Sangoma

Endpoint Security Engineer

Sangoma

full-time

Posted on:

Location Type: Remote

Location: FloridaUnited States

Visit company website

Explore more

AI Apply
Apply

Salary

💰 $100,000 - $110,000 per year

About the role

  • Serve as an escalation point for SOC/EDR/XDR alerts and suspected security incidents.
  • Automate and optimize Incident Response procedures with PowerShell, Python, and scripted API calls.
  • Write custom detection rules in EDR platforms such as CrowdStrike, SentinelOne, and Microsoft Defender.
  • Test and deploy EDR agent updates.
  • Evaluate and implement endpoint and endpoint adjacent security solutions.
  • Document Incident Response procedures and cross-train technical personnel on those procedures.
  • Participate in penetration testing and tabletop Incident Response exercises.
  • Produce and improve security dashboards and reports.
  • Maintain solution and procedure documentation.
  • Collaborate with IT, Infrastructure, and Cloud teams to implement secure endpoint configurations and controls.
  • Identify gaps in endpoint security coverage and recommend remediation or enhancements.
  • Support vulnerability remediation and endpoint hardening initiatives.
  • Participate in an on-call rotation, being reachable 24/7 during assigned on-call periods, one week per month.
  • Coordinate with SOC and IT teams to investigate and resolve high-priority endpoint security incidents during on-call periods.

Requirements

  • 4–6 years of experience in a security, SOC, or Incident Response role.
  • Solid experience working with one or more EDR solutions such as Sentinel One, CrowdStrike, or Microsoft Defender.
  • In-depth understanding of threat behaviors in the context of the MITRE ATT&CK Framework.
  • Intermediate understanding of Windows, MacOS, and Linux file structures and process architecture.
  • Experience participating in ITIL-oriented Change Management, Incident Management, and Problem Management processes in an enterprise environment.
  • Experience with automation and API calls via Python and/or PowerShell.
  • One or more industry-standard security certifications including but not limited to Security+, CySA+, Microsoft SC-200, CEH, GIAC, or similar.
Benefits
  • Extensive Benefit Options (Health, Vision, Dental, Long & Short term Disability) effective after a short waiting period
  • Matching 401K program - 100% match on 4%.
  • Employee Stock Purchase Plan after one year of service.
  • Flexible Time Off & Company Holidays
  • Entrepreneurial work environment partnered with high growth career opportunities
  • We value transparency and fairness in our compensation practices.
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills & Tools
PowerShellPythonEDRCrowdStrikeSentinelOneMicrosoft DefenderIncident Responsevulnerability remediationendpoint hardeningAPI calls
Soft Skills
collaborationdocumentationcross-trainingproblem-solvingcommunicationescalationincident managementchange managementteam coordinationon-call support
Certifications
Security+CySA+Microsoft SC-200CEHGIAC