Threat Detection & Response Engineer

Coalfire

Chicago (IL)

Hybrid

USD 80,000 - 134,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Paid parental leave
Certification and training reimburse-
Digital mental health and wellbeing
Comprehensive insurance options

Job summary

Coalfire is hiring a Detection and Response Engineer to join the Defensive Services team in Chicago. You will support SIEM monitoring, threat hunting, and purple team activities to meet federal compliance and commercial security requirements.

Responsibilities include building detection queries across multiple SIEMs, tuning alerts for fidelity, and leading cyclical hunts using threat intelligence and behavior-based analytics. Collaboration and strong communication are essential.

Qualifications

  • 2-4 years of experience in large-scale enterprise security environments.
  • Hands-on with at least two SIEM platforms in production detection and response.
  • Experience monitoring, validating, and escalating SIEM alerts per runbooks and SLAs.
  • Ability to investigate security alerts across multiple log sources.
  • Experience mapping incidents to MITRE ATT&CK and coordinating with IR teams.

Responsibilities

  • Collect and operationalize threat intelligence to drive threat hunts.
  • Develop, optimize, and maintain SIEM detection queries across platforms.
  • Lead hypothesis-driven threat hunts and update runbooks and telemetry.
  • Translate hunt outcomes into detection improvements and dashboards.

Skills

Threat hunting
SIEM
Incident response
Threat intelligence
Detection-as-Code
MITRE ATT&CK mapping
Dashboards
Runbooks
Communication
Documentation

Education

Splunk Enterprise Certified Administrator
Splunk Enterprise Security Certified Administrator
SumoLogic Administrator
Microsoft Security Operations Associate
Elastic Stack Certified Administrator

Tools

Splunk
Microsoft Sentinel
ELK
LogRhythm
Sumo Logic

Job description

Coalfire is hiring a Detection and Response Engineer to join the Defensive Services team in Chicago. You will support SIEM monitoring, threat hunting, and purple team activities to meet federal compliance and commercial security requirements.

Responsibilities include building detection queries across multiple SIEMs, tuning alerts for fidelity, and leading cyclical hunts using threat intelligence and behavior-based analytics. Collaboration and strong communication are essential.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Detection & Response Engineer
Threat Detection & Response Engineer

Coalfire- • Chicago (IL)

Hybrid
USD 80,000 - 134,000
Flexible work model
Paid parental leave
Certification reimbursement
+4
Detection & Response Engineer — Threat Hunting & SIEM Pro
Detection & Response Engineer — Threat Hunting & SIEM Pro

Coalfire • United States

Hybrid
USD 120,000 - 150,000
Flexible work model
Certification reimbursement
Comprehensive insurance options
+1
Detection and Response Engineer (SPLUNK)
Detection and Response Engineer (SPLUNK)

Coalfire • Chicago (IL)

Hybrid
USD 80,000 - 134,000
Paid parental leave
Certification and training reimburse-
Digital mental health and wellbeing
+1
Detection and Response Engineer (SPLUNK)
Detection and Response Engineer (SPLUNK)

Coalfire- • Chicago (IL)

Hybrid
USD 80,000 - 134,000
Flexible work model
Paid parental leave
Certification reimbursement
+4
Threat Detection & Response Engineer
Threat Detection & Response Engineer

United States Digital Space LLC • United States

Hybrid
USD 120,000 - 180,000
Paid parental leave
Certification reimbursement
Digital mental health support
+1
Threat Detection & Response Engineer
Threat Detection & Response Engineer

Hack Chicago • San Francisco (CA)

On-site
USD 230,000 - 260,000
Detection and Response Engineer (SPLUNK)
Detection and Response Engineer (SPLUNK)

Coalfire • United States

Hybrid
USD 120,000 - 150,000
Flexible work model
Certification reimbursement
Comprehensive insurance options
+1
Cloud Security Detection Engineer – IR & Threat Hunting
Cloud Security Detection Engineer – IR & Threat Hunting

IBM • Lowell (MA)

On-site
USD 140,000 - 190,000
DFIR Engineer II: Incident Response & Threat Hunting
DFIR Engineer II: Incident Response & Threat Hunting

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 89,000 - 134,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
Staff Security Engineer: Detection & Response Leader
Staff Security Engineer: Detection & Response Leader

IBM • Tucson (AZ)

On-site
USD 140,000 - 190,000