Endpoint Detection and Response Engineer, Senior

The Challenge:

As an Endpoint Detection and Response (EDR) Engineer, you will help design, deploy, configure, optimize, and validate next-generation endpoint security solutions for customers. You’ll work with in-house teams to identify the right mix of tools, techniques, procedures to translate our customer’s needs and future goals into a plan that will enable secure and effective solutions. In determining the best solutions, you will investigate new techniques, break free from the legacy model, and help customers exceed industry standards. As a team, we’ll take a critical approach to solution design, identifying gaps, providing alternatives, and customizing solutions to maintain a balance of security and business needs. Some travel may be required. This position is open to remote delivery anywhere within the U.S., to include the District of Columbia.

You Have:

  • 2+ years of experience with performing systems administration, including basic troubleshooting and installation, monitoring system performance or availability, performing security upgrades, and optimizing solution configurations to meet the needs of operational users

  • 2+ years of experience with deployment, configuration, or maintenance to support enterprise EDR solutions, including Carbon Black EDR, CrowdStrike Falcon, SentinelOne, FireEye HX, McAfee MVision, Microsoft Defender for Endpoint (MDE), Tanium, or Elastic Endpoint Protection as either deployment or day-to-day operations, and maintenance of the solution

  • 2+ years of experience in working with a Security Operations Center (SOC) environment, leveraging EDR tools to support incident response, vulnerability scanning, threat hunting, network monitoring and log management, and compliance management activities

  • Experience with deployment of an EDR solution in a customer environment

  • Experience with optimization of EDR solutions, including refinement data produced, development of automated workflows or playbooks, and integration if the EDR data with Enterprise solutions, including SIEM, ITSM, and TIP solutions

  • Ability to provide content on deliverables, including written reports and technical documents, SOPs and configuration guides, and training and briefing materials

  • Ability to obtain a security clearance

  • HS diploma or GED

Nice If You Have:

  • Experience with triaging security events in a SOC environment and leveraging data collected from enterprise security solutions

  • Experience with providing support in a Tier I or II IT operations and maintenance role, including ticket work information updates, issue responses, and remediation

  • Knowledge of federal information security policies, standards, procedures, directives, frameworks, federal security authorizations, assessment, and risk management processes for enterprise systems

  • Ability to integrate cybersecurity data using enterprise or custom tools data aggregation and analysis tools, including Splunk

  • Possession of excellent written and verbal communication skills

  • Bachelor’s degree

  • EDR Vendor Certifications


Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information.


At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full time and part time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs, individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. 

Salary for this position is determined by various factors, including but not limited to, location, the candidate’s particular combination of knowledge, skills, competencies and experience, as well as contract specific affordability and organizational requirements. The proposed salary range for this position is outlined below.

Colorado: $88,500 - $184,900 (annualized USD)

New York (including New York City): $94,000 - $226,000 (annualized USD)

Build Your Career:

Rewarding work, fun challenges, and a ton of investment in our people—that’s Booz Allen cyber. When you join Booz Allen, we’ll help you develop the career you want.

Competitions — From programming competitions at our PyNights (Python competition and learning events) to competing in CTFs, we’ve got plenty of chances for you to show off your skills.

Paid Research — Have an innovative idea to explore or hypothesis to test? You can participate in challenges via our crowdsourcing platform, the Garage, and other programs to be awarded dedicated time and/or funding to advance your skills.

Cyber University — CyberU has more than 5000 instructor-led and self-paced cyber courses, a free online library that you can access from just about anywhere—including your phone—and certification exam prep guides that include practical assessments to prepare you for your exam.

Academic Partnerships — In addition to our tuition reimbursement benefit, we’ve partnered with University of Maryland University College to offer two graduate certificate programs in cybersecurity—fully funded without a tuition cap.

Maker/Hackerspaces — Race drones, print 3D gadgets, drink coffee from our Wi-Fi coffee maker, and get hands-on training on tools and tech from in-house experts in our dedicated maker and hackerspaces.

We’re an equal employment opportunity/affirmative action employer that empowers our people to fearlessly drive change – no matter their race, color, ethnicity, religion, sex (including pregnancy, childbirth, lactation, or related medical conditions), national origin, ancestry, age, marital status, sexual orientation, gender identity and expression, disability, veteran status, military or uniformed service member status, genetic information, or any other status protected by applicable federal, state, local, or international law.

Not ready to apply? Join our talent community and sign up for job alerts.