EDR Architect & Penetration Testing Lead: (Cyber security)

San Jose, CA, US • Posted 2 hours ago • Updated 2 hours ago
Contract Corp To Corp
Contract Independent
Contract W2
12 Months
Able to Sponsor
On-site
$80 - $90/hr
Fitment

Dice Job Match Score™

📋 Comparing job requirements...

Job Details

Skills

  • Mentorship
  • IT Management
  • Incident Management
  • Linux
  • Malware Analysis
  • Endpoint Protection
  • Microsoft Windows
  • Network
  • OS X
  • Good Clinical Practice
  • Google Cloud Platform
  • Cloud Computing
  • Collaboration
  • Continuous Improvement
  • Python
  • Reporting
  • Cyber Security
  • Emulation
  • Hardening
  • Management
  • Microsoft Azure
  • Penetration Testing
  • Vulnerability Management
  • Web Applications
  • Windows PowerShell
  • Workflow
  • Roadmaps
  • Scripting
  • Security Architecture
  • Security Controls
  • Telecommunications
  • Bash
  • SIEM
  • Amazon Web Services

Summary

EDR Architect & Penetration Testing Lead: (Cyber security)
San Jose CA
Position Summary

We are seeking an experienced EDR Architect & Penetration Testing Lead to design, implement, optimize, and continuously improve our endpoint security strategy while conducting offensive security assessments to identify and validate security risks. This role will bridge defensive and offensive security functions, ensuring endpoint detection capabilities effectively detect, prevent, and respond to modern threats.
Key Responsibilities EDR Architecture & Endpoint Security

  • Design, deploy, and maintain enterprise-scale EDR solutions.
  • Develop endpoint security architecture, standards, and operational procedures.
  • Configure and optimize detection rules, alerting logic, threat hunting workflows, and response playbooks.
  • Integrate EDR platforms with SIEM, SOAR, vulnerability management, and incident response processes.
  • Lead endpoint security assessments and architecture reviews.
  • Evaluate and recommend endpoint security technologies and controls.
  • Develop endpoint hardening standards across Windows, Linux, and macOS environments.
  • Create metrics and reporting to measure EDR effectiveness and coverage.

Penetration Testing & Offensive Security

  • Plan and execute internal and external penetration tests.
  • Perform network, web application, cloud, and endpoint security assessments.
  • Conduct red team exercises and adversary emulation activities.
  • Validate security controls through simulated attack scenarios.
  • Identify vulnerabilities, misconfigurations, and security gaps.
  • Produce detailed technical reports with risk ratings and remediation recommendations.
  • Partner with engineering and infrastructure teams to validate remediation efforts.
  • Develop attack simulations to test EDR detections and response capabilities.

Threat Detection & Security Engineering

  • Create custom detection content and threat-hunting methodologies.
  • Map detections and attack simulations to the MITRE Telecommunication&CK framework.
  • Analyze emerging threats, attacker techniques, and security trends.
  • Support incident response investigations and post-incident reviews.
  • Develop automated detection and response workflows where appropriate.

Governance & Leadership

  • Define endpoint security strategy and roadmap.
  • Provide technical leadership for endpoint security initiatives.
  • Mentor junior security analysts and engineers.
  • Collaborate with infrastructure, cloud, and application teams on security architecture.
  • Present findings and recommendations to technical and executive stakeholders.

Required Qualifications

  • 7+ years of cybersecurity experience.
  • 3+ years designing and managing enterprise EDR platforms.
  • Hands-on penetration testing experience across multiple environments.
  • Strong knowledge of:
    • Windows security architecture
    • Linux security
    • Active Directory
    • Cloud security (AWS, Azure, Google Cloud Platform)
    • Network security
    • Incident response
    • Threat hunting
  • Experience with one or more EDR platforms such as:
    • CrowdStrike Falcon
    • Microsoft Defender for Endpoint
    • SentinelOne Singularity
    • VMware Carbon Black
  • Proficiency in scripting and automation (Python, PowerShell, Bash).
  • Strong understanding of attack techniques, malware, and adversary behaviors.

Preferred Qualifications

  • Experience conducting red team operations.
  • Experience with cloud-native security platforms.
  • Knowledge of detection engineering and purple teaming.
  • Experience with security automation and SOAR technologies.


Success Metrics

  • Improvement in endpoint visibility and detection coverage.
  • Reduction in false positives and alert fatigue.
  • Successful execution of penetration testing engagements.
  • Increased detection rates for simulated attacks.
  • Timely remediation of identified security weaknesses.
  • Continuous improvement of endpoint security posture and threat detection capabilities.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91109480
  • Position Id: 8990839
  • Posted 2 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

San Jose, California

Today

Easy Apply

Third Party, Contract

$60 - $70

San Jose, California

Today

Easy Apply

Contract, Third Party

Depends on Experience

Sunnyvale, California

Today

Easy Apply

Contract, Third Party

60 - 80

San Jose, California

2d ago

Easy Apply

Third Party, Contract

Depends on Experience

Search all similar jobs