Overview
We are seeking an experienced Cyber Security Specialist with a strong focus on Endpoint Detection & Response (EDR) technologies. In this remote position, the specialist will work on configuring, deploying, and optimizing EDR platforms while collaborating with various security teams. The primary goal is to enhance endpoint security controls and support security tooling evaluations through technical expertise and practical implementation.
Responsibilities
- Configure, administer, and optimize enterprise EDR platforms.
- Deploy and onboard endpoints across large enterprise environments.
- Develop and tune detection policies, prevention rules, exclusions, and response workflows.
- Investigate endpoint security events and provide technical remediation guidance.
- Lead and support Proof of Concept (POC) engagements for endpoint security technologies.
- Assess EDR platforms based on detection capability, operational effectiveness, and performance.
- Work closely with SOC, Infrastructure, and Desktop Engineering teams to enhance endpoint security controls.
- Integrate EDR tooling with SIEM and wider security platforms as necessary.
Requirements
- Strong hands-on engineering experience with enterprise Endpoint Detection & Response (EDR) platforms.
- Commercial experience configuring and administering Microsoft Defender for Endpoint or CrowdStrike Falcon.
- Experience deploying or migrating enterprise EDR solutions.
- Strong understanding of endpoint security, malware protection, incident response, and threat detection.
- Proficient in investigating endpoint alerts and supporting security incidents.
- Comfortable working in complex enterprise Windows environments.
- Desirable: Experience with PowerShell scripting or automation, Microsoft Intune, and Entra ID.
- Desirable: Knowledge of MITRE ATT&CK and experience managing large enterprise endpoint estates (5,000+ devices).