Remote job
Senior Detection Engineer (EDR), Defensive Agent
Job details
About this role
Role overview
This role provides the blue-team domain authority for a defensive security agent focused on endpoint detection and response. Working between Product, Engineering, and AI research, you will define what accurate detection and remediation look like, convert operational security knowledge into measurable requirements, and ensure that recommendations reflect how real SOC teams use endpoint tools. The position emphasizes judgment, validation, and domain ownership rather than software implementation.
Responsibilities
- Translate EDR effectiveness and tuning goals into practical product requirements and prioritized outcomes. - Define acceptance criteria for detection, prevention, effectiveness, and tuning capabilities, then validate releases before customer use. - Serve as the primary domain reference for engineering and AI research during design reviews, technical questions, and vendor-behavior analysis. - Maintain detailed knowledge of major endpoint platforms across consoles, policies, telemetry, APIs, detections, exclusions, and hardened configurations. - Document vendor-specific policy semantics so equivalent recommendations remain accurate across products with different models. - Track platform changes, new capabilities, and vendor guidance while keeping coverage expectations current. - Define standards for correct tuning recommendations and evaluate agent output against those standards in partnership with attack-focused teams.
Requirements
- Six or more years in detection engineering, security operations, incident response, or threat hunting, including substantial hands-on practitioner experience. - Production experience administering and tuning EDR platforms, writing detections, managing policies and exclusions, and investigating real alerts. - Deep understanding of SOC workflows, alert fatigue, false-positive and false-negative tradeoffs, and detection-coverage measurement. - Strong working knowledge of MITRE ATT&CK and related coverage frameworks, including their practical limitations. - Solid understanding of post-compromise attacker behavior and how it appears in endpoint and identity telemetry. - Demonstrated ability to turn operational expertise into clear requirements, acceptance criteria, and measurable quality standards. - Strong communication and collaboration skills for working across product, engineering, research, and security teams.
Benefits and work setup
- Remote work options may vary by role and location; some positions may require regular office attendance. - Competitive compensation with equity eligibility for full-time roles. - Health, vision, and dental coverage for employees and families, flexible vacation, and parental leave. - An environment centered on respect, ownership, collaboration, inclusion, and professional growth.