Startups

EDR Engineer / Senior EDR Engineer

Recorded Future · Remote - USA · Remote

← All jobs
About Recorded Future

Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization. Backed by GV and Insight.

About the role

EDR Administration & Fleet Health: Oversee the deployment, lifecycle management, and configuration of multiple enterprise EDR platforms (e.g., CrowdStrike, SentinelOne, Microsoft Defender for Endpoint). Monitor and maintain agent health across all managed endpoints, troubleshooting failures and performance issues to maintain established service levels.

What they're looking for

  • Experience: Minimum of 3 years of professional experience managing EDR solutions in an enterprise environment
  • Scripting: Proficiency in PowerShell, Python, or Bash for task automation and large-scale data querying
  • Operating Systems: Comprehensive knowledge of Windows, macOS, and Linux internals, specifically regarding system processes, registry/configuration files, and logging mechanisms
  • Networking: Understanding of TCP/IP, DNS, and proxy configurations as they relate to agent-to-console communication
  • Cloud Platforms: Technical familiarity with AWS, Azure, or GCP security services (e.g., GuardDuty, Microsoft Defender for Cloud)
  • Tooling: Experience with secondary security platforms such as Splunk, Tines, Palo Alto XSOAR, or Zscaler
More about this role

With 1,000+ intelligence professionals serving over 1,900 clients worldwide, Recorded Future is the world’s most advanced, and largest, intelligence company!

The EDR Security Engineer is responsible for the technical administration, configuration, and maintenance of Endpoint Detection and Response (EDR) platforms. As a member of the Incident Response (IR) team, this role ensures the integrity of endpoint telemetry and the effectiveness of detection logic. You will manage multiple EDR solutions across a diverse environment and provide secondary engineering support for the broader security toolset as necessary. As a critical member of the IR function, this position requires occasional availability after-hours to assist with urgent incident containment and system restoration.

EDR Administration & Fleet Health: Oversee the deployment, lifecycle management, and configuration of multiple enterprise EDR platforms (e.g., CrowdStrike, SentinelOne, Microsoft Defender for Endpoint). Monitor and maintain agent health across all managed endpoints, troubleshooting failures and performance issues to maintain established service levels.

Policy & Detection Engineering: Develop and refine detection...

Read the full posting on Recorded Future's site ↗

Security

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.