Responsibilities
- Design, implement, and support key security operations center systems with a focus on malware analysis and sandboxing technologies
- Design, implement, and support key security operations center systems with a focus on analyst workstations and Windows-based investigation virtual machines
- Design, implement, and support key security operations center systems with a focus on Endpoint Detection and Response or Extended Detection and Response platforms
- Design, implement, and support key security operations center systems with a focus on email security infrastructure
- Design, implement, and support key security operations center systems with a focus on vulnerability scanning frameworks
- Serve as the technical authority for security operations center platforms, ensuring alignment with architectural standards, lifecycle planning, updates, and retirement
- Ensure security operations platforms are built to support scalability, uptime, speed, and integrity of forensic data
- Collaborate with IT and infrastructure teams to resolve interdependencies, access controls, and system requirements affecting security operations
- Lead engineering, configuration, and operational oversight of the enterprise-wide EDR platform
- Establish and enforce standards for EDR health, including sensor deployment, policy uniformity, software versions, and asset ownership
- Track EDR performance indicators and address deficiencies that affect threat detection or response effectiveness
- Build test methodologies to verify EDR detection rules, configurations, and automated response functions
- Act as the technical lead for detection engineering, improving detection accuracy through enhanced tools, data streams, and data quality
- Verify that endpoint sensors, sandboxes, and auxiliary tools produce necessary telemetry for detection logic and incident investigations
- Work with teams to refine and validate detection rules, tuning processes, and automated testing workflows
- Convert knowledge of emerging threats and adversarial behaviors into requirements for tooling and data collection
- Build and manage secure environments for malware execution and analysis that enable consistent and safe examination
- Provide technical support to security and incident response teams with tools for static and dynamic malware examination
- Enhance sandbox environments to more accurately reflect enterprise systems and common attacker methods
- Analyze new offensive techniques, malware variants, and evasion strategies to identify enterprise-wide detection and prevention improvements
- Detect shortcomings in current tools or configurations that fail to expose malicious activity
- Assess new security solutions and features to close gaps in detection, analysis, or response capabilities
- Deliver practical, engineering-based recommendations informed by real-world security operations experience
- Automate repetitive security operations tasks such as system checks, validation routines, deployments, and reporting
- Create scripts and utilities using PowerShell, Python, or similar languages to minimize manual effort and reduce analyst workload