Application Engineer 4 (EDR)

Avid Technology ProfessionalsAnnapolis Junction, MD

About The Position

This role focuses on EDR Solutions, Cloud Applications, Cloud Security, Security Operations Center (SOC) Support, Network Security, and Windows Forensics. The ideal candidate will have proficiency in EDR platforms, cloud security, and SOC functions, along with a strong understanding of network security and Windows internals for forensic analysis.

Requirements

  • Proficient in one or more EDR platforms (Trellix HX/EDRF or Microsoft Defender for Endpoint EDR, preferably both).
  • Experience with cloud security and familiarity with cloud service providers (AWS or Azure, preferably both).
  • Experience securing cloud-hosted workloads using EDR solutions and understanding cloud-native security controls and logging (Microsoft Sentinel, Microsoft Defender, Microsoft Purview, AWS CoudWatch, AWS CloudTrail, AWS GuardDuty, or AWS Security Hub).
  • CCSP Certified Cloud Security Professional certification or equivalent.
  • Experience supporting SOC functions such as assisting in monitoring, training analysts, documenting SOPs, incident response coordination, analysis of security events, and process/procedure improvement.
  • Microsoft Certified: Security Operations Analyst Associate (SOAA) or equivalent.
  • Understanding of network protocols, traffic analysis, and intrusion detection systems (CompTIA Security+ is required).
  • In-depth knowledge of Windows operation system internals, registry, and file system.
  • Familiarity with forensic tools like EnCase, FTK, or open-source alternatives.
  • SANS Windows Forensic Analysis (FOR500) or equivalent.

Nice To Haves

  • Threat Hunting: Proactive identification and investigation of potential security threats and anomalies.
  • Incident Response: Experience in managing and responding to security incidents, including containment, eradication, and recovery.
  • Familiarity with SIEM systems for log analysis and correlation (e.g. Splunk, Elastic, Microsoft Sentinel).
  • Proficient in scripting languages (e.g., PowerShell, Python) for automating tasks and workflows.
  • Certified Information Systems Security Professional (CISSP)
  • Microsoft 365 Certified: Endpoint Administrator Associate (MD-102)

Responsibilities

  • Supporting SOC functions such as assisting in monitoring, training analysts, documenting SOPs, incident response coordination, analysis of security events, and process/procedure improvement.
  • Proactive identification and investigation of potential security threats and anomalies (Threat Hunting).
  • Managing and responding to security incidents, including containment, eradication, and recovery (Incident Response).
  • Automating tasks and workflows using scripting languages.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service