
Security Platform Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Europe.
• Administer, maintain, and oversee EDR and SIEM environments.
• Adjust detection rules, correlation logic, and security policies to enhance detection accuracy and minimize false positives.
• Set up and manage endpoint policies, agent health, log collection, and platform integrations.
• Create and sustain dashboards, reports, alerts, and security use cases.
• Examine noisy or ineffective detections and consistently enhance alert reliability.
• Verify endpoint protection, log collection, and response capabilities.
• Incorporate new log sources and enhance visibility across endpoints, servers, cloud services, and network infrastructure.
• Transform insights from incidents, threat intelligence, vulnerability assessments, and offensive security exercises into enhanced monitoring content.
• Monitor platform health, storage, agent connectivity, licensing, and service availability.
• Assist the Information Security team during security investigations by enhancing visibility, detections, and response workflows.
• Collaborate with Infrastructure and IT teams to integrate new systems into EDR and SIEM.
• Produce operational documentation, standard operating procedures, and platform runbooks.
• Track detection coverage, platform performance, and initiatives for continuous improvement.
• Engage in remote video screening, an online Hackerrank assessment, remote video interviews, and a final discussion with the hiring manager.
• Proven experience administering enterprise SIEM, XDR, or EDR platforms.
• Practical experience with Wazuh, Trend Micro Vision One, Microsoft Defender XDR, Microsoft Sentinel, Elastic Security, Splunk, or comparable platforms.
• Strong grasp of endpoint security, Windows, Linux, macOS, Active Directory, cloud environments, and network security.
• Experience in tuning detection rules and decreasing false positives.
• Familiarity with log collection, parsing, correlation, and analysis of security events.
• Understanding of MITRE ATT&CK and prevalent attacker techniques.
• Experience in writing automation or scripts using Python, PowerShell, or Bash.
• Strong analytical and troubleshooting abilities.
• Exceptional documentation and communication skills.
• Sporty is a remote-first organization committed to sustainability.
• A competitive salary accompanied by individual performance-based bonuses every quarter.
• 28 days of paid annual leave.
• Core working hours of 10am-3pm in your local time zone, with flexibility outside of these hours.
• Referral bonuses and flash bonuses.
• Top-of-the-line equipment.
• Annual company retreats that offer opportunities to connect and collaborate with colleagues worldwide.
Urrly
Hire Hangar Global
LegitScript
Coinbase
Get handpicked remote jobs straight to your inbox weekly.