Managed EDR Engineer I

AI overview

Guide the evolution of Proficio's Managed EDR visibility, detection, and prevention technologies by deploying and optimizing EDR solutions while collaborating across teams.

Proficio is an award-winning managed detection and response (MDR) services provider. We provide 24/7 security monitoring, investigation, alerting and response services to organizations in healthcare, financial services, manufacturing, retail and other industries. Take a video tour of our global network of 24/7 Security Operations Centers (SOCs).

Proficio has been highlighted in Gartner’s Market Guide for Managed Detection and Response Services for the last five consecutive years. MSSP Alert ranks Proficio among the top 250 global Managed Security Services Providers (MSSPs).

We have a track record of innovation. Proficio invented the concept of SOC-as-a-Service. We were the first MSSP to provide automated response services and are the only company in our space with a patent for cyber risk scoring and security posture gap analysis.

Our typical client is a medium to large-sized organization that lacks the in-house resources to address the challenges of a rapidly changing threat landscape. The difficulty of hiring and retaining cybersecurity professionals are widely understood. Our prospective clients are also challenged to effectively harness technology and build hardened processes that reduce the risk of security breaches.

While Proficio has developed a unified service delivery platform designed to meet the needs of the most demanding clients, what sets us apart is the quality and passion of our people. We believe the SOC of the Future will meld the creativity of human intelligence with the power of advanced technologies like AI.

Proficio’s commitment to developing and promoting our team members is unparalleled in our industry. Most of our senior managers were promoted from within.

Summary:

The Managed Infrastructure Services team is seeking an experienced MEDR Threat Engineer who is technical, collaborative, and truly excited about working on endpoint products. In this role, you will bring your in-depth knowledge of the endpoint and detection response tasks so your team can guide the evolution of Proficio's Managed EDR visibility, detection, and prevention technologies. You will work closely with engineering, project managers, Hosted & managed SIEM team, sales, and other departments. You will bring existing knowledge about product EDR best practices and apply them in real life scenarios while continuing to grow your knowledge base across EDR tools. The successful candidate will have the ability to interface and influence cross-functional teams throughout the company.

 

Responsibilities:

  • Deploy, configure, and maintain EDR solutions: MUST - Manage and optimize EDR platforms. This position will focus on Sophos work, but other platforms could include CrowdStrike Falcon, Microsoft Defender for Endpoint. Ensure that endpoints are adequately secured, and all EDR solutions are functioning effectively within the environment.
  • Endpoint Security Management: Administer endpoint security management tools such as antivirus, web filtering, data loss prevention, and spam filtering, focusing on integration and coordination with EDR platforms to ensure a comprehensive security posture.
  • Proactive Threat Hunting: Leverage the full capabilities of EDR tools to proactively hunt for threats across the enterprise environment. Utilize CrowdStrike Falcon's Threat Graph, Defender for Endpoint's advanced hunting queries, and SentinelOne’s behavioral AI to detect undetected threats and abuse.
  • Incident Investigation and Response: Conduct in-depth investigations using EDR solutions to analyze complex account compromises, malware infections, and vulnerabilities. Use advanced detection mechanisms in TrendMicro Vision One and CrowdStrike to understand adversarial behavior and recommend appropriate mitigation strategies.
  • Remediation and Prevention: Identify and implement detection/prevention strategies through EDR platforms. Leverage Microsoft Defender for Endpoint to automate response playbooks and block potential threats, and utilize Apex One to enhance protection against emerging threats.
  • Tactics, Techniques, and Procedures (TTPs): Apply knowledge of adversary TTPs across multiple attack surfaces using EDR tools. Utilize real-time intelligence from CrowdStrike, Defender for EndPoint and from other EDR tools to stay ahead of emerging tactics and enhance detection capabilities.
  • Cross-functional Communication: Lead technical investigations and communicate actionable insights derived from EDR tools to cross-functional teams. Ensure that the analytic findings and mitigations are clear and actionable across different teams.
  • Continuous Improvement: Continuously analyze data from EDR tools like CrowdStrike, Defender for Endppoint. TrendMicro Vision One to identify trends in adversary behavior. Under the direction and guidance of management, help to create new detection rules and adjust EDR settings to ensure optimal performance and coverage.
  • Security Analytics and Data Interpretation: Use data from EDR tools and other EDR platforms to analyze, interpret, and quantify trends. This supports the investigation of threats and validates security incidents.

Requirements

  • 2+ years of experience with IT in a professional work environment
  • 18 months+ of experience assisting with deployment, configuration, or maintenance processes that support the Sophos Enterprise EDR Solutions.  Other beneficial tools include Carbon Black EDR, CrowdStrike Falcon, Microsoft Defender APT, and/or Sentinel One
  • Additional experience in TrendMicro ApexOne, Vision, and/or Cisco AMP are pluses
  • 3+ years of experience in EDR and/or AV; previous work in malware and attack analysis (is Plus), research, investigation, and response highly desirable
  • 1+ years of experience with performing systems administration, including basic troubleshooting and installation, monitoring system performance or availability and performing security upgrades
  • Knowledge of network security architecture concepts including topology, protocols, components, and principles
  • Knowledge of various Enterprise Operating System (OS) configurations and management tools for use during deployment, configuration, and management of EDR solutions

Additional Qualifications:

  • Good to have experience working in a Security Operations Center (SOC) environment including Incident Response, Vulnerability Scanning, Threat Hunting, Network Monitoring/Log Management, or Compliance Management
  • Good to have experience with complimentary Enterprise Security Tools including Security Information & Event Management (SIEM), Threat Intelligence Platforms (TIPs), or Network Monitoring Tools
  • Experience with triaging security events in a security operations center (SOC) environment, leveraging data collected from enterprise security solutions
  • Knowledge of intrusion detection methodologies and techniques for detecting host and network-based intrusions
  • Ability to integrate Cybersecurity data using enterprise or custom tools data aggregation and analysis tools, including Splunk and Elastic

Benefits

  • Salary $80K
  • Peer training and mentoring with upward mobility
  • Health, Dental and Vision plans available first of the month and other benefits available from day 1
  • Unlimited Flex Time Off
  • 401K plan
  • Gym reimbursement
  • Employee Assistance Program
  • Life and Voluntary Life Insurance programs
  • A culture that is flat enough for you to have a “seat at the table”, but layered enough to provide you with mentoring and support
  • A place to work where security is considered a “team sport” – we work together to identify and stop cyber attacks
  • Proficio is an EOE Employer
  • Proficio collects certain personal information upon your submission of an application for an open position. More information is available about your consumer rights and our privacy policy at www.proficio.com/privacypolicy

Perks & Benefits Extracted with AI

  • Health Insurance: Health, Dental and Vision plans available first of the month and other benefits available from day 1
  • Other Benefit: Life and Voluntary Life Insurance programs
  • Paid Time Off: Unlimited Flex Time Off
Salary
$80,000 per year
Get hired quicker

Be the first to apply. Receive an email whenever similar jobs are posted.

Ace your job interview

Understand the required skills and qualifications, anticipate the questions you may be asked, and study well-prepared answers using our sample responses.

Engineer Q&A's
Report this job
Apply for this job