Jobgether

Associate Security Engineer, Security Control Management

Jobgether United States · $75K–$85K/yr

Internet Marketplace Platforms · 11-50 employees

19 h ago
Remote security Junior (0-2 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Associate Security Engineer will administer and maintain managed EDR platforms across customer environments, ensuring endpoint coverage and platform health. They will also perform technical troubleshooting, execute platform changes, and contribute to automation scripts and operational documentation.

What they look for

Endpoint security EDR operations CrowdStrike Falcon SentinelOne Microsoft Defender for Endpoint PowerShell Python Troubleshooting Automation Security policy management Incident response Technical documentation Change management API integration System administration SOC operations

Requirements

Candidates must have at least one year of experience in endpoint security, EDR operations, or a related technical role. Proficiency in at least one major EDR platform and the ability to use PowerShell or Python for automation are required.

Benefits

Flexible Paid Time Off 401(k) with company matching Medical coverage Dental coverage Vision coverage Short-term disability coverage Long-term disability coverage Employee Assistance Program Life insurance Health Savings Account contribution 10 paid holidays

Full description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Associate Security Engineer, Security Control Management based in the United States.

This role supports the day-to-day delivery of managed endpoint security services across a diverse, multi-customer environment. You’ll focus primarily on operating and maintaining EDR platforms, helping ensure endpoint coverage, security policy alignment, and platform health. The position combines hands-on technical troubleshooting with automation, operational support, documentation, and customer collaboration. You’ll work across platforms including CrowdStrike Falcon, SentinelOne, and Microsoft Defender for Endpoint, with structured cross-training available. The role offers close collaboration with senior security engineers, SOC and detection teams, professional services, and customer-facing functions. You’ll also contribute to automation, operational improvements, dashboards, runbooks, and scalable processes that reduce risk and manual effort. Success requires strong troubleshooting skills, disciplined change execution, clear communication, and the ability to manage repeatable security operations across multiple environments.

\n

Accountabilities:

  • Administer managed EDR platforms across customer environments, including configuration, policy maintenance and tuning, agent lifecycle management, operational controls, and regular platform health checks.
  • Execute approved platform changes such as agent upgrades, bulk actions, policy transitions, recovery activities, and migrations while following established change controls, validation procedures, and documentation requirements.
  • Monitor endpoint coverage, agent versions, policy alignment, platform health, and operational exceptions, investigating discrepancies and coordinating remediation when needed.
  • Support agent deployments, console configuration, integrations, and platform migrations under the guidance of senior engineering staff.
  • Investigate endpoint security issues involving agent connectivity, performance, interoperability, policy behavior, detections, exclusions, upgrades, and deployment failures.
  • Collect and analyze endpoint, console, and application evidence to determine root causes and distinguish between EDR platform issues, endpoint conditions, and problems involving other security controls.
  • Resolve support requests within established procedures and escalate complex, high-risk, or vendor-dependent issues with clear technical findings and complete documentation.
  • Work with technology vendors and internal teams to manage support cases, validate remediation approaches, and communicate progress to customer-facing stakeholders.
  • Participate in peer reviews of configuration changes, exclusions, and technical recommendations to minimize operational and customer risk.
  • Use PowerShell, Python, vendor APIs, and approved automation tools to perform repeatable tasks, collect evidence, and reduce manual operational effort.
  • Contribute to scripts, workflows, integrations, dashboards, reports, and health metrics that improve visibility into endpoint coverage, policy compliance, platform status, and recurring issues.
  • Identify recurring incidents, failure patterns, and manual processes that can be standardized or automated, while validating automation outputs and maintaining safeguards for large-scale changes.
  • Maintain engineering repositories, runbooks, operational checklists, knowledge-base materials, and technical documentation.
  • Coordinate assigned operational requests and technical investigations from intake through completion, managing dependencies, status updates, handoffs, documentation, and service expectations.
  • Provide practical guidance on EDR configuration, deployment, platform health, and endpoint security operations within the scope of the managed service.
  • Participate in customer meetings when technical context is required and communicate findings, risks, dependencies, and next steps in clear business language.
  • Develop customer-facing procedures and configuration guidance, and support customer training on routine EDR administration and supported service workflows.
  • Build proficiency across CrowdStrike Falcon, SentinelOne, and Microsoft Defender for Endpoint through hands-on experience, vendor training, and knowledge sharing.
  • Collaborate with SOC, detection engineering, professional services, customer success, and other operational teams to share troubleshooting findings and improve security operations.

Requirements

  • 1+ year of experience in endpoint security, EDR operations, security engineering, systems administration, SOC operations, or a closely related technical role.
  • Hands-on experience administering or supporting at least one of the following: CrowdStrike Falcon, SentinelOne Singularity, or Microsoft Defender for Endpoint.
  • Practical experience troubleshooting Windows endpoints, with familiarity with macOS or Linux endpoint administration considered beneficial.
  • Working knowledge of EDR concepts, endpoint security policies, agent deployment, exclusions, detection triage, and basic endpoint response actions.
  • Ability to use PowerShell, Python, command-line tools, or vendor APIs for troubleshooting, evidence collection, and repeatable operational tasks.
  • Strong ability to analyze technical evidence, document findings accurately, follow change-management controls, and escalate issues with sufficient context for efficient resolution.
  • Clear written and verbal communication skills, with the ability to work effectively with technical teams as well as customer stakeholders.
  • Experience in an MSSP, MDR, SOC, or other multi-customer security operations environment is preferred.
  • Relevant vendor certifications or training are advantageous, including CrowdStrike CCFA, SentinelOne Certified Administrator or Engineer, Microsoft SC-200, or equivalent practical training.
  • Experience with SOAR platforms, SIEM integrations, or security automation tools supporting endpoint security operations is a plus.
  • Understanding of MITRE ATT&CK, common endpoint attack techniques, and how EDR telemetry supports detection and investigation is preferred.
  • Experience supporting large-scale EDR deployments, platform consolidations, or migrations across heterogeneous enterprise environments is beneficial.
  • Familiarity with EDR-native remote response, endpoint querying, hunting, bulk management, and detection validation capabilities is a plus.
  • A collaborative, customer-focused, detail-oriented approach, combined with sound judgment and the ability to manage recurring operational work across multiple customer environments.

Benefits

  • Annual salary of $75,000–$85,000.
  • Flexible Paid Time Off.
  • 401(k) with company matching.
  • Medical, dental, and vision coverage.
  • Voluntary short-term and long-term disability coverage.
  • Employee Assistance Program with mental health support.
  • Voluntary basic, accidental, and other ancillary life insurance options.
  • Health Savings Account contribution when enrolled in the applicable high-deductible health plan.
  • 10 paid holidays annually.
  • Opportunity to work in a collaborative cybersecurity environment spanning managed detection, endpoint security, threat hunting, security research, and incident response.
  • Exposure to leading EDR platforms and opportunities to build broader expertise through structured cross-training and hands-on operational experience.
  • Opportunities to develop skills in security automation, platform engineering, customer support, and scalable security operations.
  • Collaboration with experienced security professionals across engineering, SOC, detection, professional services, and customer-facing teams.

\nHow Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

Similar roles