The
EDR Security Engineer is responsible for the technical administration, configuration, and maintenance of Endpoint Detection and Response (EDR) platforms. As a member of the Incident Response (IR) team, this role ensures the integrity of endpoint telemetry and the effectiveness of detection logic. You will manage multiple EDR solutions across a diverse environment and provide secondary engineering support for the broader security toolset as necessary. As a critical member of the IR function, this position requires occasional availability after-hours to assist with urgent incident containment and system restoration.
What You'll Do:EDR Administration & Fleet Health: Oversee the deployment, lifecycle management, and configuration of multiple enterprise EDR platforms (e.g., CrowdStrike, SentinelOne, Microsoft Defender for Endpoint). Monitor and maintain agent health across all managed endpoints, troubleshooting failures and performance issues to maintain established service levels.
Policy & Detection Engineering: Develop and refine detection policies and indicators to improve detection rates and minimize false positive alerts. Translate threat intelligence into actionable endpoint rules to ensure high-fidelity alerting.
Cloud Workload Protection: Manage security deployments across multi-cloud environments (AWS, Azure, or GCP). Ensure consistent telemetry and protection for virtual machines and containerized workloads, utilizing cloud-native security services as required.
Systems Integration & Tooling Support: Work with engineering teams to maintain integrations between EDR consoles and existing SIEM/SOAR platforms. Provide secondary technical support for auxiliary security technologies, including Audit and DLP tools.
Incident Response Support: Assist IR analysts during active security incidents by performing endpoint containment, executing live response scripts, and conducting remote data collection. Assist in the restoration of systems and the hardening of endpoint policies post-incident.
Operational Reliability & Documentation: Adhere to formal change management processes for all policy modifications. Maintain clear technical documentation, Standard Operating Procedures (SOPs), and configuration baselines for internal stakeholders.
What You'll Bring:- Experience: Minimum of 3 years of professional experience managing EDR solutions in an enterprise environment.
- Scripting: Proficiency in PowerShell, Python, or Bash for task automation and large-scale data querying.
- Operating Systems: Comprehensive knowledge of Windows, macOS, and Linux internals, specifically regarding system processes, registry/configuration files, and logging mechanisms.
- Networking: Understanding of TCP/IP, DNS, and proxy configurations as they relate to agent-to-console communication.
- Cloud Platforms: Technical familiarity with AWS, Azure, or GCP security services (e.g., GuardDuty, Microsoft Defender for Cloud).
- Tooling: Experience with secondary security platforms such as Splunk, Tines, Palo Alto XSOAR, or Zscaler.
- Forensics: Familiarity with digital forensics and proactive threat hunting methodologies and tools.
- Certifications: Relevant professional certifications such as GCFA, GCIA, or platform-specific administrator certifications.
- Problem Solving: Demonstrated ability to diagnose complex technical issues within the security stack and endpoint OS.
The base salary range for this full-time position is $78,500 - $117,500. Our salary ranges are determined by role, level, and location. The salary displayed reflects the range for new hire salaries for the position across all US locations. Within the range, individual pay is determined by state, work location and additional factors, including job-related skills, experience, and relevant education or training. This position may be eligible for incentive compensation, equity, and medical, dental, vision, life insurance and 401K. Your recruiter can share more about the specific details of the compensation and benefit package during the hiring process.
#LI-Remote