Endpoint Detection and Response (EDR) Specialist

CACIFort Meade, MD
Onsite

About The Position

Join our dynamic team and play a pivotal role in enhancing the security posture of the NSA enterprise. We are seeking an experienced Endpoint Detection and Response (EDR) Specialist to deploy, configure, test, manage, and optimize EDR solutions across our organization. This role offers the chance to make a significant impact by establishing comprehensive Standard Operating Procedures (SOPs) and leading training sessions to empower our Security Operations Center (SOC) analysts. If you are passionate about cybersecurity and eager to contribute to a mission-critical environment, we invite you to apply.

Requirements

  • Active TS/SCI w/ Polygraph
  • Proficiency in Trellix HX/EDRF or Microsoft Defender for Endpoint EDR, preferably both.
  • Experience with cloud security and familiarity with AWS or Azure, preferably both.
  • Expertise in securing cloud-hosted workloads using EDR solutions.
  • Understanding of cloud-native security controls and logging (e.g., Microsoft Sentinel, AWS CloudWatch).
  • CCSP Certified Cloud Security Professional certification or equivalent.
  • Experience in supporting SOC functions, including monitoring, analyst training, SOP documentation, and incident response coordination.
  • Microsoft Certified: Security Operations Analyst Associate (SOAA) or equivalent.
  • Knowledge of network protocols, traffic analysis, and intrusion detection systems (CompTIA Security+).
  • In-depth understanding of Windows OS internals, registry, and file system.
  • Familiarity with forensic tools like EnCase, FTK, or open-source alternatives.
  • SANS Windows Forensic Analysis (FOR500) or equivalent.

Nice To Haves

  • Experience in proactively identifying and investigating potential security threats and anomalies.
  • Proven experience in managing and responding to security incidents.
  • Familiarity with Security Information and Event Management systems for log analysis and correlation (e.g., Splunk, Elastic, Microsoft Sentinel).
  • Proficiency in scripting languages (e.g., PowerShell, Python) for automating tasks and workflows.
  • CISSP: Certified Information Systems Security Professional certification.
  • Microsoft 365: Microsoft 365 Certified: Endpoint Administrator Associate (MD-102).

Responsibilities

  • Deploy and Manage EDR Solutions: Install, configure, test, and monitor EDR capabilities in both on-premises and cloud environments.
  • SOP Development: Create and maintain comprehensive Standard Operating Procedures for EDR functionalities.
  • Training and Support: Lead training sessions for SOC analysts to maximize platform efficiency and threat visibility. Provide ongoing support to SOC functions.
  • Incident Response: Assist in the coordination and analysis of security incidents, contributing to containment, eradication, and recovery efforts.
  • Process Improvement: Continuously evaluate and improve EDR processes and procedures to enhance threat detection and response capabilities.

Benefits

  • healthcare
  • wellness
  • financial
  • retirement
  • family support
  • continuing education
  • time off benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service