Coalition

Senior Threat Engineer

Coalition$106K — $148K *
US-AnywhereRemote in Canada
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Significant experience in cybersecurity operations, including threat detection and incident response.
  • Ability to identify repeatable patterns and automate decision-making processes.
  • Strong investigative skills to translate ambiguous signals into practical solutions.
  • Experience with security tooling automation and detection systems.
  • Demonstrated ownership of complex technical challenges and improving processes.
  • Interest in improving workflows beyond traditional analyst functions.
  • Excellent communication skills to document and convey technical concepts clearly.

Responsibilities

  • Design and enhance workflows for the Wirespeed Verdict Engine.
  • Own and innovate within complex threat detection and response areas.
  • Transform investigative insights into scalable automation and decision-making processes.
  • Analyze operational data to reduce false positives and latency.
  • Continuously enhance system capabilities to minimize manual review.
  • Support complex cases while feeding insights back into the system for improvement.
  • Foster robust customer experiences by refining output clarity and accuracy.

Benefits

  • 100% medical, dental, and vision coverage
  • Flexible PTO
  • Annual home office stipend and WeWork access
  • Mental and physical wellness programs like Headspace
  • Competitive compensation with potential for career advancement.
Full Job Description
About the role

A Senior Threat Engineer builds and improves systems, logic, and workflows that allow Coalition's Wirespeed Verdict Engine to make high-precision security decisions at scale.

Disclaimer: This is not a traditional SOC analyst role.

Success in this position is not defined by working one alert at a time, but by figuring out how to handle thousands of similar situations better, faster, and more consistently through automation, patterning, and engineering. Key focus will be studying how investigations should work, identifying repeatable decision points, and turning that thinking into detections, enrichment, triage logic, and automated response workflows.

As a senior member of the team, you'll be expected to take ownership of complex problem areas, exercise strong judgment in ambiguous situations, and help shape how the broader Threat Engineering function operates. This role is for someone who can bridge threat detection, engineering, and customer experience. Its ideal for someone who is more interesting asking, "How should this entire class of problem be solved?" rather than, "How do I close the next alert in the queue?"

If you are excited by designing systems that scale expert judgment, improving both customer outcomes and operational efficiency, and doing work that looks very different from a conventional analyst job, this role is for you.

Responsibilities
  • Design, build, and improve the detection, decisioning, and response workflows that power the Wirespeed Verdict Engine
  • Own complex threat detection and workflow problem spaces from investigation concept through implementation, validation, and iteration
  • Translate investigative thinking and threat research into scalable detections, enrichment, triage logic, and automated decisions that improve speed, accuracy, reliability, and customer outcomes
  • Analyze operational data to identify false positives, false negatives, latency issues, and opportunities to improve how entire categories of work are handled
  • Continuously raise the ceiling of what the system can do autonomously, reducing manual review while improving service quality and consistency
  • Support especially complex or novel cases when needed, then feed those lessons back into the system so similar situations can be handled better in the future
  • Keep the customer experience front and center by ensuring Wirespeed outputs are clear, helpful, accurate, and appropriately calibrated to the customer's situation
  • Identify patterns in customer pain, confusion, or friction and use those insights to improve verdict logic, response content, and overall product behavior
  • Partner closely with product, engineering, and security teams to improve platform capabilities, data quality, and operational leverage
  • Help define best practices, operating principles, and technical standards for Threat Engineering work
  • Document detection concepts, workflow logic, and operating principles so the team can scale knowledge
  • Provide technical leadership through strong execution, sound judgment, and mentorship of less experienced teammates
Skills and Qualifications
  • Significant experience in cybersecurity operations such as threat detection and response, detection engineering, incident response, threat hunting, or SOC operations
  • You look for repeatable patterns, clear decision logic, and ways to scale good judgment through automation rather than repeated manual work
  • Strong investigative and analytical skills, with the ability to turn ambiguous signals and messy operational problems into practical detection logic and workflow improvements
  • Experience building, tuning, or maintaining automations, detections, playbooks, rules, or enrichment pipelines in security tooling
  • Demonstrated ability to independently own complex technical or operational problem areas, step into ambiguity, and drive them to better outcomes
  • Interest in work that is different from a traditional analyst role: improving how work gets done rather than only executing it yourself
  • Strong written and verbal communication skills, including the ability to document logic and explain threats, tradeoffs, and outcomes clearly to customers and internal partnersAbility to work closely with product, engineering, and security stakeholders
  • Comfort using data to evaluate detection quality, workflow performance, and where the system needs improvement
  • Preference for simple, scalable solutions and willingness to reduce unnecessary complexity or manual work
Bonus Points
  • Experience working in high-volume security operations environment
  • Significant experience with detection and response tooling such as SIEM, EDR, SOAR, case management, and telemetry enrichment systems
  • Familiarity writing scripts or queries to support investigations, automation, or workflow analysis
  • Experience improving operational quality through experimentation, measurement, and continuous iteration
  • Experience in workflow design, detection engineering, automation, or security product development
  • Experience mentoring fellow engineers, setting technical direction, or influencing how a team approaches detection and response problems
Compensation

As a remote-first organization, our compensation reflects the cost of labor across several Canadian geographic markets.

In Alberta, British Columbia & Ontario the base salary for this position ranges from $118,600/year up to $148,250/year.

For all other locations, the base salary for this position ranges from $106,700/year up to $133,425/year.

Consistent with applicable laws, an employee's pay within this range is based on a number of factors, which include but are not limited to relevant education, skills, job-related knowledge, qualifications, work experience, credentials, and/or geographic location. Your Recruiter can share more on the specific target salary range for your location during the interview process. Coalition, Inc. reserves the right to modify this range as needed.

Vacancy Status: This posting is for an existing vacancy.

Use of AI: We utilize AI-assisted tools to help us organize and review the high volume of applications we receive. However, our human recruiting team makes all final hiring decisions and interview selections, valuing personal connection over algorithms.

Application Updates: Consistent with our commitment to transparency, if you are interviewed for this role, we will provide a status update on your application within 45 days of your final interview.
Perks
  • 100% medical, dental, and vision coverage
  • Flexible PTO
  • Annual home office stipend and WeWork access
  • Mental & physical health wellness programs like Headspace, Lumino, and more!
  • Competitive compensation and opportunity for advancement

About Coalition

Coalition is a UK-based financial technology company that provides risk management and analytics solutions to financial institutions. The company was founded in 2008 and has since grown to become a leading provider of risk management software, with clients including some of the world's largest banks and asset managers. Coalition's technology platform allows financial institutions to monitor and manage their risk exposure in real-time, providing insights into market trends and potential risks. The company has received numerous awards for its innovative approach to risk management, including the Risk Management Technology Provider of the Year at the Risk Awards in 2019.
Learn more about Coalition
Size
200 employees
Industry
Founded
2017

Similar Jobs

More Jobs at Coalition

More Information Technology Jobs

Find similar Senior Threat Engineer jobs: