> Markdown version of [/jobs/ext/526828-edr-architect-penetration-test-lead-san-jose-ca-onsite](https://www.wearedevelopers.com/jobs/ext/526828-edr-architect-penetration-test-lead-san-jose-ca-onsite). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # EDR Architect + Penetration test Lead - San Jose, CA (Onsite) - **Company:** Svk Systems Inc - **Location:** San Jose, CA, United States - **Experience:** Expert - **Salary:** $135,200.0 - $145,600.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, Apple Mac Systems, Software System Penetration Testing, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Computing Security, Cyber Security, Linux, Intrusion Detection and Prevention, Python (Programming Language), Network Security, Linux Security Modules, Windows PowerShell, Red Team (Cyber Security), Security Information and Event Management, Software Vulnerability Management, Web Applications, Google Cloud, Mitre Att&ck, Malware, Cyber Threat Analysis, Azure Security Center, Cybercrime, Windows Security, SentinelOne Expertise, Security Orchestration, Automation & Response, Vmware - **Published:** June 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=2b9ae32aba7924cf ## About the Role Do you have experience in macOS?, * 7+ years of cybersecurity experience. * 3+ years designing and managing enterprise EDR platforms. * Hands-on penetration testing experience across multiple environments. * Strong knowledge of: * Windows security architecture * Linux security * Active Directory * Cloud security (AWS, Azure, GCP) * Network security * Incident response * Threat hunting * Experience with one or more EDR platforms such as: * CrowdStrike Falcon * Microsoft Defender for Endpoint * SentinelOne Singularity * VMware Carbon Black * Proficiency in scripting and automation (Python, PowerShell, Bash). * Strong understanding of attack techniques, malware, and adversary behaviors., * Experience conducting red team operations. * Experience with cloud-native security platforms. * Knowledge of detection engineering and purple teaming. * Experience with security automation and SOAR technologies. Success Metrics * Improvement in endpoint visibility and detection coverage. * Reduction in false positives and alert fatigue. * Successful execution of penetration testing engagements. * Increased detection rates for simulated attacks. * Timely remediation of identified security weaknesses. * Continuous improvement of endpoint security posture and threat detection capabilities. ## Description We are seeking an experienced EDR Architect & Penetration Testing Lead to design, implement, optimize, and continuously improve our endpoint security strategy while conducting offensive security assessments to identify and validate security risks. This role will bridge defensive and offensive security functions, ensuring endpoint detection capabilities effectively detect, prevent, and respond to modern threats., EDR Architecture & Endpoint Security * Design, deploy, and maintain enterprise-scale EDR solutions. * Develop endpoint security architecture, standards, and operational procedures. * Configure and optimize detection rules, alerting logic, threat hunting workflows, and response playbooks. * Integrate EDR platforms with SIEM, SOAR, vulnerability management, and incident response processes. * Lead endpoint security assessments and architecture reviews. * Evaluate and recommend endpoint security technologies and controls. * Develop endpoint hardening standards across Windows, Linux, and macOS environments. * Create metrics and reporting to measure EDR effectiveness and coverage. Penetration Testing & Offensive Security * Plan and execute internal and external penetration tests. * Perform network, web application, cloud, and endpoint security assessments. * Conduct red team exercises and adversary emulation activities. * Validate security controls through simulated attack scenarios. * Identify vulnerabilities, misconfigurations, and security gaps. * Produce detailed technical reports with risk ratings and remediation recommendations. * Partner with engineering and infrastructure teams to validate remediation efforts. * Develop attack simulations to test EDR detections and response capabilities. Threat Detection & Security Engineering * Create custom detection content and threat-hunting methodologies. * Map detections and attack simulations to the MITRE ATT&CK framework. * Analyze emerging threats, attacker techniques, and security trends. * Support incident response investigations and post-incident reviews. * Develop automated detection and response workflows where appropriate. Governance & Leadership * Define endpoint security strategy and roadmap. * Provide technical leadership for endpoint security initiatives. * Mentor junior security analysts and engineers. * Collaborate with infrastructure, cloud, and application teams on security architecture. * Present findings and recommendations to technical and executive stakeholders. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [WebAssembly: The Next Frontier of Cloud Computing](https://www.wearedevelopers.com/videos/972-webassembly-the-next-frontier-of-cloud-computing) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)