3 дня назад
Security Platform Engineer (SIEM/EDR)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Platform Engineer (SIEM/EDR): Strengthening security monitoring and detection across endpoints, servers, cloud infrastructure, and corporate systems with an accent on EDR and SIEM administration, detection tuning, and visibility. Focus on reducing false positives, integrating log sources, improving alert fidelity, and supporting incident investigations through reliable detection and response workflows.
Location: Europe - Remote
Company
is a remote-first company focused on sustainability.
What you will do
- Administer, maintain, and monitor enterprise EDR, XDR, and SIEM environments.
- Tune detection rules, correlation logic, endpoint policies, and security use cases to improve alert quality and reduce false positives.
- Configure log collection, integrations, dashboards, reports, alerts, and endpoint agent health monitoring.
- Integrate new log sources across endpoints, servers, cloud services, network infrastructure, and corporate systems.
- Improve monitoring content using findings from incidents, threat intelligence, vulnerability assessments, and offensive security exercises.
- Support security investigations, platform health monitoring, operational documentation, and continuous improvement initiatives.
Requirements
- Experience administering enterprise SIEM, XDR, or EDR platforms.
- Hands-on experience with Wazuh, Trend Micro Vision One, Microsoft Defender XDR, Microsoft Sentinel, Elastic Security, Splunk, or similar platforms.
- Strong knowledge of endpoint security, Windows, Linux, macOS, Active Directory, cloud environments, and network security.
- Experience tuning detection rules, reducing false positives, and analyzing security events.
- Understanding of MITRE ATT&CK and common attacker techniques.
- Experience with Python, PowerShell, or Bash automation, together with strong analytical, troubleshooting, documentation, and communication skills.
Culture & Benefits
- Remote-first work with core hours from 10am to 3pm in the local time zone and flexibility outside those hours.
- Competitive salary with individual performance-based quarterly bonuses.
- 28 days of paid annual leave.
- Top-of-the-line equipment, referral bonuses, and flash bonuses.
- Annual company retreats with colleagues from around the world.
Hiring process
- Remote video screening with the Talent Acquisition Team.
- Online HackerRank assessment.
- Remote video interview with team members followed by a final discussion with the hiring manager.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 дней назад
Security Engineer (Fintech)
5 дней назад
Security Engineer (Cybersecurity)
6 дней назад
Senior Security Monitoring Analyst (Cybersecurity)
3 500€
5 дней назад
SOC Analyst (Cybersecurity)
7 дней назад
Senior Detection & Response Engineer (Cybersecurity)
6 дней назад