[All remote jobs](https://jobicy.com/jobs.md)Open role[![Sporty Group logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8e6c246a-221.png)](https://jobicy.com/company/sporty-group.md)Remote opportunity at[Sporty Group](https://jobicy.com/company/sporty-group.md)

# Security Platform Engineer

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/sporty-group.md)Share24 Aug 2026Published56Listing views4Application actions24 Sep 2026Apply before  Opportunity details

## About this role.

AI SummaryThe Security Platform Engineer will own the administration, health, and continuous improvement of EDR, XDR, and SIEM platforms in a remote-first environment. The role focuses on tuning detections, reducing false positives, onboarding log sources, and improving security visibility across endpoints, cloud services, servers, and network infrastructure. This engineer will partner with Information Security, Infrastructure, and IT teams to support investigations and convert incident findings into stronger monitoring content. Success requires hands-on experience with enterprise security tools, event analysis, scripting, MITRE ATT&CK, and clear operational documentation.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

4/5EasyHard

### Pace & Pressure

4/5RelaxedFast-paced

### Autonomy Level

4/5GuidedFull ownership

### Communication Load

4/5IndependentCollaborative

AI insightThis is a technically demanding security engineering position requiring practical expertise across detection engineering, endpoint protection, log pipelines, cloud systems, and incident support. The continuous tuning and cross-functional platform ownership create a fast-moving workload with meaningful operational impact.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianHighly competitive$145,000US market range$115k–$175k0$193k

AI insightNo employer salary range was provided. Based on the U.S. market, a Security Platform Engineer with enterprise SIEM/EDR administration and detection-engineering responsibilities would typically earn approximately $115,000 to $175,000 annually, with an estimated median base salary of $145,000; bonuses may increase total compensation.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Security Engineering](https://jobicy.com/jobs?search_keywords=Security%20Engineering.md)[SIEM](https://jobicy.com/jobs?search_keywords=SIEM.md)[EDR](https://jobicy.com/jobs?search_keywords=EDR.md)[XDR](https://jobicy.com/jobs?search_keywords=XDR.md)[Detection Engineering](https://jobicy.com/jobs?search_keywords=Detection%20Engineering.md)[Microsoft Sentinel](https://jobicy.com/jobs?search_keywords=Microsoft%20Sentinel.md)[Splunk](https://jobicy.com/jobs?search_keywords=Splunk.md)[MITRE ATT&CK](https://jobicy.com/jobs?search_keywords=MITRE%20ATTCK.md)[Python](https://jobicy.com/jobs?search_keywords=Python.md)[Incident Response](https://jobicy.com/jobs?search_keywords=Incident%20Response.md)

Sample interview questionsHow would you approach reducing false positives in a SIEM detection rule?I would first review alert volume, affected assets, event fields, and the behavior that triggers the rule. I would validate the detection against known benign activity, add context such as allowlists or asset/user criticality where appropriate, and test refinements in a controlled manner. I would track the resulting true-positive rate and revisit the logic regularly as environments and attacker techniques change.

What checks would you perform when endpoint agents stop reporting to an EDR platform?

I would verify agent service status, device network connectivity, DNS and proxy configuration, certificate or authentication status, platform reachability, version compatibility, and endpoint policy health. I would also review EDR console telemetry and infrastructure-side logs to determine whether the issue is isolated, policy-related, or a broader service problem. The final outcome would include remediation steps and documentation for recurring triage.

How do you use MITRE ATT&CK when developing detection content?

I map detections and log coverage to relevant ATT&CK techniques to identify where visibility exists and where gaps remain. This helps prioritize use cases based on likely adversary behavior, business risk, and available telemetry. I also use the framework to communicate detection coverage clearly to security and infrastructure stakeholders.

Describe how you would onboard a new cloud log source into a SIEM.

I would identify the required security use cases, confirm the source produces the necessary audit and event data, and configure secure collection and retention. Next, I would validate parsing, field normalization, timestamps, data completeness, and alerting behavior before building dashboards or correlation rules. I would document ownership, expected volume, troubleshooting steps, and ongoing health checks.

What automation opportunities do you see in security platform engineering?

Automation can improve agent-health reporting, enrichment of alerts, detection-rule deployment, log-source validation, access reviews, and routine platform maintenance. Using Python, PowerShell, or Bash, I would prioritize repeatable tasks that reduce analyst effort while preserving auditability and change control. Any automation should include error handling, monitoring, and clear rollback procedures.

## About the role

Strengthen Sporty’s security monitoring and detection capability by managing, tuning, and continuously improving EDR and SIEM platforms. Ensure security alerts are accurate, actionable, and provide reliable visibility across endpoints, servers, cloud infrastructure, and corporate systems.

## What you’ll be doing

* Administer, maintain, and monitor EDR and SIEM environments.
* Tune detection rules, correlation logic, and security policies to improve detection quality and reduce false positives.
* Configure and maintain endpoint policies, agent health, log collection, and platform integrations.
* Develop and maintain dashboards, reports, alerts, and security use cases.
* Investigate noisy or ineffective detections and continuously improve alert fidelity.
* Validate that endpoint protection, log collection, and response capabilities operate as expected.
* Integrate new log sources and improve visibility across endpoints, servers, cloud services, and network infrastructure.
* Convert findings from incidents, threat intelligence, vulnerability assessments, and offensive security exercises into improved monitoring content.
* Monitor platform health, storage, agent connectivity, licensing, and overall service availability.
* Support the Information Security team during security investigations by improving visibility, detections, and response workflows.
* Work with Infrastructure and IT teams to onboard new systems into EDR and SIEM.
* Produce operational documentation, standard operating procedures, and platform runbooks.
* Track detection coverage, platform performance, and continuous improvement initiatives.

## What you’ll bring

* Experience administering enterprise SIEM, XDR, or EDR platforms.
* Hands on experience with Wazuh, Trend Micro Vision One, Microsoft Defender XDR, Microsoft Sentinel, Elastic Security, Splunk, or similar platforms.
* Strong understanding of endpoint security, Windows, Linux, macOS, Active Directory, cloud environments, and network security.
* Experience tuning detection rules and reducing false positives.
* Familiarity with log collection, parsing, correlation, and security event analysis.
* Understanding of MITRE ATT&CK and common attacker techniques.
* Experience writing automation or scripting using Python, PowerShell, or Bash.
* Strong analytical and troubleshooting skills.
* Excellent documentation and communication skills.

## What’s in it for you

* Sporty is a remote-first company in pursuit of sustainability
* A competitive salary plus individual performance-based bonuses every quarter
* 28 days paid annual leave
* Core working hours of 10am-3pm in your local time zone, with flexibility outside of these hours
* Referral bonuses and flash bonuses
* Top-of-the-line equipment
* Annual company retreats that provide opportunities to connect and collaborate with colleagues from around the world

## Interview Process

* Remote video screening with our Talent Acquisition Team
* Online assessment via Hackerrank
* Remote video interview with Team Members (60 Mins)
* Final discussion with the hiring manager (60 mins)

If you’re interested, we encourage you to apply! Every application is reviewed by a member of our team and we aim to respond within 48 hours.

Show more

[Apply now >](https://jobicy.com/jobs/151442-security-platform-engineer.md)

>  Annual salary information is not provided for this position. Explore salary ranges for similar roles in our [Salary Directory ›](https://jobicy.com/salaries.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Docplanner logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/84f2fa86-221.png)
Docplanner  Aug 24

### [Senior Platform Security Engineer (100% Remote within Poland)](https://jobicy.com/jobs/151521-senior-platform-security-engineer-100-remote-within-poland.md)

Welcome to the good side of tech 👋 You might have heard about us, but with a different name: Znany Lekarz. It all started 12 years ago when we asked…

*
![Docplanner logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/84f2fa86-221.png)
Docplanner  Aug 24

### [Senior Platform Security Engineer (100% Remote within Spain)](https://jobicy.com/jobs/151520-senior-platform-security-engineer-100-remote-within-spain.md)

Welcome to the good side of tech 👋 You might have heard about us, but with a different name: Doctoralia. It all started 12 years ago when we asked ourselves:…

*
![Qventus logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2022/01/0ad7e933ffa7b62281cc4b26710abfab.jpeg)
Qventus  Aug 24

### [Senior Security Engineer](https://jobicy.com/jobs/151504-senior-security-engineer-2.md)

On this journey for over 12 years, Qventus is leading the transformation of healthcare. We enable hospitals to focus on what matters most: patient care. Our innovative solutions harness the…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Aug 24

### [Blockchain Security Engineer – (Solidity / Rust / Golang)](https://jobicy.com/jobs/151470-blockchain-security-engineer-solidity-rust-golang.md)

About the Company CertiK is the largest blockchain security auditor and provides a comprehensive suite of tools to secure the industry at scale. To date, CertiK has worked with over…

*
![Lakeshore Learning Materials, LLC logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/d8ba23f6-221.jpg)
Lakeshore Learning Materials, LLC  Aug 23

### [Manager of IT Security](https://jobicy.com/jobs/149591-manager-of-it-security.md)

Company DescriptionAt Lakeshore, we create innovative learning materials and world-class guest experiences for teachers, parents and children. Since 1954, we’ve grown into a global community—with a thriving e-commerce business, multiple…

*
![Tenable logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/01879e02-221.jpg)
Tenable  Aug 22

### [Senior Director, Ecosystem & Solution Architectures – Technical Alliances](https://jobicy.com/jobs/151413-senior-director-ecosystem-solution-architectures-technical-alliances.md)

Who is Tenable? Tenable® is the Exposure Management company. Over 40,000 organizations around the globe rely on Tenable to understand and reduce cyber risk. Our global employees support 65 percent…

*
![Canonical Ltd. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b4d068a9-221-1.png)
Canonical Ltd.  Aug 22

### [Security Risk Management Specialist](https://jobicy.com/jobs/149564-security-risk-management-specialist.md)

In security risk management we’re looking to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security…

*
![Canonical Ltd. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b4d068a9-221-1.png)
Canonical Ltd.  Aug 22

### [Ubuntu Security Engineer](https://jobicy.com/jobs/149565-ubuntu-security-engineer.md)

Canonical is a leading provider of open source software and operating systems to the global enterprise and technology markets. Our platform, Ubuntu, is very widely used in breakthrough enterprise initiatives…

*
![Canonical Ltd. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b4d068a9-221-1.png)
Canonical Ltd.  Aug 22

### [Senior Security Operations Engineer](https://jobicy.com/jobs/149578-senior-security-operations-engineer.md)

The Canonical Security Operations team is hiring for a Senior or Staff engineer. The Security Operations team is responsible for designing, building, and operating a world-class Security Operations Center, and…

*
![Canonical Ltd. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b4d068a9-221-1.png)
Canonical Ltd.  Aug 22

### [Head of Security Operations](https://jobicy.com/jobs/149541-head-of-security-operations.md)

This global leadership role in cyber security is to manage the Security Operations (SecOps) team responsible for design, implementation and evolution of Canonical security practices, techniques, tools, systems and policies….