Senior Endpoint Security Engineer
Listed on 2026-10-02
-
IT/Tech
Cybersecurity
Location:
Remote
Come join our passionate team! Barracuda is a leading cybersecurity company providing complete protection against complex threats. Our platform protects email, data, applications, and networks with innovative solutions, and a managed XDR service, to strengthen cyber resilience. Hundreds of thousands of IT professionals and managed service providers worldwide trust us to protect and support them with solutions that are easy to buy, deploy, and use.
We know a diverse workforce adds to our collective value and strength as an organization. Barracuda Networks is proud to be an Equal Opportunity Employer, committed to equal employment opportunity and equitable compensation regardless of race, gender, religion, sex, sexual orientation, national origin, or disability.
Envision Yourself at Barracuda:We are seeking a Senior Endpoint Security & IR Engineer to join our incident response team. You will lead management of our Sentinel One XDR platform, complex investigations across multiple client environments, drive rapid containment of active threats, and serve as a trusted advisor to clients during their most critical security events. This role combines deep technical expertise with client-facing communication skills in a fast-paced, multi-tenant MSSP environment.
You will work closely with our Cyber Concierge, Threat Analysts and Automation teams to continuously improve our response capabilities and protect our clients from sophisticated adversaries.
What You’ll be Working On:Expert knowledge and experience in Sentinel One – Key Requirement
Lead end-to-end incident response engagements across diverse client environments, from initial triage through remediation and lessons learned
Perform host-based forensics using Binalyze AIR for remote evidence acquisition, triage, and analysis at scale
Design custom detection rules within Sentinel One and fine tune protection policies.
Proven experience in windows, mac and linux environments
Investigate alerts and threats detected by Sentinel One, including Deep Visibility hunting, threat timeline reconstruction, and MITRE ATT&CK mapping
Analyze Microsoft 365 security incidents including business email compromise, OAuth abuse, mailbox rule manipulation, and Azure AD/Entra
Conduct log analysis and threat hunting in Elastic to identify indicators of compromise, lateral movement, and data exfiltration
Leverage Databricks for large-scale log analytics, anomaly detection, and threat hunting across aggregated client telemetry
Document findings in clear, executive-ready incident reports tailored to both technical and non-technical stakeholders
Participate in a 24/7 on-call rotation
Develop and maintain Python scripts for evidence collection, log parsing, IOC enrichment, and automated response actions
Build and optimize automated response workflows in Tines to accelerate containment and MTTR
Create and tune detection rules in Elastic and Sentinel One based on investigative findings and emerging threat intelligence
Integrate tooling across the security stack to streamline IR workflows and reduce manual effort.
Serve as the primary IR point of contact for client stakeholders during active incidents
Conduct client-facing incident briefings, root cause analysis presentations, and post-incident reviews
Deliver actionable remediation guidance tailored to each client's environment and risk tolerance
Maintain SLA commitments for incident acknowledgment, updates, and resolution
Contribute to client security posture assessments and IR readiness recommendations.
Minimum of bachelor’s degree in computer science and 5+ years of hands-on experience in incident response, digital forensics,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).