Logo for CyberMaxx

Operations Engineer

Role overview

Qualifications

  • 4+ years of experience in endpoint security, EDR operations, security engineering, systems administration, SOC operations, or a closely related technical role
  • Hands-on experience administering or supporting at least one of the following: CrowdStrike Falcon, SentinelOne Singularity, or Microsoft Defender for Endpoint
  • Working knowledge of EDR concepts, endpoint security policies, agent deployment, exclusions, detection triage, and basic response actions
  • Ability to use PowerShell, Python, command-line tools, or vendor APIs for troubleshooting and repeatable operational tasks

Responsibilities

  • Administer CyberMaxx-managed EDR platforms across customer environments, including routine configuration and policy maintenance
  • Investigate endpoint security issues involving agent connectivity, performance, and policy behavior
  • Use PowerShell, Python, vendor APIs, or approved automation tooling to perform operational tasks and reduce manual effort
  • Coordinate assigned operational requests and technical investigations from intake through completion

Key facts

  • Remote from: United States
  • Full time
  • Operations Specialist
  • English

Hard skills

Other skills

  • Troubleshooting (Problem Solving)
  • Communication
  • Collaboration
  • Problem Solving

About the company

CyberMaxx logo

CyberMaxx

Cybersecurity

We built CyberMaxx with one goal in mind: to be the industry’s leading trusted partner in preventing, detecting, and responding to cyber attacks.Equipped with a 24/7/365 security operations center and a team of cybersecurity experts, our managed security services were designed to help you increase compliance, eliminate talent shortages, and keep your organization out of the headlines so you can spend your time focusing on what’s most important.Featuring around-the-clock monitoring and early threat warnings with immediate response, we’re proud to serve as an extension of your security team, backed with over 19 years protecting customers against the ever-changing landscape of advanced cybersecurity threats.

Company details

IndustryCybersecurity
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Description

At CyberMaxx, we believe it is our duty to defend against those committed to wide-scale societal disruption through cyberattacks.

We help our customers reduce risk by tightly integrating MDR with offensive security, threat hunting, security research, and digital forensics and incident response (DFIR) to continually adapt to new and evolving threats. Our modern MDR (Managed Detection & Response) approach is tailored to the unique characteristics and risk factors of each customer, enabling us to take full ownership of the response process and, optionally, manage key security controls. By thinking like an adversary and defending like a guardian, we help our customers stay a step ahead of threat actors.

At CyberMaxx, we value humility, transparency, intellectual curiosity, and a customer first approach.

CyberMaxx is seeking an Operations Engineer to join our Operations Engineering team with a primary focus on Endpoint Detection and Response (EDR) platform operations. This individual contributor role supports the day-to-day delivery of CyberMaxx's managed EDR service across a diverse customer base. 

In this role, you will administer and troubleshoot EDR and XDR security platforms in multi-tenant customer environments. The role calls for a team-oriented, client-facing mindset and the ability to work effectively with both technical and non-technical stakeholders. You will follow established engineering standards, execute service requests, investigate platform health and agent issues, and document work clearly. You will work cross-functionally with our Security Operations Center, Detection Engineering, Platform Engineering, and Customer Success teams. 

You will primarily support the EDR consoles behind our MDR service, including CrowdStrike Falcon, SentinelOne, and Microsoft Defender for Endpoint; prior hands-on experience with at least one of these platforms is expected. You will also help support our other managed technologies, including SIEM, email security, vulnerability scanners, and deception technologies. Structured cross-training will be provided to build working proficiency across the supported portfolio. Success in this role requires sound troubleshooting, careful change execution, clear communication, and the ability to manage repeatable work across multiple customer environments. 

What You Will Do:

EDR Platform Operations:

  • Administer CyberMaxx-managed EDR platforms across customer environments, including routine configuration, policy maintenance and tuning, agent lifecycle activities, operational controls, and platform health checks. 
  • Execute approved routine and large-scale platform changes including agent upgrades, bulk actions, policy transitions, and recovery activities using established change controls, validation procedures, and documentation requirements; escalate unexpected behavior or risk. 
  • Monitor platform health, agent coverage, version status, policy alignment, and operational exceptions; investigate discrepancies and coordinate remediation. 
  • Support agent deployment, console configuration, integrations, and platform migrations under the direction of senior engineering staff. 
  • Monitor vendor roadmaps, emerging capabilities, and industry developments across supported EDR platforms, and contribute findings and recommendations regarding potential changes to internal standards for senior engineering review. 

Technical Support & Troubleshooting

  • Investigate endpoint security issues involving agent connectivity, performance, interoperability, policy behavior, detections, exclusions, upgrades, and deployment failures. 
  • Collect and analyze endpoint, console, and application evidence to isolate likely causes and determine whether an issue is related to the EDR platform, endpoint conditions, or another security control. 
  • Resolve requests within defined procedures and escalate complex, high-risk, or vendor-dependent issues with complete technical findings and a clear record of actions taken. 
  • Work with vendors and internal teams to progress support cases, validate proposed remediations, and communicate status to customer-facing stakeholders. 
  • Participate in peer review of configuration changes, exclusions, and technical recommendations to reduce operational and customer risk. 

Automation & Service Improvement

  • Use PowerShell, Python, vendor APIs, or approved automation tooling to perform repeatable operational tasks, collect evidence, and reduce manual effort. 
  • Contribute to scripts, workflows, and platform integrations developed by the Operations Engineering team, including testing, documentation, and controlled rollout. 
  • Identify recurring requests, failure patterns, and manual processes that are candidates for standardization or automation. 
  • Validate automation output and maintain appropriate safeguards for changes executed across multiple customer environments. 
  • Develop and maintain operational dashboards, reports, and health metrics that provide visibility into agent coverage, platform status, policy compliance, and recurring service issues. 
  • Contribute to internal engineering repositories, runbooks, operational checklists, and tooling documentation. 

Customer & Operational Support

  • Coordinate assigned operational requests and technical investigations from intake through completion, managing dependencies, status updates, documentation, and handoffs while meeting documented service expectations. 
  • Provide practical recommendations on EDR configuration, deployment, platform health, and endpoint security operations within the scope of the managed service. 
  • Support customer meetings when technical context is required and communicate findings, risk, dependencies, and next steps in clear business language. 
  • Develop and maintain customer-facing procedures, configuration guidance, and implementation documentation. 
  • Support customer training and provide guidance on routine EDR platform administration, operational practices, and supported service workflows. 
  • Recognize recurring issues or misconfigurations across environments and raise them to senior engineers for broader corrective action. 

Knowledge Development & Collaboration

  • Build working proficiency across CrowdStrike Falcon, SentinelOne, and Microsoft Defender for Endpoint through hands-on operations, vendor training, and team knowledge sharing. 
  • Share troubleshooting findings, technical notes, and reusable procedures with Operations Engineering team members and SOC analysts. 
  • Collaborate effectively with SOC, Detection Engineering, Professional Services, Customer Success, and other operational teams. 

Required Qualifications

  • 4+ of experience in endpoint security, EDR operations, security engineering, systems administration, SOC operations, or a closely related technical role. 
  • Hands-on experience administering or supporting at least one of the following: CrowdStrike Falcon, SentinelOne Singularity, or Microsoft Defender for Endpoint. 
  • Practical experience troubleshooting Windows endpoints; familiarity with macOS or Linux endpoint administration is beneficial. 
  • Working knowledge of EDR concepts, endpoint security policies, agent deployment, exclusions, detection triage, and basic response actions. 
  • Ability to use PowerShell, Python, command-line tools, or vendor APIs for troubleshooting and repeatable operational tasks. 
  • Ability to analyze technical evidence, document findings, follow change controls, and escalate issues with sufficient context for efficient resolution. 
  • Clear written and verbal communication skills for working with internal engineering teams and customer stakeholders. 

Preferred Qualifications

  • Experience working in an MSSP, MDR, SOC, or other multi-customer security operations environment. 
  • Familiarity with Linux systems, the ITIL framework, and availability monitoring. 
  • Experience using agentic or AI-assisted tooling to automate routine, recurring tasks. 
  • Relevant vendor certification or training, such as CrowdStrike CCFA, SentinelOne Certified Administrator or Engineer, Microsoft SC-200, or equivalent practical coursework. 
  • Experience with SOAR platforms, SIEM integrations, or security automation tooling in the context of endpoint security operations. 
  • Understanding of MITRE ATT&CK, common endpoint attack techniques, and how EDR telemetry supports detection and investigation. 
  • Experience using EDR-native remote response, query, hunting, bulk-management, or detection validation capabilities to investigate and manage endpoints at scale. 

Some Of What We Offer

  • Flexible Paid Time Off
  • 401k with a company match
  • Medical, Dental and Vision Coverage
  • Voluntary Short Term and Long-Term Disability
  • Employee Assistance Program with Mental Health Supplement
  • Voluntary Basic, Accidental, and other ancillary life insurance
  • Health Savings Account Contribution (with selection of a HDHP)
  • 10 annual, paid holidays

CyberMaxx will consider all qualified applicants without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, disability, veteran or military status, age, genetic information, or other characteristics protected by federal, state, or local applicable law.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Operations Specialist Related jobs

Other jobs at CyberMaxx

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.