What you'll be doing Administer, maintain, and monitor EDR and SIEM environments.
Tune detection rules, correlation logic, and security policies to improve detection quality and reduce false positives.
Configure and maintain endpoint policies, agent health, log collection, and platform integrations.
Investigate noisy or ineffective detections and continuously improve alert fidelity.
Validate that endpoint protection, log collection, and response capabilities operate as expected.
Integrate new log sources and improve visibility across endpoints, servers, cloud services, and network infrastructure.
Convert findings from incidents, threat intelligence, vulnerability assessments, and offensive security exercises into improved monitoring content.
Monitor platform health, storage, agent connectivity, licensing, and overall service availability.
Work with Infrastructure and IT teams to onboard new systems into EDR and SIEM.
Produce operational documentation, standard operating procedures, and platform runbooks.
Track detection coverage, platform performance, and continuous improvement initiatives.
What you'll bring Experience administering enterprise SIEM, XDR, or EDR platforms.
Hands on experience with Wazuh, Trend Micro Vision One, Microsoft Defender XDR, Microsoft Sentinel, Elastic Security, Splunk, or similar platforms.
Strong understanding of endpoint security, Windows, Linux, macOS, Active Directory, cloud environments, and network security.
Experience tuning detecti.