
EDR Engineer – Senior EDR Engineer
Posted Sep 17

Posted Sep 17
This is a fully remote position, open to applicants in Massachusetts.
• Supervise the deployment, lifecycle management, and configuration of various enterprise EDR platforms, such as CrowdStrike, SentinelOne, and Microsoft Defender for Endpoint.
• Monitor and uphold agent health across managed endpoints, addressing failures and performance challenges.
• Create and enhance detection policies and indicators to boost detection rates and reduce false positives.
• Convert threat intelligence into actionable endpoint rules for high-fidelity alerting.
• Manage security deployments in AWS, Azure, or GCP multi-cloud settings.
• Ensure consistent telemetry and protection for virtual machines and containerized workloads.
• Maintain integrations between EDR consoles and SIEM/SOAR platforms.
• Offer secondary technical support for Audit and DLP tools.
• Aid incident response analysts with endpoint containment, live response scripts, and remote data collection.
• Support system restoration and post-incident endpoint policy hardening.
• Adhere to formal change management processes for policy adjustments.
• Keep technical documentation, SOPs, and configuration baselines updated for internal stakeholders.
• At least 3 years of professional experience managing EDR solutions within an enterprise setting.
• Proficient in PowerShell, Python, or Bash for task automation and extensive data querying.
• In-depth understanding of Windows, macOS, and Linux internals, including system processes, registry/configuration files, and logging systems.
• Knowledge of TCP/IP, DNS, and proxy configurations related to agent-to-console communication.
• Technical familiarity with AWS, Azure, or GCP security services.
• Experience with Splunk, Tines, Palo Alto XSOAR, or Zscaler.
• Acquainted with digital forensics and proactive threat hunting techniques and tools.
• Possession of relevant professional certifications such as GCFA, GCIA, or platform-specific administrator certifications.
• Capability to diagnose complex technical issues within the security stack and endpoint operating systems.
• Availability for occasional after-hours support for urgent incident containment and system restoration.
• Eligibility for incentive compensation.
• Eligibility for equity.
• Medical insurance coverage.
• Dental insurance coverage.
• Vision insurance coverage.
• Life insurance coverage.
• 401(k) plan.
• Commitment to diversity, inclusion, and affirmative action in the workplace.
• Provision of accommodation or special assistance during the application process.
Shield AI
Netflix
Travoom
HeroSoftware GmbH - Shopify Apps
Get handpicked remote jobs straight to your inbox weekly.