Remote job
EDR Engineer / Senior EDR Engineer
Job details
About this role
Role overview The EDR Security Engineer runs the technical administration, configuration, and lifecycle management of Endpoint Detection and Response platforms as part of an Incident Response function. The role keeps endpoint telemetry healthy and detection logic effective across a diverse fleet, with occasional after-hours availability for urgent containment and restoration work.
Responsibilities - Deploy, configure, and maintain multiple enterprise EDR platforms, monitoring agent health and resolving failures to meet defined service levels. - Build and tune detection policies and indicators, translating threat intelligence into high-fidelity endpoint rules and reducing false positives. - Manage endpoint and workload protection across multi-cloud environments, covering virtual machines and containerized workloads alongside native cloud security services. - Maintain integrations between EDR consoles and SIEM/SOAR platforms and provide secondary support for adjacent technologies such as audit and DLP tools. - Support active incidents with endpoint containment, live response scripts, remote data collection, and post-incident hardening. - Follow formal change management processes and maintain SOPs, configuration baselines, and internal documentation.
Requirements - At least three years managing EDR solutions in an enterprise environment. - Proficiency in PowerShell, Python, or Bash for automation and large-scale data querying. - Deep knowledge of Windows, macOS, and Linux internals, including processes, registry/config files, and logging mechanisms. - Working understanding of TCP/IP, DNS, and proxy configurations as they relate to agent-to-console communication. - Familiarity with AWS, Azure, or GCP security services such as GuardDuty or Defender for Cloud. - Experience with platforms such as Splunk, Tines, Palo Alto XSOAR, or Zscaler, plus comfort with digital forensics and proactive threat hunting.
Nice to have - Relevant certifications such as GCFA, GCIA, or platform-specific administrator credentials. - Demonstrated ability to diagnose complex issues spanning the security stack and endpoint operating systems.
Benefits and work setup The base salary range is $78,500–$117,500, with variation by role, level, and location. The position may be eligible for incentive compensation, equity, and medical, dental, vision, and life insurance plus a 401(k). Occasional after-hours availability is required for urgent incident response.