
Operations Engineer
Posted Sep 4

Posted Sep 4
This is a fully remote position, open to applicants in Maryland.
• Oversee the administration of CyberMaxx-managed EDR platforms within various customer environments.
• Conduct configuration, policy maintenance, tuning, agent lifecycle activities, operational controls, and health checks of the platform.
• Implement approved platform modifications, such as agent upgrades, bulk operations, policy transitions, and recovery tasks, adhering to change controls and validation processes.
• Track platform health, agent coverage, version status, policy alignment, and operational exceptions; probe discrepancies and facilitate remediation efforts.
• Assist in agent deployment, console setup, integrations, and platform migrations.
• Keep abreast of vendor roadmaps and emerging features, offering recommendations to enhance internal standards.
• Examine endpoint security challenges related to agent connectivity, performance, interoperability, policies, detections, exclusions, upgrades, and deployment failures.
• Gather and scrutinize endpoint, console, and application evidence to determine root causes.
• Address requests in accordance with established procedures and escalate complex, high-risk, or vendor-dependent issues.
• Collaborate with vendors and internal teams on support cases and validation of remediation efforts.
• Engage in peer reviews of configuration alterations, exclusions, and technical suggestions.
• Utilize PowerShell, Python, vendor APIs, or approved automation tools for tasks and evidence collection that require repetition.
• Contribute to scripts, workflows, platform integrations, testing, documentation, and controlled rollouts.
• Identify recurring requests and manual tasks for potential standardization or automation.
• Create and maintain operational dashboards, reports, and health metrics.
• Manage engineering repositories, runbooks, operational checklists, and documentation for tools.
• Coordinate operational requests and technical investigations from initiation to completion.
• Provide guidance on EDR configuration, deployment, platform health, and endpoint security operations.
• Facilitate customer meetings, training sessions, and routine EDR administration support.
• Develop documentation for customer-facing procedures, configuration guidance, and implementation instructions.
• Share troubleshooting insights and reusable procedures with Operations Engineering and SOC teams.
• Collaborate with SOC, Detection Engineering, Professional Services, Customer Success, and other operational teams.
• A minimum of 4 years of experience in endpoint security, EDR operations, security engineering, systems administration, SOC operations, or a similar technical role.
• Hands-on experience with administering or supporting at least one of the following: CrowdStrike Falcon, SentinelOne Singularity, or Microsoft Defender for Endpoint.
• Practical experience in troubleshooting Windows endpoints.
• Familiarity with macOS or Linux endpoint administration is a plus.
• Solid understanding of EDR concepts, endpoint security policies, agent deployment, exclusions, detection triage, and basic response actions.
• Proficient in using PowerShell, Python, command-line tools, or vendor APIs for troubleshooting and repetitive operational tasks.
• Capable of analyzing technical evidence, documenting findings, adhering to change controls, and escalating issues with adequate context.
• Excellent written and verbal communication skills for interaction with internal engineering teams and customer stakeholders.
• Preferably experienced in an MSSP, MDR, SOC, or similar multi-customer security operations environment.
• Familiarity with Linux systems, the ITIL framework, and availability monitoring is advantageous.
• Experience with agentic or AI-assisted tools for automating routine, recurring tasks is preferred.
• Relevant vendor certifications or training, such as CrowdStrike CCFA, SentinelOne Certified Administrator or Engineer, Microsoft SC-200, or equivalent practical coursework, is preferred.
• Experience with SOAR platforms, SIEM integrations, or security automation tools within endpoint security operations is an asset.
• Understanding of MITRE ATT&CK, common endpoint attack methods, and EDR telemetry is desirable.
• Familiarity with EDR-native remote response, query, hunting, bulk management, or detection validation capabilities is a plus.
• Flexible Paid Time Off
• 401k with a company match
• Medical, Dental and Vision Coverage
• Voluntary Short Term and Long-Term Disability
• Employee Assistance Program with Mental Health Supplement
• Voluntary Basic, Accidental, and other ancillary life insurance
• Health Savings Account Contribution (with selection of a HDHP)
• 10 annual, paid holidays
• Structured cross-training to build working proficiency across the supported portfolio
Mercor
Mission Lane
ICF
The Cigna Group
Get handpicked remote jobs straight to your inbox weekly.