All remote jobs

EDR Engineer / Senior EDR Engineer

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Remote from
USA
Salary
USD 78,500–117,500 / yr
Department
Cybersecurity
Employment
Full Time
Experience
Senior
Published
Apply before
5 Nov 2026
Listing views
28
Application actions
0
Application toolkit

Make your next move.

Prepare your resume, explore your fit, and draft a cover letter for this opportunity.

AI Summary

The role, at a glance.

Recorded Future is hiring an EDR Engineer/Senior EDR Engineer to administer, configure, and maintain enterprise endpoint detection and response platforms within its Incident Response team. The role manages EDR fleet health, detection policies, cloud workload protection, integrations with SIEM/SOAR tools, and endpoint containment during active incidents. Candidates need at least three years of enterprise EDR experience, scripting ability, strong Windows/macOS/Linux knowledge, and familiarity with cloud security and forensic practices. This is a remote US full-time position with occasional after-hours availability for urgent incident response and restoration work.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

4/5
EasyHard

Pace & Pressure

4/5
RelaxedFast-paced

Autonomy Level

4/5
GuidedFull ownership

Communication Load

4/5
IndependentCollaborative
AI insightThe role requires hands-on expertise across multiple EDR platforms, endpoint operating systems, cloud workloads, detection engineering, and incident-response procedures. It also carries operational responsibility for reliable telemetry and urgent support during security incidents.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate
$98,000
US market range$85k–$135k
AI insightThe disclosed US base-salary range is $78,500 to $117,500 yearly, producing an offer midpoint of $98,000. A typical US market base-pay range for an EDR/security engineer with roughly 3+ years of experience is estimated at $85,000 to $135,000 annually; senior-level expertise in detection engineering, cloud security, and incident response can place compensation toward the upper end or above this range. Incentive compensation and equity may be available but are not included in the stated base salary.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
How would you investigate a sudden decline in EDR agent health across a large endpoint fleet?

I would first scope the affected operating systems, agent versions, network segments, and timing of the failures. I would review console telemetry, deployment logs, proxy and DNS connectivity, certificate status, recent policy or software changes, and endpoint resource utilization. After identifying the common cause, I would test remediation on a small group, deploy through approved change control, and validate recovery through agent check-ins and telemetry quality metrics.

How do you reduce false positives without weakening endpoint detection coverage?

I begin by validating the alert logic against endpoint telemetry, known-good administrative activity, and threat intelligence. I tune detections with narrow, explainable exclusions such as signed binaries, approved paths, specific service accounts, or environmental context rather than broadly suppressing behavior. I document each change, monitor detection results after deployment, and periodically retest the rule against relevant adversary techniques.

Describe how you would support an incident involving a potentially compromised endpoint.

I would coordinate with the incident lead to preserve evidence and determine whether containment is required. Using the EDR platform, I would isolate the endpoint if authorized, collect relevant process, network, persistence, and file artifacts, and execute approved live-response commands or scripts. I would then help eradicate persistence, restore the system safely, strengthen relevant policies, and document findings for post-incident improvement.

What is your approach to integrating EDR data with a SIEM or SOAR platform?

I would confirm the required use cases, such as alert enrichment, correlation, automated containment, or case creation, before configuring the integration. I would validate API permissions, event schemas, field mappings, ingestion reliability, alert deduplication, and sensitive-data handling. Finally, I would test end-to-end workflows with representative detections and maintain runbooks for failures, token rotation, and escalation.

How have you used scripting to improve endpoint-security operations?

I use PowerShell, Python, or Bash to automate repetitive tasks such as agent-health reporting, endpoint inventory reconciliation, policy validation, data collection, and bulk investigation queries. I design scripts with input validation, least-privilege access, logging, error handling, and a safe test mode. For production use, I store code in version control, document its purpose and rollback approach, and follow formal change-management requirements.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.
Opportunity details

About this role.

With 1,000+ intelligence professionals serving over 1,900 clients worldwide, Recorded Future is the world’s most advanced, and largest, intelligence company!

The EDR Security Engineer is responsible for the technical administration, configuration, and maintenance of Endpoint Detection and Response (EDR) platforms. As a member of the Incident Response (IR) team, this role ensures the integrity of endpoint telemetry and the effectiveness of detection logic. You will manage multiple EDR solutions across a diverse environment and provide secondary engineering support for the broader security toolset as necessary. As a critical member of the IR function, this position requires occasional availability after-hours to assist with urgent incident containment and system restoration.

What You’ll Do:

EDR Administration & Fleet Health: Oversee the deployment, lifecycle management, and configuration of multiple enterprise EDR platforms (e.g., CrowdStrike, SentinelOne, Microsoft Defender for Endpoint). Monitor and maintain agent health across all managed endpoints, troubleshooting failures and performance issues to maintain established service levels.

Policy & Detection Engineering: Develop and refine detection policies and indicators to improve detection rates and minimize false positive alerts. Translate threat intelligence into actionable endpoint rules to ensure high-fidelity alerting.

Cloud Workload Protection: Manage security deployments across multi-cloud environments (AWS, Azure, or GCP). Ensure consistent telemetry and protection for virtual machines and containerized workloads, utilizing cloud-native security services as required.

Systems Integration & Tooling Support: Work with engineering teams to maintain integrations between EDR consoles and existing SIEM/SOAR platforms. Provide secondary technical support for auxiliary security technologies, including Audit and DLP tools.

Incident Response Support: Assist IR analysts during active security incidents by performing endpoint containment, executing live response scripts, and conducting remote data collection. Assist in the restoration of systems and the hardening of endpoint policies post-incident.

Operational Reliability & Documentation: Adhere to formal change management processes for all policy modifications. Maintain clear technical documentation, Standard Operating Procedures (SOPs), and configuration baselines for internal stakeholders.

What You’ll Bring:

  • Experience: Minimum of 3 years of professional experience managing EDR solutions in an enterprise environment.
  • Scripting: Proficiency in PowerShell, Python, or Bash for task automation and large-scale data querying.
  • Operating Systems: Comprehensive knowledge of Windows, macOS, and Linux internals, specifically regarding system processes, registry/configuration files, and logging mechanisms.
  • Networking: Understanding of TCP/IP, DNS, and proxy configurations as they relate to agent-to-console communication.
  • Cloud Platforms: Technical familiarity with AWS, Azure, or GCP security services (e.g., GuardDuty, Microsoft Defender for Cloud).
  • Tooling: Experience with secondary security platforms such as Splunk, Tines, Palo Alto XSOAR, or Zscaler.
  • Forensics: Familiarity with digital forensics and proactive threat hunting methodologies and tools.
  • Certifications: Relevant professional certifications such as GCFA, GCIA, or platform-specific administrator certifications.
  • Problem Solving: Demonstrated ability to diagnose complex technical issues within the security stack and endpoint OS.

The base salary range for this full-time position is $78,500 – $117,500. Our salary ranges are determined by role, level, and location. The salary displayed reflects the range for new hire salaries for the position across all US locations. Within the range, individual pay is determined by state, work location and additional factors, including job-related skills, experience, and relevant education or training. This position may be eligible for incentive compensation, equity, and medical, dental, vision, life insurance and 401K. Your recruiter can share more about the specific details of the compensation and benefit package during the hiring process.

#LI-Remote

Why should you join Recorded Future?
Recorded Future employees (or “Futurists”), represent over 40 nationalities and embody our core values of having high standards, practicing inclusion, and acting ethically. Our dedication to empowering clients with intelligence to disrupt adversaries has earned us a 4.6-star user rating on G2 and more than 50% of Fortune 100 companies as customers.

Want more info?
Blog & Podcast: Learn everything you want to know (and maybe some things you’d rather not know) about the world of cyber threat intelligence
Linkedin, Instagram & Twitter: What’s happening at Recorded Future
The Record: The Record is a cybersecurity news publication that explores the untold stories in this rapidly changing field
Timeline: History of Recorded Future
Recognition: Check out our awards and announcements

We are committed to maintaining an environment that attracts and retains talent from a diverse range of experiences, backgrounds and lifestyles. By ensuring all feel included and respected for being unique and bringing their whole selves to work, Recorded Future is made a better place every day.

If you need any accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to our recruiting team at careers@recordedfuture.com

Recorded Future is an equal opportunity and affirmative action employer and we encourage candidates from all backgrounds to apply. Recorded Future does not discriminate based on race, religion, color, national origin, gender including pregnancy, sexual orientation, gender identity, age, marital status, veteran status, disability or any other characteristic protected by law.

Recorded Future will not discharge, discipline or in any other manner discriminate against any employee or applicant for employment because such employee or applicant has inquired about, discussed, or disclosed the compensation of the employee or applicant or another employee or applicant.

Recorded Future does not administer a lie detector test as a condition of employment or continued employment. This is in compliance with the law of the Commonwealth of Massachusetts, and in alignment with our hiring practices across all jurisdictions.

Recorded Future maintains a drug-free workplace.

Note: Our interview process for all final-round candidates requires a mandatory in-person interview or a live, scheduled video conference with the hiring manager. We do not conduct interviews via instant messaging or text. All communications during the application process will come from individuals within our HR department via their Recorded Future email address.


Notice to Agency and Search Firm Representatives: Recorded Future will not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to Recorded Future, including those sent to our employees or through our website, will become the property of Recorded Future. Recorded Future will not be liable for any fees related to unsolicited resumes.

Agencies must have a valid written agreement in place with Recorded Future’s recruitment team and must receive written authorization before submitting resumes. Submissions made without such agreements and authorization will not be accepted and no fees will be paid.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. .

Log in to save
One quick step before you apply

Sign in to continue.

Sign in or create a free account to continue to the employer's application.

Applying is free. After signing in, return to this job and select Apply Now.
Add alert
Jobs Talent AI Tools Salaries
Menu