
Senior Detection Engineer, EDR – Defensive Agent
Posted 21 hours ago

Posted 21 hours ago
This is a fully remote position, open to applicants in United States.
• Collaborate with Product to transform EDR effectiveness and tuning objectives into actionable, buildable requirements.
• Convert blue team workflows and challenges into prioritized product outcomes.
• Challenge features or agent behaviors that would not withstand scrutiny in a real Security Operations Center (SOC).
• Establish acceptance criteria for detection, effectiveness, and tuning features.
• Verify releases against acceptance criteria prior to customer access.
• Act as the domain reference for Engineering and AI research.
• Provide design evaluations, technique advice, and vendor behavior recommendations.
• Maintain up-to-date knowledge of major EDR and endpoint platforms at the console, policy, telemetry, and API levels.
• Stay informed about detection logic, prevention policies, exclusions, and tuning across various products.
• Define vendor-specific policy semantics across differently modeled platforms.
• Monitor platform changes, new detection capabilities, and vendor guidance.
• Ensure the coverage model remains current as vendors implement changes.
• Establish appropriate tuning recommendations and evaluate agent output against that benchmark.
• Collaborate with the Attack team to ground technique coverage and detection expectations in contemporary adversary tradecraft.
• Over 6 years of experience in detection engineering, security operations, incident response, or threat hunting.
• Significant practitioner experience rather than exclusively advisory roles.
• Practical experience in administering and tuning EDR platforms.
• Proficient in writing detections, managing policies and exclusions, and investigating genuine alerts.
• Comprehensive understanding of SOC workflows that involve EDR output.
• Awareness of false-positive and false-negative trade-offs, alert fatigue, and detection coverage metrics.
• Strong familiarity with MITRE ATT&CK and detection coverage frameworks.
• Insight into post-compromise attacker behavior and endpoint and identity telemetry.
• Experience shaping a product or platform as a subject matter expert.
• Capability to influence without direct authority.
• Outstanding technical writing proficiency.
• Ability to effectively communicate between engineers, AI researchers, product managers, SOC analysts, and executives.
• Scripting skills, preferably in Python, for querying APIs, analyzing telemetry, and prototyping analyses.
• Comfort with SQL and handling large volumes of event and telemetry data.
• Equity package in the form of stock options for all full-time positions.
• Health, vision, and dental insurance for you and your family.
• Flexible vacation policy.
• Generous parental leave.
• Opportunities for career development.
• An inclusive and collaborative workplace culture.
• Remote and hybrid work arrangements based on role and location.
Spyrosoft
Jamf
Qualus
Qualus
Get handpicked remote jobs straight to your inbox weekly.