Coalition Logo

Coalition

Senior Threat Engineer

Posted 18 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in United Kingdom
Senior level
Remote
Hiring Remotely in United Kingdom
Senior level
Design and implement scalable detections, enrichment, triage logic, and automated response workflows for the Wirespeed Verdict Engine. Own complex threat detection problem spaces from investigation through implementation and iteration, analyze operational data to reduce false positives/negatives and latency, mentor teammates, and partner with product, engineering, and security to improve platform capabilities and customer outcomes.
The summary above was generated by AI
About us

Coalition is the world's first Active Insurance provider designed to help prevent digital risk before it strikes. Founded in 2017, Coalition combines comprehensive insurance coverage and innovative cybersecurity tools to help businesses manage and mitigate potential cyberattacks.   

Opportunities to make an impact with bold thinking are real—and happening daily at Coalition.

About the role

A Senior Threat Engineer builds and improves systems, logic, and workflows that allow Coalition’s Wirespeed Verdict Engine to make high-precision security decisions at scale.

Disclaimer: This is not a traditional SOC analyst role.

Success in this position is not defined by working one alert at a time, but by figuring out how to handle thousands of similar situations better, faster, and more consistently through automation, patterning, and engineering. Key focus will be studying how investigations should work, identifying repeatable decision points, and turning that thinking into detections, enrichment, triage logic, and automated response workflows.

As a senior member of the team, you'll be expected to take ownership of complex problem areas, exercise strong judgment in ambiguous situations, and help shape how the broader Threat Engineering function operates. This role is for someone who can bridge threat detection, engineering, and customer experience. Its ideal for someone who is more interesting asking, “How should this entire class of problem be solved?” rather than, “How do I close the next alert in the queue?”

If you are excited by designing systems that scale expert judgment, improving both customer outcomes and operational efficiency, and doing work that looks very different from a conventional analyst job, this role is for you.

Responsibilities
  • Design, build, and improve the detection, decisioning, and response workflows that power the Wirespeed Verdict Engine
  • Own complex threat detection and workflow problem spaces from investigation concept through implementation, validation, and iteration
  • Translate investigative thinking and threat research into scalable detections, enrichment, triage logic, and automated decisions that improve speed, accuracy, reliability, and customer outcomes
  • Analyze operational data to identify false positives, false negatives, latency issues, and opportunities to improve how entire categories of work are handled
  • Continuously raise the ceiling of what the system can do autonomously, reducing manual review while improving service quality and consistency
  • Support especially complex or novel cases when needed, then feed those lessons back into the system so similar situations can be handled better in the future
  • Keep the customer experience front and center by ensuring Wirespeed outputs are clear, helpful, accurate, and appropriately calibrated to the customer’s situation
  • Identify patterns in customer pain, confusion, or friction and use those insights to improve verdict logic, response content, and overall product behavior
  • Partner closely with product, engineering, and security teams to improve platform capabilities, data quality, and operational leverage
  • Help define best practices, operating principles, and technical standards for Threat Engineering work
  • Document detection concepts, workflow logic, and operating principles so the team can scale knowledge
  • Provide technical leadership through strong execution, sound judgment, and mentorship of less experienced teammates
Skills and Qualifications
  • Significant experience in cybersecurity operations such as threat detection and response, detection engineering, incident response, threat hunting, or SOC operations
  • You look for repeatable patterns, clear decision logic, and ways to scale good judgment through automation rather than repeated manual work
  • Strong investigative and analytical skills, with the ability to turn ambiguous signals and messy operational problems into practical detection logic and workflow improvements
  • Experience building, tuning, or maintaining automations, detections, playbooks, rules, or enrichment pipelines in security tooling
  • Demonstrated ability to independently own complex technical or operational problem areas, step into ambiguity, and drive them to better outcomes
  • Interest in work that is different from a traditional analyst role: improving how work gets done rather than only executing it yourself
  • Strong written and verbal communication skills, including the ability to document logic and explain threats, tradeoffs, and outcomes clearly to customers and internal partnersAbility to work closely with product, engineering, and security stakeholders
  • Comfort using data to evaluate detection quality, workflow performance, and where the system needs improvement
  • Preference for simple, scalable solutions and willingness to reduce unnecessary complexity or manual work
Bonus Points 
  • Experience working in high-volume security operations environment
  • Significant experience with detection and response tooling such as SIEM, EDR, SOAR, case management, and telemetry enrichment systems
  • Familiarity writing scripts or queries to support investigations, automation, or workflow analysis
  • Experience improving operational quality through experimentation, measurement, and continuous iteration
  • Experience in workflow design, detection engineering, automation, or security product development
  • Experience mentoring fellow engineers, setting technical direction, or influencing how a team approaches detection and response problems
Perks
  • 100% medical coverage, including outpatient care
  • Life insurance 
  • 25+ paid holidays
  • Annual home office stipend
  • 7% employer pension contribution
  • Mental and physical health wellness programs like Headspace, Wellhub
  • Competitive compensation and opportunity for advancement
Why Coalition? 

Work at Coalition is centered on the joint mission to Protect the Unprotected. We have built a remote-first, highly inclusive culture that welcomes people from diverse backgrounds. We trust each other to take responsibility, share ownership of outcomes, and put in the work together to protect businesses from digital risk. Coalition’s exceptional growth stems from its ability to address real-world problems for organizations of all sizes while remaining true to our founding values of character, humility, responsibility, purpose, authenticity, and inclusion.

We’re always looking for collaborative, inquisitive individuals to join #OurCoalition.

Visit our Newsroom > 

Privacy Notice

Coalition is committed to protecting your privacy and handling your personal information responsibly. We collect, use, and store personal information as necessary for the recruitment process and in compliance with applicable privacy laws and regulations in all regions where we operate. We want you to understand what personal information we collect, how we use it, and your rights regarding access, correction, and deletion of your data where applicable. Information submitted, collected, and processed as part of your application is subject to Coalition's Privacy Policy. For further details, please review our full Privacy Policy or contact us with any questions regarding how your information is handled.

Our Privacy Policy > 

Safe Hiring Notice

All legitimate communication from Coalition comes from @coalitioninc.com emails, and open roles are listed only on our Careers page. We never ask for payment, banking details, or personal identification before an offer is accepted through our secure systems. If you believe you’ve been a victim of fraudulent recruiting, follow guidance from the Federal Trade Commission (FTC).

Anti-Discrimination Notice

Coalition is proud to be an Equal Opportunity employer. Our policy is to provide equal employment opportunities to all individuals, without discrimination or harassment on the basis of any characteristic protected by applicable laws in each country where we operate. This commitment includes, but is not limited to, ensuring equal treatment in recruitment, selection, training, promotion, transfer, compensation, and all other aspects of employment. Coalition does not tolerate discrimination or harassment of any kind, and we are dedicated to fostering an inclusive and supportive workplace.

Accommodations

Coalition is committed to providing reasonable accommodations to qualified individuals with disabilities, including applicants and employees, in accordance with applicable laws and regulations in each country where we operate. Our policy is to support equal opportunity in the hiring process by considering qualified applicants regardless of disability or other protected characteristics, unless providing accommodation would impose an undue hardship or disproportionate burden. If you require accommodation to complete an application, interview, pre-employment testing, or participate in the selection process, please contact us at [email protected]. We also consider all qualified applicants, including those with criminal histories, in line with applicable laws and regulations in each jurisdiction.

To all recruitment agencies: Coalition does not accept unsolicited agency resumes. Do not forward resumes to our email alias, employees, or other physical or virtual organization locations. Coalition is not responsible for any fees related to unsolicited resumes.

Similar Jobs

16 Hours Ago
Remote
United Kingdom
Junior
Junior
Cybersecurity
As a Commercial/Enterprise BDR, you'll generate strategic outbound opportunities and manage incoming leads, establishing groundwork for successful sales engagements in the EMEA region. You will develop skills in pipeline generation and collaborate with marketing and sales teams.
Top Skills: Linkedin Sales NavigatorOutreachSalesforce
16 Hours Ago
Remote
UK
Junior
Junior
Cloud • Software
Drive new logo revenue by researching prospects, executing multi-channel outbound campaigns, qualifying leads, and setting first meetings. Personalize messaging for technical and business buyers, maintain CRM data in HubSpot, and collaborate with Sales to build pipeline.
Top Skills: HubspotLinkedin NavigatorNetboxNetbox CloudNetbox EnterpriseNetwork AutomationOrbSalesloftZoominfo
16 Hours Ago
Easy Apply
Remote or Hybrid
UK
Easy Apply
Expert/Leader
Expert/Leader
Cloud • Information Technology • Security • Software • Cybersecurity
Lead and scale an AI Security incubation team to drive technical GTM strategy, recruit and mentor principal AI security specialists, enable global sales with repeatable POVs and playbooks, advise Fortune 500 C-levels on safe AI deployments, and feed field insights into Product and Engineering to drive revenue growth.
Top Skills: Agentic ArchitecturesCloud-Native SecurityData Loss Prevention (Dlp)LlmsMcpPrompt WorkflowsPublic Cloud ArchitectureRagZero Trust ArchitectureZscaler Zero Trust Exchange

What you need to know about the Belfast Tech Scene

If asked to name the birthplace of the RMS Titanic, you might not say Belfast. Similarly, if asked to name Europe's leading destination for foreign direct investment in new software development, Belfast might not come to mind. Yet, both are true. The city has emerged as a tech powerhouse, recently ranked among the best in the U.K. for tech careers — especially for software developers. It also leads the U.K. with the highest percentage of software development jobs advertised.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account