Detection and Response Engineer (SPLUNK)

Coalfire Systems

Chicago (IL)

Hybrid

USD 80,000 - 134,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Coalfire Systems is seeking a Detection and Response Engineer to join our Defensive Services team, focusing on SIEM monitoring, threat hunting, and purple team activities to meet federal and commercial security requirements.

Work closely with clients and internal teams to develop detections, tune alerts, and improve security posture across environments. The role emphasizes proactive defense, threat intelligence use, and incident response collaboration.

Qualifications

  • Experience in threat intel collection, validation, and operationalization for detections.
  • Hands-on in developing and tuning queries across multiple SIEMs in production.
  • Ability to lead threat hunts and map findings to MITRE ATT&CK and runbooks.

Responsibilities

  • Collect, analyze, and operationalize threat intel to drive proactive detection and hunts.
  • Develop, optimize, and maintain SIEM queries, dashboards, and alerts.
  • Plan and lead hypothesis-driven threat hunts; translate outcomes into improvements and runbooks.

Skills

Threat intelligence
SIEM monitoring
Threat hunting
Query development
Incident response
Documentation
Communication
Collaboration
MITRE ATT&CK
Detection as Code

Education

Splunk Enterprise Certified Administrator
Splunk Enterprise Security Certified Administrator
SumoLogic Administrator
Microsoft Security Operations Associate
Elastic Stack Certified Administrator

Tools

Splunk
Microsoft Sentinel
ELK stack
Sumo Logic
Terraform
Ansible

Job description

Coalfire Systems

Coalfire is an EEO employer. We celebrate diversity and are committed to respecting one another, embracing individual differences, and creating an inclusive environment for all employees.

Detection and Response Engineer (SPLUNK)
About Coalfire

Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Chicago, Illinois with offices across the U.S. and U.K., and we support clients around the world.

But that’s not who we are – that’s just what we do.

We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.

Why Join Us

We are seeking a Detection and Response Engineer to join our Defensive Services team, supporting SIEM monitoring and alerting, threat hunting, and purple team activities that help our clients meet both federal compliance and commercial security requirements. If you're passionate about defending organizations against evolving threats, driven to innovate, and thrive in a collaborative, high-performing environment, we'd love to have you on our team. Join us in our mission to make the world a safer place through proactive cybersecurity and operational excellence.

What You'll Do
  • Collect, analyze, and operationalize threat intelligence to inform proactive detection and threathunting activities, driving measurable security posture improvements across client environments.
  • Develop, optimize, and maintain custom detection and threathunting queries across two or more SIEM platforms, tuning alerts for improved fidelity and building dashboards and saved searches that support repeatable, operational use cases.
  • Plan and lead cyclical, hypothesisdriven threat hunts using threat intelligence and behaviorbased analytics; identify detection gaps and telemetry blind spots, and translate hunt outcomes into detection improvements, alert tuning, and updated runbooks.
What You'll Bring
  • 2–4 years of experience operating within largescale enterprise security environments, including exposure to cloudhosted or hybrid infrastructures.
  • Foundational working knowledge of at least one major cloud platform (Azure, AWS, or GCP) and how cloud telemetry is leveraged for security monitoring and investigations.
  • Handson experience with at least two SIEM platforms (e.g., Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic) in a production detection and response environment.
  • Experience independently monitoring, validating, and escalating SIEM alerts in accordance with documented runbooks, SLAs, and severity thresholds.
  • Proven ability to independently investigate and respond to security alerts, performing deepdive analysis across multiple log sources to determine scope, root cause, and impact.
  • Experience escalating confirmed or highconfidence incidents with clear timelines, evidence, and MITRE ATT&CK mapping to Incident Response teams or senior engineers.
  • Experience conducting structured and cyclical threathunting activities using hypothesisdriven and behaviorbased methodologies.
  • Ability to leverage threat intelligence to understand threat actor tradecraft, attack chains, and expected telemetry, and apply that knowledge to investigations and hunts.
  • Handson experience developing, optimizing, and maintaining custom detection and threathunting queries in at least two SIEM platforms, and translating investigative requirements into performant, reusable query logic.
  • Experience identifying detection gaps, telemetry blind spots, and data quality issues, and translating findings into alert tuning, new detection logic, dashboards, and updated runbooks or SOPs.
  • Excellent communication, organizational, and problem-solving skills, with the ability to convey complex technical information clearly.
  • Strong documentation skills for creating technical diagrams, written descriptions, and other supporting materials.
  • Demonstrated ability to work both independently and as a member of a team, maintaining a professional attitude and demeanor.
  • Critical thinking skills to balance robust security requirements against mission objectives.
  • Proven track record of adapting quickly and efficiently in fast-paced, dynamic environments.
  • Experience utilizing a Detection-as-Code framework
  • Experience working with NIST 800-53 environments
Required Certifications

At least one of the following:

  • Splunk Enterprise Certified Administrator
  • Splunk Enterprise Security Certified Administrator
  • SumoLogic Administrator
  • Microsoft Security Operations Associate
  • Elastic Stack Certified Administrator
Bonus Points
  • Professional services background: Prior experience supporting external clients from within a consulting or professional services organization.
  • Automation capabilities: Experience automating workflows in GitLab or GitHub with Terraform and Ansible.
  • Compliance frameworks: Understanding of FedRAMP, FISMA, HIPAA, HITRUST, PCI, and similar regulatory standards.

The salary range listed is a reasonable estimate of the compensation range for this role based on national salary averages. The actual salary offer to the successful candidate will be based on job-related education, geographic location, training, licensure and certifications and other factors. You may also be eligible to participate in annual incentive, commission, and/or recognition programs.

Why You'll Want to Join Us

At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office.

Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.

At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, contact our Human Resources team at HumanResourcesMB@coalfire.com.

$80,000 - $134,000 a year

Equal employment opportunity, including veterans and individuals with disabilities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection and Response Engineer (SPLUNK)
Detection and Response Engineer (SPLUNK)

Coalfire • United States

Hybrid
USD 120,000 - 150,000
Flexible work model
Certification reimbursement
Comprehensive insurance options
+1
Senior SIEM Engineer
Senior SIEM Engineer

Coalfire • Northern (KY)

Hybrid
USD 85,000 - 141,000
Flexible work model
Parental leave
Certification reimbursement
+1
Senior SIEM Engineer
Senior SIEM Engineer

Coalfire • United States

Hybrid
USD 120,000 - 180,000
Paid parental leave
Certification reimbursement
Flexible work model
+1
SIEM Detection & Threat Hunting Engineer (Splunk)
SIEM Detection & Threat Hunting Engineer (Splunk)

Coalfire Systems • Chicago (IL)

Hybrid
USD 80,000 - 134,000
Security Operations Center Analyst
Security Operations Center Analyst

Coalfire Federal • Denver (CO)

On-site
USD 96,000 - 154,000
Parental leave
Flexible time off
Certification reimbursement
+2
Detection & Response Engineer — Threat Hunting & SIEM Pro
Detection & Response Engineer — Threat Hunting & SIEM Pro

Coalfire • United States

Hybrid
USD 120,000 - 150,000
Flexible work model
Certification reimbursement
Comprehensive insurance options
+1
Principal Cloud Engineer
Principal Cloud Engineer

Coalfire • United States

Hybrid
USD 109,000 - 182,000
Flexible work model
Competitive benefits
Paid parental leave
+1
Senior Consultant, FedRAMP Assessment
Senior Consultant, FedRAMP Assessment

Coalfire • United States

On-site
USD 86,000 - 148,000
Paid parental leave
Flexible time off
Certification and training reimbursement
Senior Consultant, Application Security
Senior Consultant, Application Security

Coalfire • United States

Hybrid
USD 100,000 - 130,000
Paid parental leave
Flexible time off
Training reimbursement
+2
Cloud Operations Engineer
Cloud Operations Engineer

Coalfire • United States

Hybrid
USD 64,000 - 112,000
Flexible work model
Paid parental leave
Flexible time off
+3