Senior Detection Engineer (EDR), Defensive Agent

horizon3ai

United States

Hybrid

USD 150,000 - 190,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Equity eligibility
Health, vision, and dental coverage
Flexible vacation
Parental leave

Job summary

horizon3ai is seeking a senior role providing blue-team domain authority for endpoint detection and response. You will translate operational security expertise into measurable product requirements, define acceptance criteria, and validate releases with cross-functional teams.

The role emphasizes judgment and domain ownership over software implementation, with strong collaboration across product, engineering, and AI research to align with SOC workflows and real-world usage.

Qualifications

  • Six+ years in detection engineering, security operations, incident response, or threat hunting.
  • Hands-on experience administering and tuning EDR platforms and policies.
  • Deep understanding of SOC workflows, alert fatigue and tradeoffs.
  • Strong knowledge of MITRE ATT&CK and practical limitations.
  • Ability to translate operational expertise into clear requirements and criteria.

Responsibilities

  • Translate detection goals into practical product requirements and outcomes.
  • Define acceptance criteria for detection, prevention, and tuning; validate releases.
  • Serve as domain reference during design reviews and vendor analyses.
  • Maintain knowledge of major endpoint platforms, telemetries, and policies.
  • Document vendor policy semantics for cross-product accuracy.
  • Track platform changes and vendor guidance to keep coverage current.
  • Define tuning standards and evaluate agent output with attack-focused teams.

Skills

Detection engineering
Security operations
Incident response
Threat hunting
SOC workflows
MITRE ATT&CK knowledge
Operational requirements to product
Communication and collaboration

Tools

EDR platforms

Job description

Role overview

This role provides the blue-team domain authority for a defensive security agent focused on endpoint detection and response. Working between Product, Engineering, and AI research, you will define what accurate detection and remediation look like, convert operational security knowledge into measurable requirements, and ensure that recommendations reflect how real SOC teams use endpoint tools. The position emphasizes judgment, validation, and domain ownership rather than software implementation.

Responsibilities
  • Translate EDR effectiveness and tuning goals into practical product requirements and prioritized outcomes.
  • Define acceptance criteria for detection, prevention, effectiveness, and tuning capabilities, then validate releases before customer use.
  • Serve as the primary domain reference for engineering and AI research during design reviews, technical questions, and vendor-behavior analysis.
  • Maintain detailed knowledge of major endpoint platforms across consoles, policies, telemetry, APIs, detections, exclusions, and hardened configurations.
  • Document vendor-specific policy semantics so equivalent recommendations remain accurate across products with different models.
  • Track platform changes, new capabilities, and vendor guidance while keeping coverage expectations current.
  • Define standards for correct tuning recommendations and evaluate agent output against those standards in partnership with attack-focused teams.
Requirements
  • Six or more years in detection engineering, security operations, incident response, or threat hunting, including substantial hands-on practitioner experience.
  • Production experience administering and tuning EDR platforms, writing detections, managing policies and exclusions, and investigating real alerts.
  • Deep understanding of SOC workflows, alert fatigue, false-positive and false-negative tradeoffs, and detection-coverage measurement.
  • Strong working knowledge of MITRE ATT&CK and related coverage frameworks, including their practical limitations.
  • Solid understanding of post-compromise attacker behavior and how it appears in endpoint and identity telemetry.
  • Demonstrated ability to turn operational expertise into clear requirements, acceptance criteria, and measurable quality standards.
  • Strong communication and collaboration skills for working across product, engineering, research, and security teams.
Benefits and work setup
  • Remote work options may vary by role and location; some positions may require regular office attendance.
  • Competitive compensation with equity eligibility for full-time roles.
  • Health, vision, and dental coverage for employees and families, flexible vacation, and parental leave.
  • An environment centered on respect, ownership, collaboration, inclusion, and professional growth.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Detection Engineer (EDR), Defensive Agent
Senior Detection Engineer (EDR), Defensive Agent

Horizon3 • United States

Hybrid
USD 195,000 - 230,000
Inclusive Team
Growth Opportunities
Innovative Culture
+2
Endpoint Detection & Response Engineer, Senior
Endpoint Detection & Response Engineer, Senior

Booz Allen Hamilton • Shiloh (IL)

On-site
USD 86,000 - 198,000
Health insurance
Tuition assistance
Paid leave
+1
Senior Detection Engineer (EDR), Defensive Agent
Senior Detection Engineer (EDR), Defensive Agent

AI Chopping Block • Northern (KY)

Hybrid
USD 195,000 - 230,000
Inclusive Team
Growth Opportunities
Innovative Culture
+2
Endpoint Detection & Response Engineer, Senior
Endpoint Detection & Response Engineer, Senior

Booz Allen Hamilton • Illinois

On-site
USD 86,000 - 198,000
Health insurance
Professional development
Tuition assistance
Senior Detection Engineer (EDR), Defensive Agent
Senior Detection Engineer (EDR), Defensive Agent

Socket.dev • United States

Hybrid
USD 195,000 - 230,000
Inclusive team
Growth opportunities
Innovative culture
+2
Senior Detection Engineer — EDR & SOC Domain Expert
Senior Detection Engineer — EDR & SOC Domain Expert

Horizon3 • United States

Hybrid
USD 195,000 - 230,000
Inclusive Team
Growth Opportunities
Innovative Culture
+2
Senior Detection Engineer — EDR Strategy & Validation
Senior Detection Engineer — EDR Strategy & Validation

Socket.dev • United States

On-site
USD 195,000 - 230,000
Inclusive team
Growth opportunities
Innovative culture
+2
Cybersecurity Engineer
Cybersecurity Engineer

Vortalsoft Inc • New Jersey

On-site
USD 90,000 - 130,000
Senior Security Engineer - Threat Detection
Senior Security Engineer - Threat Detection

samsara • United States

Hybrid
USD 150,000 - 190,000
Professional development stipend
Comprehensive health coverage
Parental leave plans
Endpoint Security Engineer
Endpoint Security Engineer

PlanIT Group, LLC • Reston (VA)

On-site
USD 150,000 - 200,000