Endpoint Security Engineer jobs in United States
cer-icon
Apply on Employer Site
company-logo

Sangoma · 1 day ago

Endpoint Security Engineer

Sangoma is seeking a motivated and detail-oriented Endpoint Security Engineer to enhance their security posture. The role involves designing and implementing endpoint security solutions, investigating security events, and collaborating with various teams to improve security capabilities.

HardwareInformation TechnologySoftwareTelecommunicationsUnified Communications
badNo H1Bnote

Responsibilities

Serve as an escalation point for SOC/EDR/XDR alerts and suspected security incidents
Automate and optimize Incident Response procedures with PowerShell, Python, and scripted API calls
Write custom detection rules in EDR platforms such as CrowdStrike, SentinelOne, and Microsoft Defender
Test and deploy EDR agent updates
Evaluate and implement endpoint and endpoint adjacent security solutions
Document Incident Response procedures and cross-train technical personnel on those procedures
Participate in penetration testing and tabletop Incident Response exercises
Produce and improve security dashboards and reports
Maintain solution and procedure documentation
Collaborate with IT, Infrastructure, and Cloud teams to implement secure endpoint configurations and controls
Identify gaps in endpoint security coverage and recommend remediation or enhancements
Support vulnerability remediation and endpoint hardening initiatives
Participate in an on-call rotation, being reachable 24/7 during assigned on-call periods, one week per month
Coordinate with SOC and IT teams to investigate and resolve high-priority endpoint security incidents during on-call periods

Qualification

Incident ResponseEDR solutionsAutomation with PythonMITRE ATT&CK FrameworkWindowsMacOSLinuxSecurity certificationsProblem ManagementCommunication skillsCollaboration skills

Required

4-6 years of experience in a security, SOC, or Incident Response role
Solid experience working with one or more EDR solutions such as Sentinel One, CrowdStrike, or Microsoft Defender
In-depth understanding of threat behaviors in the context of the MITRE ATT&CK Framework
Intermediate understanding of Windows, MacOS, and Linux file structures and process architecture
Experience participating in ITIL-oriented Change Management, Incident Management, and Problem Management processes in an enterprise environment
Experience with automation and API calls via Python and/or PowerShell
One or more industry-standard security certifications including but not limited to Security+, CySA+, Microsoft SC-200, CEH, GIAC, or similar

Preferred

Solid experience working with SIEM / SOAR solutions for event correlation and automated response
Experience performing forensic investigations and malware analysis
Ability to perform and document penetration testing exercises
Knowledge of cloud and/or hybrid environments such as Microsoft 365, Azure, AWS, Intune, or similar platforms

Benefits

Extensive Benefit Options (Health, Vision, Dental, Long & Short term Disability) effective after a short waiting period
Matching 401K program - 100% match on 4%
Employee Stock Purchase Plan after one year of service
Flexible Time Off & Company Holidays
Entrepreneurial work environment partnered with high growth career opportunities

Company

Sangoma

twittertwittertwitter
company-logo
Sangoma Technologies Corporation (TSX: STC; Nasdaq: SANG) is a global leader in essential business communications.

Funding

Current Stage
Public Company
Total Funding
$96.21M
2020-07-23Post Ipo Equity· $60.06M
2019-07-16Post Ipo Equity· $23.01M
2018-03-15Post Ipo Equity· $13.14M

Leadership Team

C
Charles Salameh
Chief Executive Officer
linkedin
leader-logo
Jeremy Wubs
Chief Operating Officer
linkedin
Company data provided by crunchbase