At CyberMaxx, we believe it is our duty to defend against those committed to wide-scale societal disruption through cyberattacks.
We help our customers reduce risk by tightly integrating MDR with offensive security, threat hunting, security research, and digital forensics and incident response (DFIR) to continually adapt to new and evolving threats. Our modern MDR (Managed Detection & Response) approach is tailored to the unique characteristics and risk factors of each customer, enabling us to take full ownership of the response process and, optionally, manage key security controls. By thinking like an adversary and defending like a guardian, we help our customers stay a step ahead of threat actors.
At CyberMaxx, we value humility, transparency, intellectual curiosity, and a customer first approach.
CyberMaxx is seeking a Security Engineer to join our Security Control Management team with a primary focus on Endpoint Detection and Response (EDR) platform operations. This individual contributor role supports the day-to-day delivery of CyberMaxx's managed EDR service across a diverse customer base.
In this role, you will configure, maintain, and troubleshoot endpoint security platforms in multi-tenant customer environments. The position requires a team-oriented, client-facing mindset and the ability to work effectively with both technical and non-technical stakeholders. You will follow established engineering standards, execute operational requests, investigate platform health and agent issues, and document work clearly. You will work closely with senior engineers, the SOC, detection engineering, professional services, and customer-facing teams.
The team supports CrowdStrike Falcon, SentinelOne, and Microsoft Defender for Endpoint. Prior experience with at least one platform is expected; structured cross-training will be provided to build working proficiency across the supported portfolio. Success in this role requires sound troubleshooting, careful change execution, clear communication, and the ability to manage repeatable work across multiple customer environments.
What You Will Do:
EDR Platform Operations:
- Administer CyberMaxx-managed EDR platforms across customer environments, including routine configuration, policy maintenance and tuning, agent lifecycle activities, operational controls, and platform health checks.
- Execute approved routine and large-scale platform changes—including agent upgrades, bulk actions, policy transitions, and recovery activities—using established change controls, validation procedures, and documentation requirements; escalate unexpected behavior or risk.
- Monitor platform health, agent coverage, version status, policy alignment, and operational exceptions; investigate discrepancies and coordinate remediation.
- Support agent deployment, console configuration, integrations, and platform migrations under the direction of senior engineering staff.
- Monitor vendor roadmaps, emerging capabilities, and industry developments across supported EDR platforms, and contribute findings and recommendations regarding potential changes to internal standards for senior engineering review.
Technical Support & Troubleshooting
- Investigate endpoint security issues involving agent connectivity, performance, interoperability, policy behavior, detections, exclusions, upgrades, and deployment failures.
- Collect and analyze endpoint, console, and application evidence to isolate likely causes and determine whether an issue is related to the EDR platform, endpoint conditions, or another security control.
- Resolve requests within defined procedures and escalate complex, high-risk, or vendor-dependent issues with complete technical findings and a clear record of actions taken.
- Work with vendors and internal teams to progress support cases, validate proposed remediations, and communicate status to customer-facing stakeholders.
- Participate in peer review of configuration changes, exclusions, and technical recommendations to reduce operational and customer risk.
Automation & Service Improvement
- Use PowerShell, Python, vendor APIs, or approved automation tooling to perform repeatable operational tasks, collect evidence, and reduce manual effort.
- Contribute to scripts, workflows, and platform integrations developed by the Security Control Management team, including testing, documentation, and controlled rollout.
- Identify recurring requests, failure patterns, and manual processes that are candidates for standardization or automation.
- Validate automation output and maintain appropriate safeguards for changes executed across multiple customer environments.
- Develop and maintain operational dashboards, reports, and health metrics that provide visibility into agent coverage, platform status, policy compliance, and recurring service issues.
- Contribute to internal engineering repositories, runbooks, operational checklists, and tooling documentation.
Customer & Operational Support
- Coordinate assigned operational requests and technical investigations from intake through completion, managing dependencies, status updates, documentation, and handoffs while meeting documented service expectations.
- Provide practical recommendations on EDR configuration, deployment, platform health, and endpoint security operations within the scope of the managed service.
- Support customer meetings when technical context is required and communicate findings, risk, dependencies, and next steps in clear business language.
- Develop and maintain customer-facing procedures, configuration guidance, and implementation documentation.
- Support customer training and provide guidance on routine EDR platform administration, operational practices, and supported service workflows.
- Recognize recurring issues or misconfigurations across environments and raise them to senior engineers for broader corrective action.
Knowledge Development & Collaboration
- Build working proficiency across CrowdStrike Falcon, SentinelOne, and Microsoft Defender for Endpoint through hands-on operations, vendor training, and team knowledge sharing.
- Share troubleshooting findings, technical notes, and reusable procedures with Security Control Management team members and SOC analysts.
- Collaborate effectively with SOC, detection engineering, professional services, customer success, and other operational teams.
Required Qualifications
- 1+ years of experience in endpoint security, EDR operations, security engineering, systems administration, SOC operations, or a closely related technical role.
- Hands-on experience administering or supporting at least one of the following: CrowdStrike Falcon, SentinelOne Singularity, or Microsoft Defender for Endpoint.
- Practical experience troubleshooting Windows endpoints; familiarity with macOS or Linux endpoint administration is beneficial.
- Working knowledge of EDR concepts, endpoint security policies, agent deployment, exclusions, detection triage, and basic response actions.
- Ability to use PowerShell, Python, command-line tools, or vendor APIs for troubleshooting and repeatable operational tasks.
- Ability to analyze technical evidence, document findings, follow change controls, and escalate issues with sufficient context for efficient resolution.
- Clear written and verbal communication skills for working with internal engineering teams and customer stakeholders.
Preferred Qualifications
- Experience working in an MSSP, MDR, SOC, or other multi-customer security operations environment.
- Relevant vendor certification or training, such as CrowdStrike CCFA, SentinelOne Certified Administrator or Engineer, Microsoft SC-200, or equivalent practical coursework.
- Experience with SOAR platforms, SIEM integrations, or security automation tooling in the context of endpoint security operations.
- Understanding of MITRE ATT&CK, common endpoint attack techniques, and how EDR telemetry supports detection and investigation.
- Experience with large-scale EDR deployments, platform consolidations, or migrations across heterogeneous enterprise environments.
- Experience using EDR-native remote response, query, hunting, bulk-management, or detection validation capabilities to investigate and manage endpoints at scale.
Some Of What We Offer
- Flexible Paid Time Off
- 401k with a company match
- Medical, Dental and Vision Coverage
- Voluntary Short Term and Long-Term Disability
- Employee Assistance Program with Mental Health Supplement
- Voluntary Basic, Accidental, and other ancillary life insurance
- Health Savings Account Contribution (with selection of a HDHP)
- 10 annual, paid holidays
CyberMaxx will consider all qualified applicants without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, disability, veteran or military status, age, genetic information, or other characteristics protected by federal, state, or local applicable law.