Security Platform Engineer
Core
Manage, tune, and improve EDR and SIEM platforms to ensure accurate security alerts and reliable visibility across endpoints, servers, cloud infrastructure, and corporate systems.
Role type
Security Platform Engineer (SIEM/EDR)
Builds
Production security monitoring and detection capabilities
Domain
Cybersecurity, Endpoint Security, Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
EDR/SIEM administration, detection rule tuning, log collection and parsing, endpoint security, cloud security, MITRE ATT&CK knowledge, automation scripting (Python/PowerShell/Bash), security event analysis
Preferred skills
Experience with Wazuh, Trend Micro Vision One, Microsoft Defender XDR, Microsoft Sentinel, Elastic Security, Splunk
Technologies
Wazuh, Trend Micro Vision One, Microsoft Defender XDR, Microsoft Sentinel, Elastic Security, Splunk, Python, PowerShell, Bash
Responsibilities
Administer and monitor EDR and SIEM environments; tune detection rules and correlation logic to reduce false positives; configure endpoint policies and agent health; develop and maintain security dashboards and reports; integrate new log sources; support security investigations; produce operational documentation and runbooks; track platform performance and coverage.
Seniority
Mid-level, hands-on IC