Overview
As a Senior Threat Engineer, you design and scale detection and response workflows for Coalition’s Wirespeed Verdict Engine. You own complex threat detection domains, turning investigations into scalable detections and automated decisions. You bridge threat detection, engineering, and customer experience to improve speed, accuracy, and outcomes. You shape Threat Engineering practices and mentor teammates, tackling high-impact problems at scale.
Pay / Benefits
- 100% medical coverage, including outpatient care
- Life insurance
- 25+ paid holidays
- Annual home office stipend
- 7% employer pension contribution
- Mental and physical health wellness programs
Responsibilities
- Design, build, and improve detection, decisioning, and response workflows powering the Wirespeed Verdict Engine
- Own complex threat detection and workflow areas from concept through implementation and iteration
- Translate investigations into scalable detections, enrichment, triage logic, and automated decisions
- Analyze operational data to reduce false positives/negatives and latency, improve handling of categories of work
- Increase autonomous capabilities of the system while maintaining service quality and consistency
- Support complex or novel cases and feed lessons back into the system
- Ensure outputs are clear, helpful, accurate, and appropriately calibrated to customer situations
- Identify patterns in customer pain to improve verdict logic and product behavior
- Collaborate with product, engineering, and security teams to enhance platform capabilities and data quality
- Define best practices, operating principles, and technical standards for Threat Engineering
- Document detection concepts and workflow logic to scale knowledge
- Provide technical leadership and mentorship to less experienced teammates
Key requirements
- Significant experience in cybersecurity operations (threat detection/response, detection engineering, incident response, threat hunting, or SOC operations)
- Ability to identify repeatable patterns and automate judgment to scale without manual work
- Strong investigative/analytical skills to convert signals into practical detection logic
- Experience building or maintaining automations, detections, playbooks, rules, or enrichment pipelines
- Proven ability to own complex technical problems and drive outcomes in ambiguity
- Interest in non-traditional analyst work focused on improving processes
- Strong written and verbal communication to document logic and explain threats to customers and partners
- Comfort using data to evaluate detection quality and workflow performance
- Preference for simple, scalable solutions
- strong communication
- collaboration
- mentorship
- threat detection and response tooling
- automation, detection engineering, or enrichment pipelines
- data-driven workflow analysis
…
