远程工作雷达

EDR工程师 / 高级EDR工程师

EDR Engineer / Senior EDR Engineer

开发工程限定地区(需当地身份)
公司recordedfuture
薪资未公开
工作地点Remote - USA
地域资格限定地区(需当地身份)
时区要求无特别要求
用工类型未标注
发布时间3 天前
数据来源Greenhouse
前往企业招聘页投递 →
注意地域限制:该职位明确限定在 Remote - USA 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

与1000多名情报专家为全球1900多家客户提供服务,Recorded Future是全球最先进、规模最大的情报公司!

EDR安全工程师负责端点检测与响应(EDR)平台的技术管理、配置和维护。作为事件响应(IR)团队的一员,该职位确保端点遥测的完整性以及检测逻辑的有效性。您将管理多种环境中的多个EDR解决方案,并在需要时为更广泛的安全部件提供次级工程支持。作为IR功能的关键成员,此职位需要偶尔在非工作时间待命,以协助紧急事件的遏制和系统恢复。

您将负责:

EDR管理与集群健康:负责多个企业EDR平台(如CrowdStrike、SentinelOne、Microsoft Defender for Endpoint)的部署、生命周期管理和配置。监控并维护所有受管端点的代理健康状况,排查故障和性能问题,以保持既定的服务水平。

策略与检测工程:开发和优化检测策略和指标,以提高检测率并减少误报警。将威胁情报转化为可操作的端点规则,以确保高精度的警报。

云工作负载保护:在多云环境(AWS、Azure或GCP)中管理安全部署。确保虚拟机和容器化工作负载的一致遥测和保护,根据需要使用云原生安全服务。

系统集成与工具支持:与工程团队合作,维护EDR控制台与现有SIEM/SOAR平台的集成。为辅助安全技术(包括审计和DLP工具)提供次级技术支持。

事件响应支持:在安全事件发生期间协助IR分析师,执行端点遏制、运行实时响应脚本并进行远程数据收集。协助系统恢复和事件后端点策略的强化。

运营可靠性与文档:遵循正式的变更管理流程处理所有策略修改。为内部利益相关者维护清晰的技术文档、标准操作程序(SOP)和配置基线。

您将具备:

  • 经验:至少3年专业经验
查看英文原文

With 1,000+ intelligence professionals serving over 1,900 clients worldwide, Recorded Future is the world’s most advanced, and largest, intelligence company!

The EDR Security Engineer is responsible for the technical administration, configuration, and maintenance of Endpoint Detection and Response (EDR) platforms. As a member of the Incident Response (IR) team, this role ensures the integrity of endpoint telemetry and the effectiveness of detection logic. You will manage multiple EDR solutions across a diverse environment and provide secondary engineering support for the broader security toolset as necessary. As a critical member of the IR function, this position requires occasional availability after-hours to assist with urgent incident containment and system restoration.

What You'll Do:

EDR Administration & Fleet Health: Oversee the deployment, lifecycle management, and configuration of multiple enterprise EDR platforms (e.g., CrowdStrike, SentinelOne, Microsoft Defender for Endpoint). Monitor and maintain agent health across all managed endpoints, troubleshooting failures and performance issues to maintain established service levels.

Policy & Detection Engineering: Develop and refine detection policies and indicators to improve detection rates and minimize false positive alerts. Translate threat intelligence into actionable endpoint rules to ensure high-fidelity alerting.

Cloud Workload Protection: Manage security deployments across multi-cloud environments (AWS, Azure, or GCP). Ensure consistent telemetry and protection for virtual machines and containerized workloads, utilizing cloud-native security services as required.

Systems Integration & Tooling Support: Work with engineering teams to maintain integrations between EDR consoles and existing SIEM/SOAR platforms. Provide secondary technical support for auxiliary security technologies, including Audit and DLP tools.

Incident Response Support: Assist IR analysts during active security incidents by performing endpoint containment, executing live response scripts, and conducting remote data collection. Assist in the restoration of systems and the hardening of endpoint policies post-incident.

Operational Reliability & Documentation: Adhere to formal change management processes for all policy modifications. Maintain clear technical documentation, Standard Operating Procedures (SOPs), and configuration baselines for internal stakeholders.

What You'll Bring:

  • Experience: Minimum of 3 years of professional experience managing EDR solutions in an enterprise environment.
  • Scripting: Proficiency in PowerShell, Python, or Bash for task automation and large-scale data querying.
  • Operating Systems: Comprehensive knowledge of Windows, macOS, and Linux internals, specifically regarding system processes, registry/configuration files, and logging mechanisms.
  • Networking: Understanding of TCP/IP, DNS, and proxy configurations as they relate to agent-to-console communication.
  • Cloud Platforms: Technical familiarity with AWS, Azure, or GCP security services (e.g., GuardDuty, Microsoft Defender for Cloud).
  • Tooling: Experience with secondary security platforms such as Splunk, Tines, Palo Alto XSOAR, or Zscaler.
  • Forensics: Familiarity with digital forensics and proactive threat hunting methodologies and tools.
  • Certifications: Relevant professional certifications such as GCFA, GCIA, or platform-specific administrator certifications.
  • Problem Solving: Demonstrated ability to diagnose complex technical issues within the security stack and endpoint OS.

The base salary range for this full-time position is $78,500 - $117,500. Our salary ranges are determined by role, level, and location. The salary displayed reflects the range for new hire salaries for the position across all US locations. Within the range, individual pay is determined by state, work location and additional factors, including job-related skills, experience, and relevant education or training. This position may be eligible for incentive compensation, equity, and medical, dental, vision, life insurance and 401K. Your recruiter can share more about the specific details of the compensation and benefit package during the hiring process.

#LI-Remote
Why should you join Recorded Future?
Recorded Future employees (or “Futurists”), represent over 40 nationalities and embody our core values of having high standards, practicing inclusion, and acting ethically. Our dedication to empowering clients with intelligence to disrupt adversaries has earned us a 4.6-star user rating on G2 and more than 50% of Fortune 100 companies as customers.

Want more info? 
Blog & Podcast: Learn everything you want to know (and maybe some things you’d rather not know) about the world of cyber threat intelligence
Linkedin, Instagram & Twitter: What’s happening at Recorded Future
The Record: The Record is a cybersecurity news publication that explores the untold stories in this rapidly changing field
Timeline: History of Recorded Future
Recognition: Check out our awards and announcements

We are committed to maintaining an environment that attracts and retains talent from a diverse range of experiences, backgrounds and lifestyles.  By ensuring all feel included and respected for being unique and bringing their whole selves to work, Recorded Future is made a better place every day.

If you need any accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to our recruiting team at careers@recordedfuture.com

Recorded Future is an equal opportunity and affirmative action employer and we encourage candidates from all backgrounds to apply. Recorded Future does not discriminate based on race, religion, color, national origin, gender including pregnancy, sexual orientation, gender identity, age, marital status, veteran status, disability or any other characteristic protected by law.

Recorded Future will not discharge, discipline or in any other manner discriminate against any employee or applicant for employment because such employee or applicant has inquired about, discussed, or disclosed the compensation of the employee or applicant or another employee or applicant.

Recorded Future does not administer a lie detector test as a condition of employment or continued employment. This is in compliance with the law of the Commonwealth of Massachusetts, and in alignment with our hiring practices across all jurisdictions.

Recorded Future maintains a drug-free workplace.

Note: Our interview process for all final-round candidates requires a mandatory in-person interview or a live, scheduled video conference with the hiring manager. We do not conduct interviews via instant messaging or text. All communications during the application process will come from individuals within our HR department via their Recorded Future email address.

Notice to Agency and Search Firm Representatives: Recorded Future will not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to Recorded Future, including those sent to our employees or through our website, will become the property of Recorded Future. Recorded Future will not be liable for any fees related to unsolicited resumes.

Agencies must have a valid written agreement in place with Recorded Future's recruitment team and must receive written authorization before submitting resumes. Submissions made without such agreements and authorization will not be accepted and no fees will be paid.

本页面信息整理自 Greenhouse,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

企业客户总监

recordedfutureSeattle, WA - Remote17 天前
市场运营职能支持全球可投

← 返回全部职位