Endpoint Security Engineer (Sentinel One)
Wittaff
ENDPOINT SECURITY ENGINEER Position Overview We are seeking an experienced Information Security Engineer to support and manage our enterprise endpoint security environment, with a primary focus on SentinelOne EDR/XDR. The ideal candidate will have...
Job description
The candidate should be comfortable working in a large-scale environment with thousands of endpoints and collaborating with Security Operations, Infrastructure, Cloud, and IT teams.
Key Responsibilities
SentinelOne / EDR Administration
Manage and administer the SentinelOne EDR/XDR platform across a large enterprise environment.
Deploy, configure, upgrade, and maintain SentinelOne agents across:
Windows
Linux
macOS
Monitor overall endpoint/agent health, connectivity, versions, and coverage.
Troubleshoot SentinelOne agent installation, communication, performance, and operational issues.
Develop and maintain SentinelOne policies, exclusions, application controls, and security configurations.
Perform EDR policy tuning to minimize false positives while maintaining appropriate security protection.
Manage endpoint groups, policies, tags, and organizational structures within SentinelOne.
Support onboarding of newly acquired environments and migrate endpoints into the enterprise EDR platform.
Maintain strong endpoint coverage and identify systems that are missing, unhealthy, or improperly configured.
Threat Detection & Incident Response
Monitor and investigate endpoint alerts and suspicious activities identified by SentinelOne.
Perform initial triage and investigation of endpoint security incidents.
Analyze endpoint telemetry, process trees, command lines, network connections, and behavioral indicators.
Use SentinelOne capabilities such as threat hunting, Deep Visibility, Storyline, remediation, isolation, and rollback where applicable.
Contain compromised endpoints through appropriate isolation and remediation actions.
Support malware analysis and investigation of suspicious files, processes, scripts, and activities.
Escalate complex security incidents to the appropriate Security Operations or Incident Response teams.
Participate in incident response activities and post-incident analysis.
Endpoint Security Engineering
Develop and maintain endpoint security standards and configuration baselines.
Ensure EDR coverage and security controls align with organizational security requirements.
Work with Windows, Linux, and macOS engineering teams to resolve endpoint security issues.
Support vulnerability management and endpoint hardening initiatives.
Assist with security assessments, audits, and compliance requirements.
Develop automation and scripting to improve EDR administration and operational efficiency.
Create dashboards, reports, and metrics related to endpoint security posture and EDR coverage.
Enterprise Security Operations
Collaborate with SOC team, Incident Response, Network Security, Cloud Security, and IT teams.
Participate in security investigations and incident response activities.
Support security projects involving endpoint protection, EDR, XDR, and threat detection.
Participate in change management, documentation, and operational procedures.
Stay current with emerging endpoint threats, attack techniques, malware, and EDR technologies.
Required Qualifications
5+ years of experience in Information Security, Endpoint Security, Security Operations, or a related field.
Strong hands-on experience administeringSentinelOne EDR/XDR in a large enterprise environment.
Demonstrated experience managing EDR acrosslarge numbers of endpoints.
Strong experience with Windows endpoint security and administration.
Working experience with Linux endpoint/server security and administration.
Working experience with macOS endpoint security and administration.
Experience with EDR alert investigation and incident response.
Strong understanding of endpoint attack techniques, malware, persistence mechanisms, and common attacker behaviors.
Experience with endpoint isolation, remediation, threat hunting, and security policy tuning.
Experience troubleshooting EDR agents and endpoint security issues at scale.
Strong understanding of networking fundamentals, including TCP/IP, DNS, HTTP/HTTPS, and common security protocols.
Experience with scripting/automation usingPowerShell, Python, Bash, or similar technologies.
Ability to work effectively in a large enterprise environment with multiple technology and infrastructure teams.
Preferred Qualifications
SentinelOne certifications or relevant vendor training.
Experience with SentinelOne Singularity XDR / Vigilance MDR.
Experience integrating SentinelOne with SIEM platforms, SOAR, ticketing systems, or other security tools.
Experience with Microsoft security technologies such as Microsoft Defender, Entra ID, Intune, and Microsoft 365 Defender.
Experience with cloud environments such as Azure or AWS.
Knowledge of MITRE ATT&CK framework and endpoint attack techniques.
Experience with vulnerability management tools such as Tenable.
Experience supporting CIS benchmarks, security hardening, and compliance requirements.
Experience with enterprise endpoint management tools such as SCCM/MECM, Intune, Jamf, Ansible, or similar platforms.
Experience supporting mergers and acquisitions, including onboarding and standardizing endpoint security across acquired environments.
Ideal Candidate
The ideal candidate is a hands-on endpoint security engineer who has managed SentinelOne across a large and complex environment. They should be able to independently troubleshoot an unhealthy agent, investigate a suspicious endpoint alert, tune an EDR policy, perform threat hunting, and work with infrastructure teams to remediate security issues.
The candidate should have strong practical experience across Windows, Linux, and macOS, and be comfortable operating in a fast-paced enterprise security environment.
Pay: $55.00 - $60.00 per hour
Experience:
macOS: 1 year (Required)
Work Location: In person