
Security Engineer, Security Control Management
Posted Aug 25

Posted Aug 25
This is a fully remote position, open to applicants in Maryland.
• Manage CyberMaxx-controlled EDR platforms within customer environments, encompassing routine configuration, policy upkeep and adjustments, agent lifecycle management, operational controls, and platform health assessments.
• Implement sanctioned routine and extensive platform modifications, including agent upgrades, bulk operations, policy transitions, and recovery actions, adhering to established change controls, validation procedures, and documentation standards.
• Oversee platform health, agent coverage, version status, policy alignment, and operational anomalies; investigate inconsistencies and coordinate remediation efforts.
• Assist in agent deployment, console configuration, integrations, and platform migrations under the guidance of senior engineering personnel.
• Track vendor roadmaps, emerging functionalities, and industry trends across supported EDR platforms, providing insights and recommendations.
• Examine endpoint security challenges related to agent connectivity, performance, interoperability, policy behavior, detections, exclusions, upgrades, and deployment failures.
• Gather and evaluate endpoint, console, and application data to identify probable causes.
• Address requests within specified protocols and escalate complex, high-risk, or vendor-dependent issues with comprehensive technical findings.
• Collaborate with vendors and internal teams to advance support cases, validate remediation efforts, and relay status updates to customer-facing stakeholders.
• Engage in peer review of configuration modifications, exclusions, and technical advice.
• Utilize PowerShell, Python, vendor APIs, or approved automation tools to execute repeatable tasks and minimize manual effort.
• Contribute to scripts, workflows, and platform integrations, including testing, documentation, and controlled deployment.
• Identify recurring requests, failure patterns, and manual processes for standardization or automation.
• Confirm automation output and maintain safeguards for changes across multiple customer environments.
• Create and sustain operational dashboards, reports, and health metrics.
• Contribute to engineering repositories, runbooks, operational checklists, and tooling documentation.
• Coordinate operational requests and technical investigations from initiation to completion.
• Offer insights on EDR configuration, deployment, platform health, and endpoint security operations.
• Support customer meetings by clearly communicating findings, risks, dependencies, and next steps in business-friendly language.
• Develop and maintain customer-facing procedures, configuration guidance, and implementation documentation.
• Assist in customer training and guidance on routine EDR platform administration and workflows.
• Identify recurring issues or misconfigurations and escalate them to senior engineers.
• Attain working proficiency across CrowdStrike Falcon, SentinelOne, and Microsoft Defender for Endpoint.
• Share troubleshooting insights, technical notes, and reusable procedures with team members and SOC analysts.
• Collaborate with SOC, detection engineering, professional services, customer success, and other operational teams.
• A minimum of 1 year of experience in endpoint security, EDR operations, security engineering, systems administration, SOC operations, or a closely related technical role.
• Hands-on experience administering or supporting at least one of the following: CrowdStrike Falcon, SentinelOne Singularity, or Microsoft Defender for Endpoint.
• Practical experience in troubleshooting Windows endpoints.
• Familiarity with macOS or Linux endpoint administration is advantageous.
• Working knowledge of EDR concepts, endpoint security policies, agent deployment, exclusions, detection triage, and basic response actions.
• Proficiency in using PowerShell, Python, command-line tools, or vendor APIs for troubleshooting and repeatable operational tasks.
• Capability to analyze technical evidence, document findings, adhere to change controls, and escalate issues with sufficient context for effective resolution.
• Strong written and verbal communication skills for collaboration with internal engineering teams and customer stakeholders.
• Experience in an MSSP, MDR, SOC, or other multi-customer security operations environment is preferred.
• Relevant vendor certification or training, such as CrowdStrike CCFA, SentinelOne Certified Administrator or Engineer, Microsoft SC-200, or equivalent practical coursework, is preferred.
• Experience with SOAR platforms, SIEM integrations, or security automation tools in the context of endpoint security operations is preferred.
• Understanding of MITRE ATT&CK, common endpoint attack techniques, and how EDR telemetry supports detection and investigation is preferred.
• Experience in large-scale EDR deployments, platform consolidations, or migrations across diverse enterprise environments is preferred.
• Experience utilizing EDR-native remote response, querying, hunting, bulk management, or detection validation capabilities to investigate and manage endpoints at scale is preferred.
• Flexible Paid Time Off.
• 401k with a company match.
• Medical, Dental and Vision Coverage.
• Voluntary Short Term and Long-Term Disability.
• Employee Assistance Program with Mental Health Supplement.
• Voluntary Basic, Accidental, and other ancillary life insurance.
• Health Savings Account Contribution (with selection of a HDHP).
• 10 annual, paid holidays.
• Structured cross-training will be provided to build working proficiency across the supported portfolio.
GuidePoint Security
Gravie
Your Software Supplier
Dragonfli Group
Get handpicked remote jobs straight to your inbox weekly.