIEM platforms (e.g., Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic) in a production detection and response environment.
- Experience independently monitoring, validating, and escalating SIEM alerts in accordance with documented runbooks, SLAs, and severity thresholds.
- Proven ability to independently investigate and respond to security alerts, performing deep‑dive analysis across multiple log sources to determine scope, root cause, and impact.
- Experience escalating confirmed or high‑confidence incidents with clear timelines, evidence, and MITRE ATT&CK mapping to Incident Response teams or senior engineers.
- Experience conducting structured and cyclical threat‑hunting activities using hypothesis‑driven and behavior‑based methodologies.
- Ability to leverage threat intelligence to understand threat actor tradecraft, attack chains, and expected telemetry, and apply that knowledge to investigations and hunts.
- Hands‑on experience developing, optimizing, and maintaining custom detection and threat‑hunting queries in at least two SIEM platforms, and translating investigative requirements into performant, reusable query logic.
- Experience identifying detection gaps, telemetry blind spots, and data quality issues, and translating findings into alert tuning, new detection logic, dashboards, and updated runbooks or SOPs.
- Excellent communication, organizational, and problem-solving skills, with the ability to convey complex technical information clearly.
- Strong documentation skills for creating technical diagrams, written descriptions, and other supporting materials.
- Demonstrated ability to work both independently and as a member of a team, maintaining a professional attitude and demeanor.
- Critical thinking skills to balance robust security requirements against mission objectives.
- Proven track record of adapting quickly and efficiently in fast-paced, dynamic environments.
- Experience utilizing a Detection-as-Code framework
- Experience working with NIST 800-53 environments
REQUIRED CERTIFICATIONS:
At least one of the following:
- Splunk Enterprise Certified Administrator
- Splunk Enterprise Security Certified Administrator
- SumoLogic Administrator
- Microsoft Security Operations Associate
- Elastic Stack Certified Administrator
Bonus Points
- Professional services background: Prior experience supporting external clients from within a consulting or professional services organization.
- Automation capabilities: Experience automating workflows in GitLab or GitHub with Terraform and Ansible.
- Compliance frameworks: Understanding of FedRAMP, FISMA, HIPAA, HITRUST, PCI, and similar regulatory standards.
Why You’ll Want to Join Us
At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office.
Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.
At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, contact our Human Resources team at .
Originally posted on Himalayas