Coalition

Senior Threat Engineer

Coalition
Apply
2 months ago
Remote, United KingdomSenior
H1B Sponsor

Responsibilities

  • Design, build, and improve detection, decisioning, and response workflows for the Wirespeed Verdict Engine.
  • Own complex threat detection and workflow problems from investigation concept through implementation, validation, and iteration.
  • Translate threat research and investigative thinking into scalable detections, enrichment, triage logic, and automated decisions.
  • Analyze operational data to identify false positives, false negatives, latency issues, and opportunities to improve entire categories of work.
  • Increase system autonomy while reducing manual review and maintaining service quality and consistency.
  • Support complex or novel cases and feed resulting lessons back into the system.
  • Improve customer-facing verdict clarity, accuracy, helpfulness, and calibration.
  • Use customer pain, confusion, and friction patterns to improve verdict logic, response content, and product behavior.
  • Partner with product, engineering, and security teams to improve platform capabilities, data quality, and operational leverage.
  • Define best practices, operating principles, and technical standards for Threat Engineering.
  • Document detection concepts, workflow logic, and operating principles.
  • Provide technical leadership, execute with sound judgment, and mentor less experienced teammates.

Requirements

  • Significant experience in cybersecurity operations, such as threat detection and response, detection engineering, incident response, threat hunting, or SOC operations.
  • Experience building, tuning, or maintaining security automations, detections, playbooks, rules, or enrichment pipelines.
  • Strong investigative and analytical skills, including the ability to convert ambiguous signals and operational problems into practical detection logic and workflow improvements.
  • Ability to independently own complex technical or operational problem areas and drive them to improved outcomes.
  • Strong written and verbal communication skills, including documenting logic and explaining threats, tradeoffs, and outcomes to customers and internal partners.
  • Ability to work closely with product, engineering, and security stakeholders and use data to evaluate detection quality and workflow performance.
  • Experience in high-volume security operations environments is a bonus.
  • Experience with SIEM, EDR, SOAR, case management, and telemetry enrichment systems is a bonus.
  • Familiarity with writing scripts or queries for investigations, automation, or workflow analysis is a bonus.
  • Experience with workflow design, detection engineering, automation, or security product development is a bonus.
  • Experience mentoring engineers, setting technical direction, or influencing detection and response practices is a bonus.

Benefits

  • 100% medical coverage, including outpatient care
  • Life insurance
  • 25+ paid holidays
  • Annual home office stipend
  • 7% employer pension contribution
  • Mental and physical health wellness programs including Headspace and Wellhub
  • Remote-first work culture
  • Competitive compensation and opportunity for advancement

Categories

Coalition

About Coalition

501-1,000 employees

Coalition is the world's first Active Insurance provider designed to help prevent digital risk before it strikes. By combining comprehensive insurance coverage and cybersecurity tools, Coalition helps businesses manage and mitigate potential cyber attacks. Coalition offers its Active Insurance products to policyholders in the U.S., the U.K., Canada, and Australia through Coalition’s relationships with leading global insurers and cyber capacity through its own carrier, Coalition Insurance Company. Coalition also provides automated cyber alerts, expert guidance and advice, and third-party risk management to businesses worldwide through its holistic cyber risk management platform, Coalition Control. Coalition also offers Wirespeed Managed Detection & Response, a 24/7 fully automated MDR that initiates mitigation in milliseconds to shut down threats before they can wreak havoc.