Build and improve detection, decisioning, and response workflows for Coalition's Wirespeed Verdict Engine. Focus on scaling expert judgment through automation and pattern recognition rather than traditional SOC alert handling. Bridge threat detection, engineering, and customer experience.
Significant experience in cybersecurity operations such as threat detection and response, detection engineering, incident response, threat hunting, or SOC operations
Experience building, tuning, or maintaining automations, detections, playbooks, rules, or enrichment pipelines in security tooling
Demonstrated ability to independently own complex technical or operational problem areas
Strong investigative and analytical skills with ability to turn ambiguous signals into practical detection logic
Strong written and verbal communication skills
Comfort using data to evaluate detection quality and workflow performance
Design, build, and improve detection, decisioning, and response workflows that power the Wirespeed Verdict Engine
Own complex threat detection and workflow problem spaces from investigation concept through implementation and iteration
Translate investigative thinking and threat research into scalable detections, enrichment, triage logic, and automated decisions
Analyze operational data to identify false positives, false negatives, latency issues, and improvement opportunities
Continuously raise the ceiling of what the system can do autonomously while improving service quality
Support complex or novel cases and feed lessons back into the system
Keep customer experience front and center ensuring Wirespeed outputs are clear, helpful, and accurate
Partner closely with product, engineering, and security teams to improve platform capabilities
Help define best practices, operating principles, and technical standards for Threat Engineering work
Document detection concepts, workflow logic, and operating principles so the team can scale knowledge
Provide technical leadership through strong execution, sound judgment, and mentorship
This is not a traditional SOC analyst role
Success is defined by handling thousands of similar situations better through automation and engineering
Ideal for someone who asks how entire classes of problems should be solved
Remote-first organization with compensation reflecting cost of labor across Canadian markets
Vacancy status is for an existing vacancy
AI-assisted tools used to organize applications but human team makes all final decisions
Application status updates provided within 45 days of final interview
190,000 – 237,000 USD
/ year
90,000 – 110,000 CAD
/ year
150,000 – 200,000 USD
/ year
165,000 – 210,000 USD
/ year
120,000 – 160,000 USD
/ year