×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Detection and Response Engineer; SPLUNK

Job in Chicago, Cook County, Illinois, 60290, USA
Listing for: Coalfire Systems
Full Time position
Listed on 2026-10-05
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 80000 - 134000 USD Yearly USD 80000.00 134000.00 YEAR
Job Description & How to Apply Below
Position: Detection and Response Engineer (SPLUNK)

Coalfire Systems

Coalfire is an EEO employer. We celebrate diversity and are committed to respecting one another, embracing individual differences, and creating an inclusive environment for all employees.

Detection and Response Engineer (SPLUNK)
About Coalfire

Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Chicago, Illinois with offices across the U.S. and U.K., and we support clients around the world.

But that’s not who we are – that’s just what we do.

We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.

Why Join Us

We are seeking a Detection and Response Engineer to join our Defensive Services team, supporting SIEM monitoring and alerting, threat hunting, and purple team activities that help our clients meet both federal compliance and commercial security requirements. If you're passionate about defending organizations against evolving threats, driven to innovate, and thrive in a collaborative, high-performing environment, we'd love to have you on our team.

Join us in our mission to make the world a safer place through proactive cybersecurity and operational excellence.

What You'll Do
  • Collect, analyze, and operationalize threat intelligence to inform proactive detection and threat hunting activities, driving measurable security posture improvements across client environments.
  • Develop, optimize, and maintain custom detection and threat hunting queries across two or more SIEM platforms, tuning alerts for improved fidelity and building dashboards and saved searches that support repeatable, operational use cases.
  • Plan and lead cyclical, hypothesis driven threat hunts using threat intelligence and behavior based analytics; identify detection gaps and telemetry blind spots, and translate hunt outcomes into detection improvements, alert tuning, and updated runbooks.
What You'll Bring
  • 2–4 years of experience operating within large scale enterprise security environments, including exposure to cloud hosted or hybrid infrastructures.
  • Foundational working knowledge of at least one major cloud platform (Azure, AWS, or GCP) and how cloud telemetry is leveraged for security monitoring and investigations.
  • Handson experience with at least two SIEM platforms (e.g., Splunk, Microsoft Sentinel, ELK, Log Rhythm, or Sumo Logic) in a production detection and response environment.
  • Experience independently monitoring, validating, and escalating SIEM alerts in accordance with documented runbooks, SLAs, and severity thresholds.
  • Proven ability to independently investigate and respond to security alerts, performing deepdive analysis across multiple log sources to determine scope, root cause, and impact.
  • Experience escalating confirmed or high confidence incidents with clear timelines, evidence, and MITRE ATT&CK mapping to Incident Response teams or senior engineers.
  • Experience conducting structured and cyclical threat hunting activities using hypothesis driven and behavior based methodologies.
  • Ability to leverage threat intelligence to understand threat actor tradecraft, attack chains, and expected telemetry, and apply that knowledge to investigations and hunts.
  • Handson experience developing, optimizing, and maintaining custom detection and threat hunting queries in at least two SIEM platforms, and translating investigative requirements into performant, reusable query logic.
  • Experience identifying detection gaps, telemetry blind spots, and data quality issues, and…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary