EDR Engineer / Senior EDR Engineer

Recorded Future•Remote - USA, MA
•$78,500 - $117,500•Remote

About The Position

The EDR Security Engineer is responsible for the technical administration, configuration, and maintenance of Endpoint Detection and Response (EDR) platforms. As a member of the Incident Response (IR) team, this role ensures the integrity of endpoint telemetry and the effectiveness of detection logic. You will manage multiple EDR solutions across a diverse environment and provide secondary engineering support for the broader security toolset as necessary. As a critical member of the IR function, this position requires occasional availability after-hours to assist with urgent incident containment and system restoration.

Requirements

  • Minimum of 3 years of professional experience managing EDR solutions in an enterprise environment.
  • Proficiency in PowerShell, Python, or Bash for task automation and large-scale data querying.
  • Comprehensive knowledge of Windows, macOS, and Linux internals, specifically regarding system processes, registry/configuration files, and logging mechanisms.
  • Understanding of TCP/IP, DNS, and proxy configurations as they relate to agent-to-console communication.
  • Technical familiarity with AWS, Azure, or GCP security services (e.g., GuardDuty, Microsoft Defender for Cloud).
  • Experience with secondary security platforms such as Splunk, Tines, Palo Alto XSOAR, or Zscaler.
  • Familiarity with digital forensics and proactive threat hunting methodologies and tools.
  • Relevant professional certifications such as GCFA, GCIA, or platform-specific administrator certifications.
  • Demonstrated ability to diagnose complex technical issues within the security stack and endpoint OS.

Responsibilities

  • Oversee the deployment, lifecycle management, and configuration of multiple enterprise EDR platforms (e.g., CrowdStrike, SentinelOne, Microsoft Defender for Endpoint).
  • Monitor and maintain agent health across all managed endpoints, troubleshooting failures and performance issues to maintain established service levels.
  • Develop and refine detection policies and indicators to improve detection rates and minimize false positive alerts.
  • Translate threat intelligence into actionable endpoint rules to ensure high-fidelity alerting.
  • Manage security deployments across multi-cloud environments (AWS, Azure, or GCP).
  • Ensure consistent telemetry and protection for virtual machines and containerized workloads, utilizing cloud-native security services as required.
  • Work with engineering teams to maintain integrations between EDR consoles and existing SIEM/SOAR platforms.
  • Provide secondary technical support for auxiliary security technologies, including Audit and DLP tools.
  • Assist IR analysts during active security incidents by performing endpoint containment, executing live response scripts, and conducting remote data collection.
  • Assist in the restoration of systems and the hardening of endpoint policies post-incident.
  • Adhere to formal change management processes for all policy modifications.
  • Maintain clear technical documentation, Standard Operating Procedures (SOPs), and configuration baselines for internal stakeholders.

Benefits

  • medical
  • dental
  • vision
  • life insurance
  • 401K
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service