SlipstreamJobsFresh Startup & VC-Backed Jobs

EDR Engineer / Senior EDR Engineer

Recorded Future - Remote - Remote - posted 2026-09-17

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 78,500 - 117,500 / annual

Recorded Future, a leading intelligence company serving 1,900+ clients globally, is seeking an EDR Security Engineer to join its Incident Response team. This role is responsible for the technical administration, configuration, and maintenance of Endpoint Detection and Response (EDR) platforms across the enterprise. Key Responsibilities: EDR Administration & Fleet Health: Oversee deployment, lifecycle management, and configuration of multiple enterprise EDR platforms (CrowdStrike, SentinelOne, Microsoft Defender for Endpoint). Monitor and maintain agent health across all managed endpoints, troubleshooting failures and performance issues to maintain service levels. Policy & Detection Engineering: Develop and refine detection policies and indicators to improve detection rates and minimize false positives. Translate threat intelligence into actionable endpoint rules for high-fidelity alerting. Cloud Workload Protection: Manage security deployments across multi-cloud environments (AWS, Azure, GCP). Ensure consistent telemetry and protection for virtual machines and containerized workloads using cloud-native security services. Systems Integration & Tooling Support: Maintain integrations between EDR consoles and existing SIEM/SOAR platforms. Provide secondary technical support for auxiliary security technologies including Audit and DLP tools. Incident Response Support: Assist IR analysts during active security incidents by performing endpoint containment, executing live response scripts, and conducting remote data collection. Support system restoration and endpoint policy hardening post-incident. Operational Reliability & Documentation: Adhere to formal change management processes. Maintain technical documentation, SOPs, and configuration baselines. Occasional after-hours availability required for urgent incident containment and system restoration. Requirements: - Minimum 3 years of professional experience managing EDR solutions in an enterprise environment - Proficiency in PowerShell, Python, or Bash for task automation and large-scale data querying - Comprehensive knowledge of Windows, macOS, and Linux internals (system processes, registry/configuration files, logging mechanisms) - Understanding of TCP/IP, DNS, and proxy configurations as they relate to agent-to-console communication - Technical familiarity with AWS, Azure, or GCP security services (GuardDuty, Microsoft Defender for Cloud) - Experience with secondary security platforms such as Splunk, Tines, Palo Alto XSOAR, or Zscaler - Familiarity with digital forensics and proactive threat hunting methodologies and tools - Relevant professional certifications such as GCFA, GCIA, or platform-specific administrator certifications preferred - Demonstrated ability to diagnose complex technical issues within the security stack and endpoint OS

Similar roles