> Markdown version of [/jobs/ext/3003786-senior-endpoint-security-engineer](https://www.wearedevelopers.com/jobs/ext/3003786-senior-endpoint-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Endpoint Security Engineer - **Company:** Barracuda Networks, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $110,000.0 - $135,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Data Analysis, Apple Mac Systems, Configuration Management, Cyber Security, Linux, Digital Forensics, Intrusion Detection and Prevention, Python (Programming Language), Linux System Administration, Log Analysis, Network Forensics, OAuth, Azure Active Directory, SQL Databases, Scripting, Mitre Att&ck, Mttr, Cyber Threat Analysis, Azure Security Center, Information Technology, Cybercrime, SentinelOne Expertise, Api Management, Databricks - **Published:** September 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=8d86e801c222a3d6 ## About the Role * Minimum of bachelor's degree in computer science and 5+ years of hands-on experience in incident response, digital forensics, or security operations * MSSP, MDR, or consulting experience is strongly preferred. Demonstrated ability to manage multiple client engagements simultaneously. * Proven track record investigating real-world incidents including ransomware, BEC Attacks, lateral movement, data exfiltration etc. * Experience working in multi-tenant environments with diverse security maturity levels. * GIAC certification required; one or more of the following: * + GCIH (GIAC Certified Incident Handler) + GCFA (GIAC Certified Forensic Analyst) + GCFE (GIAC Certified Forensic Examiner) + GNFA (GIAC Network Forensic Analyst) + Equivalent certifications considered: OSCP, eCIR, eCDFP, EnCE, SC-200, AZ-500 Required Technical Skills in Core Platforms * DFIR - Binalyze AIR - remote acquisition, triage, timeline analysis and artifact collection. * EDR - SentinelOne threat investigations, Deep Visibility, detection engineering, policy configuration * Microsoft 365 / Defender - BEC investigation, UAL analysis, Safe Links/Attachments, Entra ID etc. * Analytics - Databricks - large-scale log analysis, SQL/Python notebooks, threat hunting at scale * Automation - workflow automation, playbook development, API integrations and continuous monitoring. Preferred Qualifications * Experience with additional EDR platforms (CrowdStrike, Microsoft Defender for Endpoint) * Advanced knowledge of macOS and Linux forensics * Familiarity with threat intelligence platforms (MISP, Recorded Future, Virus Total Enterprise) * Experience with Velociraptor, KAPE, or Volatility for advanced forensic collection and investigations. * Prior experience in IR teams or serving as an IR practice SME ## Description We are seeking a Senior Endpoint Security & IR Engineer to join our incident response team. You will lead management of our SentinelOne XDR platform, complex investigations across multiple client environments, drive rapid containment of active threats, and serve as a trusted advisor to clients during their most critical security events. This role combines deep technical expertise with client-facing communication skills in a fast-paced, multi-tenant MSSP environment. You will work closely with our Cyber Concierge, Threat Analysts and Automation teams to continuously improve our response capabilities and protect our clients from sophisticated adversaries. What You'll be Working On: * Expert knowledge and experience in SentinelOne - Key Requirement * Lead end-to-end incident response engagements across diverse client environments, from initial triage through remediation and lessons learned * Perform host-based forensics using Binalyze AIR for remote evidence acquisition, triage, and analysis at scale * Design custom detection rules within SentinelOne and fine tune protection policies. * Proven experience in windows, mac and linux environments * Investigate alerts and threats detected by SentinelOne, including Deep Visibility hunting, threat timeline reconstruction, and MITRE ATT&CK mapping * Analyze Microsoft 365 security incidents including business email compromise, OAuth abuse, mailbox rule manipulation, and Azure AD/Entra ID attacks * Conduct log analysis and threat hunting in Elastic to identify indicators of compromise, lateral movement, and data exfiltration * Leverage Databricks for large-scale log analytics, anomaly detection, and threat hunting across aggregated client telemetry * Document findings in clear, executive-ready incident reports tailored to both technical and non-technical stakeholders * Participate in a 24/7 on-call rotation Automation & Detection Engineering * Develop and maintain Python scripts for evidence collection, log parsing, IOC enrichment, and automated response actions * Build and optimize automated response workflows in Tines to accelerate containment and MTTR * Create and tune detection rules in Elastic and SentinelOne based on investigative findings and emerging threat intelligence * Integrate tooling across the security stack to streamline IR workflows and reduce manual effort. Client Engagement & Service Delivery * Serve as the primary IR point of contact for client stakeholders during active incidents * Conduct client-facing incident briefings, root cause analysis presentations, and post-incident reviews * Deliver actionable remediation guidance tailored to each client's environment and risk tolerance * Maintain SLA commitments for incident acknowledgment, updates, and resolution * Contribute to client security posture assessments and IR readiness recommendations. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)