← Back to jobs

Remote job

Senior Detection Engineer (EDR), Defensive Agent

Other Full-time Permanent United States

Job details

Not specified Salary
United States Eligibility
Senior Experience
Full-time Employment

About this role

Role overview

This role provides the blue-team domain authority for a defensive security agent focused on endpoint detection and response. Working between Product, Engineering, and AI research, you will define what accurate detection and remediation look like, convert operational security knowledge into measurable requirements, and ensure that recommendations reflect how real SOC teams use endpoint tools. The position emphasizes judgment, validation, and domain ownership rather than software implementation.

Responsibilities

- Translate EDR effectiveness and tuning goals into practical product requirements and prioritized outcomes. - Define acceptance criteria for detection, prevention, effectiveness, and tuning capabilities, then validate releases before customer use. - Serve as the primary domain reference for engineering and AI research during design reviews, technical questions, and vendor-behavior analysis. - Maintain detailed knowledge of major endpoint platforms across consoles, policies, telemetry, APIs, detections, exclusions, and hardened configurations. - Document vendor-specific policy semantics so equivalent recommendations remain accurate across products with different models. - Track platform changes, new capabilities, and vendor guidance while keeping coverage expectations current. - Define standards for correct tuning recommendations and evaluate agent output against those standards in partnership with attack-focused teams.

Requirements

- Six or more years in detection engineering, security operations, incident response, or threat hunting, including substantial hands-on practitioner experience. - Production experience administering and tuning EDR platforms, writing detections, managing policies and exclusions, and investigating real alerts. - Deep understanding of SOC workflows, alert fatigue, false-positive and false-negative tradeoffs, and detection-coverage measurement. - Strong working knowledge of MITRE ATT&CK and related coverage frameworks, including their practical limitations. - Solid understanding of post-compromise attacker behavior and how it appears in endpoint and identity telemetry. - Demonstrated ability to turn operational expertise into clear requirements, acceptance criteria, and measurable quality standards. - Strong communication and collaboration skills for working across product, engineering, research, and security teams.

Benefits and work setup

- Remote work options may vary by role and location; some positions may require regular office attendance. - Competitive compensation with equity eligibility for full-time roles. - Health, vision, and dental coverage for employees and families, flexible vacation, and parental leave. - An environment centered on respect, ownership, collaboration, inclusion, and professional growth.

Skills detected in the listing

PythonSQLInformation Security
Detected Sep 19, 2026
Last verified Sep 19, 2026

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight