远程工作雷达

安全平台工程师

Security Platform Engineer

开发工程限定地区(需当地身份)
公司sportygroup
薪资未公开
工作地点Europe - Remote
地域资格限定地区(需当地身份)
时区要求无特别要求
用工类型未标注
发布时间25 天前
数据来源Greenhouse
前往企业招聘页投递 →
注意地域限制:该职位明确限定在 Europe - Remote 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

职位描述

通过管理、调优和持续改进EDR和SIEM平台,加强Sporty的安全监控和检测能力。确保安全警报准确、可操作,并在终端、服务器、云基础设施和企业系统上提供可靠的可见性。

你将负责的工作

  • 管理、维护和监控EDR和SIEM环境。
  • 调整检测规则、相关逻辑和安全策略,以提高检测质量并减少误报。
  • 配置和维护终端策略、代理健康状态、日志收集和平台集成。
  • 开发和维护仪表盘、报告、警报和安全使用案例。
  • 调查嘈杂或无效的检测,并持续提升警报的准确性。
  • 验证端点保护、日志收集和响应功能是否按预期运行。
  • 集成新的日志源,并提升对终端、服务器、云服务和网络基础设施的可见性。
  • 将事件、威胁情报、漏洞评估和进攻性安全演练中的发现转化为改进的监控内容。
  • 监控平台健康状况、存储、代理连接、许可和整体服务可用性。
  • 在安全调查期间为信息安全团队提供支持,通过提升可见性、检测和响应流程来协助。
  • 与基础设施和IT团队合作,将新系统接入EDR和SIEM。
  • 编写操作文档、标准操作程序和平台操作手册。
  • 跟踪检测覆盖范围、平台性能和持续改进计划。

你将带来的能力

  • 具备管理企业级SIEM、XDR或EDR平台的经验。
  • 具有使用Wazuh、Trend Micro Vision One、Microsoft Defender XDR、Microsoft Sentinel、Elastic Security、Splunk或类似平台的实际操作经验。
  • 对端点安全、Windows、Linux、macOS、Active Directory、云环境和网络安全有深入理解。
  • 具备调整检测规则和减少误报的经验。
  • 熟悉日志收集、解析、关联和安全事件分析。
  • 了解MITRE ATT&CK框架和常见的攻击技术。
  • 具备使用Python、PowerShell或Bash编写自动化脚本的经验。
  • 具备强大的分析和故障排除能力。
  • 具备优秀的文档编写和沟通能力。

你能获得什么

  • Sporty是一家以远程办公为主的公司,致力于实现…
查看英文原文

About the role

Strengthen Sporty’s security monitoring and detection capability by managing, tuning, and continuously improving EDR and SIEM platforms. Ensure security alerts are accurate, actionable, and provide reliable visibility across endpoints, servers, cloud infrastructure, and corporate systems.

What you'll be doing

  • Administer, maintain, and monitor EDR and SIEM environments.
  • Tune detection rules, correlation logic, and security policies to improve detection quality and reduce false positives.
  • Configure and maintain endpoint policies, agent health, log collection, and platform integrations.
  • Develop and maintain dashboards, reports, alerts, and security use cases.
  • Investigate noisy or ineffective detections and continuously improve alert fidelity.
  • Validate that endpoint protection, log collection, and response capabilities operate as expected.
  • Integrate new log sources and improve visibility across endpoints, servers, cloud services, and network infrastructure.
  • Convert findings from incidents, threat intelligence, vulnerability assessments, and offensive security exercises into improved monitoring content.
  • Monitor platform health, storage, agent connectivity, licensing, and overall service availability.
  • Support the Information Security team during security investigations by improving visibility, detections, and response workflows.
  • Work with Infrastructure and IT teams to onboard new systems into EDR and SIEM.
  • Produce operational documentation, standard operating procedures, and platform runbooks.
  • Track detection coverage, platform performance, and continuous improvement initiatives.

What you'll bring

  • Experience administering enterprise SIEM, XDR, or EDR platforms.
  • Hands on experience with Wazuh, Trend Micro Vision One, Microsoft Defender XDR, Microsoft Sentinel, Elastic Security, Splunk, or similar platforms.
  • Strong understanding of endpoint security, Windows, Linux, macOS, Active Directory, cloud environments, and network security.
  • Experience tuning detection rules and reducing false positives.
  • Familiarity with log collection, parsing, correlation, and security event analysis.
  • Understanding of MITRE ATT&CK and common attacker techniques.
  • Experience writing automation or scripting using Python, PowerShell, or Bash.
  • Strong analytical and troubleshooting skills.
  • Excellent documentation and communication skills.

What's in it for you

  • Sporty is a remote-first company in pursuit of sustainability
  • A competitive salary plus individual performance-based bonuses every quarter
  • 28 days paid annual leave
  • Core working hours of 10am-3pm in your local time zone, with flexibility outside of these hours
  • Referral bonuses and flash bonuses
  • Top-of-the-line equipment
  • Annual company retreats that provide opportunities to connect and collaborate with colleagues from around the world

Interview Process

  • Remote video screening with our Talent Acquisition Team
  • Online assessment via Hackerrank
  • Remote video interview with Team Members (60 Mins)
  • Final discussion with the hiring manager (60 mins)

If you're interested, we encourage you to apply! Every application is reviewed by a member of our team and we aim to respond within 48 hours.

本页面信息整理自 Greenhouse,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

前端工程师

sportygroupGlobal - Remote2026-01-14
开发工程全球可投

← 返回全部职位