All remote jobs
Open role
Remote opportunity atSporty Group

Security Platform Engineer

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Published
50Listing views
3Application actions
24 Sep 2026Apply before
Opportunity details

About this role.

AI Summary

The Security Platform Engineer will own the administration, health, and continuous improvement of EDR, XDR, and SIEM platforms in a remote-first environment. The role focuses on tuning detections, reducing false positives, onboarding log sources, and improving security visibility across endpoints, cloud services, servers, and network infrastructure. This engineer will partner with Information Security, Infrastructure, and IT teams to support investigations and convert incident findings into stronger monitoring content. Success requires hands-on experience with enterprise security tools, event analysis, scripting, MITRE ATT&CK, and clear operational documentation.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

4/5
EasyHard

Pace & Pressure

4/5
RelaxedFast-paced

Autonomy Level

4/5
GuidedFull ownership

Communication Load

4/5
IndependentCollaborative
AI insightThis is a technically demanding security engineering position requiring practical expertise across detection engineering, endpoint protection, log pipelines, cloud systems, and incident support. The continuous tuning and cross-functional platform ownership create a fast-moving workload with meaningful operational impact.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianHighly competitive
$145,000
US market range$115k–$175k
AI insightNo employer salary range was provided. Based on the U.S. market, a Security Platform Engineer with enterprise SIEM/EDR administration and detection-engineering responsibilities would typically earn approximately $115,000 to $175,000 annually, with an estimated median base salary of $145,000; bonuses may increase total compensation.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
How would you approach reducing false positives in a SIEM detection rule?

I would first review alert volume, affected assets, event fields, and the behavior that triggers the rule. I would validate the detection against known benign activity, add context such as allowlists or asset/user criticality where appropriate, and test refinements in a controlled manner. I would track the resulting true-positive rate and revisit the logic regularly as environments and attacker techniques change.

What checks would you perform when endpoint agents stop reporting to an EDR platform?

I would verify agent service status, device network connectivity, DNS and proxy configuration, certificate or authentication status, platform reachability, version compatibility, and endpoint policy health. I would also review EDR console telemetry and infrastructure-side logs to determine whether the issue is isolated, policy-related, or a broader service problem. The final outcome would include remediation steps and documentation for recurring triage.

How do you use MITRE ATT&CK when developing detection content?

I map detections and log coverage to relevant ATT&CK techniques to identify where visibility exists and where gaps remain. This helps prioritize use cases based on likely adversary behavior, business risk, and available telemetry. I also use the framework to communicate detection coverage clearly to security and infrastructure stakeholders.

Describe how you would onboard a new cloud log source into a SIEM.

I would identify the required security use cases, confirm the source produces the necessary audit and event data, and configure secure collection and retention. Next, I would validate parsing, field normalization, timestamps, data completeness, and alerting behavior before building dashboards or correlation rules. I would document ownership, expected volume, troubleshooting steps, and ongoing health checks.

What automation opportunities do you see in security platform engineering?

Automation can improve agent-health reporting, enrichment of alerts, detection-rule deployment, log-source validation, access reviews, and routine platform maintenance. Using Python, PowerShell, or Bash, I would prioritize repeatable tasks that reduce analyst effort while preserving auditability and change control. Any automation should include error handling, monitoring, and clear rollback procedures.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.

About the role

Strengthen Sporty’s security monitoring and detection capability by managing, tuning, and continuously improving EDR and SIEM platforms. Ensure security alerts are accurate, actionable, and provide reliable visibility across endpoints, servers, cloud infrastructure, and corporate systems.

What you’ll be doing

  • Administer, maintain, and monitor EDR and SIEM environments.
  • Tune detection rules, correlation logic, and security policies to improve detection quality and reduce false positives.
  • Configure and maintain endpoint policies, agent health, log collection, and platform integrations.
  • Develop and maintain dashboards, reports, alerts, and security use cases.
  • Investigate noisy or ineffective detections and continuously improve alert fidelity.
  • Validate that endpoint protection, log collection, and response capabilities operate as expected.
  • Integrate new log sources and improve visibility across endpoints, servers, cloud services, and network infrastructure.
  • Convert findings from incidents, threat intelligence, vulnerability assessments, and offensive security exercises into improved monitoring content.
  • Monitor platform health, storage, agent connectivity, licensing, and overall service availability.
  • Support the Information Security team during security investigations by improving visibility, detections, and response workflows.
  • Work with Infrastructure and IT teams to onboard new systems into EDR and SIEM.
  • Produce operational documentation, standard operating procedures, and platform runbooks.
  • Track detection coverage, platform performance, and continuous improvement initiatives.

What you’ll bring

  • Experience administering enterprise SIEM, XDR, or EDR platforms.
  • Hands on experience with Wazuh, Trend Micro Vision One, Microsoft Defender XDR, Microsoft Sentinel, Elastic Security, Splunk, or similar platforms.
  • Strong understanding of endpoint security, Windows, Linux, macOS, Active Directory, cloud environments, and network security.
  • Experience tuning detection rules and reducing false positives.
  • Familiarity with log collection, parsing, correlation, and security event analysis.
  • Understanding of MITRE ATT&CK and common attacker techniques.
  • Experience writing automation or scripting using Python, PowerShell, or Bash.
  • Strong analytical and troubleshooting skills.
  • Excellent documentation and communication skills.

What’s in it for you

  • Sporty is a remote-first company in pursuit of sustainability
  • A competitive salary plus individual performance-based bonuses every quarter
  • 28 days paid annual leave
  • Core working hours of 10am-3pm in your local time zone, with flexibility outside of these hours
  • Referral bonuses and flash bonuses
  • Top-of-the-line equipment
  • Annual company retreats that provide opportunities to connect and collaborate with colleagues from around the world

Interview Process

  • Remote video screening with our Talent Acquisition Team
  • Online assessment via Hackerrank
  • Remote video interview with Team Members (60 Mins)
  • Final discussion with the hiring manager (60 mins)

If you’re interested, we encourage you to apply! Every application is reviewed by a member of our team and we aim to respond within 48 hours.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.
Application method

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. View safety guidance.

Log in to save
One quick step before you apply

Create your free account, then apply.

Build a more organized job search on Jobicy and continue to the employer's application when you're ready.

  • Never lose a promising opportunitySave roles and return to them from your dashboard.
  • See your entire search at a glanceTrack applications, stages and next steps in one place.
  • Get matched with relevant remote jobsChoose the alerts and digests that work for you.
or continue without an account
Applying is free. The employer's application opens in a new tab.
Add alert
Jobs Talent AI Tools Salaries
Menu