EDR Engineer / Senior EDR Engineer
Recorded Future · Remote - USA
About this role
**Recorded Future — EDR Security Engineer (Senior EDR Engineer)** With 1,000+ intelligence professionals serving 1,900+ clients worldwide, Recorded Future is seeking an **EDR Security Engineer** to support the technical administration, configuration, and maintenance of Endpoint Detection and Response (EDR) platforms. As part of the **Incident Response (IR)** team, you’ll help ensure the integrity of endpoint telemetry and the effectiveness of detection logic. You’ll manage multiple EDR solutions across a diverse environment and provide secondary engineering support for the broader security toolset as needed. **Occasional after-hours availability** may be required for urgent incident containment and system restoration. --- ## What you’ll do - **EDR Administration & Fleet Health:** Oversee deployment, lifecycle management, and configuration of enterprise EDR platforms (e.g., **CrowdStrike, SentinelOne, Microsoft Defender for Endpoint**). Monitor agent health, troubleshoot failures/performance issues, and maintain service levels. - **Policy & Detection Engineering:** Develop/refine detection policies and indicators to improve detection rates and reduce false positives. Convert threat intelligence into actionable endpoint rules. - **Cloud Workload Protection:** Manage security deployments across **AWS, Azure, and/or GCP**, ensuring consistent telemetry and protection for VMs and containerized workloads using cloud-native services. - **Systems Integration & Tooling Support:** Maintain integrations between EDR consoles and **SIEM/SOAR** platforms. Provide secondary support for tools such as **Audit** and **DLP**. - **Incident Response Support:** Assist IR analysts during active incidents with endpoint containment, live response scripts, and remote data collection. Support restoration and post-incident endpoint policy hardening. - **Operational Reliability & Documentation:** Follow change management for policy updates. Maintain technical documentation, **SOPs**, and configuration baselines. --- ## What you’ll bring - **Experience:** Minimum **3 years** managing EDR solutions in an enterprise environment. - **Scripting:** Proficiency in **PowerShell, Python, or Bash** for automation and large-scale querying. - **Operating Systems:** Strong knowledge of **Windows, macOS, and Linux** internals (processes, registry/config files, logging). - **Networking:** Understanding of **TCP/IP, DNS, and proxy** configurations for agent-to-console communication. - **Cloud Platforms:** Familiarity with **AWS, Azure, or GCP** security services (e.g., **GuardDuty, Microsoft Defender for Cloud**). - **Tooling:** Experience with platforms such as **Splunk, Tines, Palo Alto XSOAR, or Zscaler**. - **Forensics:** Familiarity with digital forensics and proactive threat hunting. - **Certifications:** Relevant certifications such as **GCFA, GCIA**, or platform-specific admin certs. - **Problem Solving:** Ability to diagnose complex technical issues across the security stack and endpoint OS. --- ## Compensation & location - Base salary range (full-time): **$78,500 – $117,500** (US locations) - **#LI-Remote** --- ## Why join Recorded Future? Recorded Future employees (“**Futurists**”) represent 40+ nationalities and focus on high standards, inclusion, and ethical action. The company has a **4.6-star G2** rating and is used by **50%+ of Fortune 100** companies. --- *Note: Final-round interviews require a mandatory **in-person interview** or a live, scheduled **v
Listing freshness
CronJobs last confirmed this listing 3h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.