← Back to results

edr jobs in San Diego

$65,000 – $85,000 · Posted 2 days ago

An Associate Cybersecurity Engineer will monitor security alerts from SIEM, EDR, and IDS/IPS tools to detect and triage security incidents, then investigate confirmed events and support containment and recovery efforts. The role includes threat analysis, vulnerability validation, security awareness training administration, and phishing simulation campaign execution.… The engineer will document investigations, maintain runbooks and playbooks, and collaborate with Security, IT, and DevOps teams while supporting compliance frameworks (SOC 2, ISO 27001, PCI DSS).

San DiegoLast seen 1 day ago
Posted 2 days ago

Lead high-severity incident investigations, mentor L1/L2 analysts, and drive detection engineering at a cybersecurity services firm. Responsibilities include threat hunting, malware analysis, digital/network forensics, SIEM/EDR tuning (KQL, SPL, Sigma, YARA), playbook development, and automation scripting in Python/PowerShell/Bash.… This is a 5+ year senior incident responder role requiring deep hands-on expertise across the full incident response lifecycle, MITRE ATT&CK, and client-facing technical briefings.

San DiegoLast seen 1 day ago
$82,600 – $162,800 · Posted 5 days ago

As a Managed Services Engineer II (L1 SOC Analyst) on Deloitte's Cyber Operate team, you will monitor security alerts from SIEM and other security tools, validate and escalate incidents within SLA timeframes, investigate suspected threats, and perform IOC searches. You will respond to security events using documented procedures, distinguish false positives from genuine incidents, coordinate with escalation paths, and maintain runbooks and shift handover documentation.… The role requires a Bachelor's degree in IT/Computer Science plus 1+ years of security operations or cybersecurity experience, hands-on familiarity with SIEM platforms, IDS/IPS, EDR, DLP, WAF, firewalls, and threat intelligence, and the ability to work rotating 24/7 shifts from a Deloitte office 50% of the time.

San DiegoLast seen 3 days ago
$157,675 – $238,500 · Posted 15 days ago

Build, deploy, and continuously improve MITRE ATT&CK–aligned threat detections across cloud, endpoint, identity, email, and application telemetry. Own the full detection lifecycle from hypothesis and data validation through deployment, tuning, and retirement, advancing a detection-as-code platform with version control, peer review, automated testing, and CI/CD.… Evaluate AI-powered security capabilities including LLMs, anomaly detection, and response automation. Partner with Security Operations on investigations, incidents, and detection maintenance.

San DiegoLast seen 13 days ago
$117,000 – $130,000 · Posted 18 days ago

The Cybersecurity Analyst leads Bumble Bee's day-to-day cybersecurity operations, investigating and responding to security incidents, hunting threats, and tuning detection tooling. The role owns the full incident response lifecycle, manages vulnerability remediation, optimizes SIEM platforms, conducts security risk assessments for platforms and vendors, and maintains compliance through access control reviews and policy development.… The analyst builds incident response playbooks, monitors threat intelligence and CVE disclosures, and advises on third-party cyber risk. The position requires 4+ years of cybersecurity experience, proficiency with SIEM platforms, EDR tools, vulnerability management, MITRE ATT&CK framework, and knowledge of NIST, SOC, and ISO standards.

San DiegoLast seen 16 days ago
$130,000 – $175,000 · Posted 20 days ago

A Senior Endpoint Engineer will stand up and manage Microsoft 365 (Exchange Online, SharePoint, Teams, Entra ID) and endpoint management platforms (Intune, Jamf) from scratch in a startup environment. Responsibilities include designing IT onboarding/offboarding workflows, implementing endpoint security policies (EDR, disk encryption, patch management, conditional access), managing vendor relationships and budgets, and providing Tier 1/2 technical support.… The role requires 4+ years of hands-on IT operations or systems administration experience, deep proficiency with Microsoft 365 and MDM/UEM platforms, strong networking fundamentals, and scripting ability (PowerShell, Bash, or Python); must support SOC 2 and ISO 27001 compliance.

San DiegoLast seen 18 days ago
$129,986 – $216,609 · Posted 27 days ago

Lead a team of security engineers responsible for the operational effectiveness and innovation of security engineering controls across LPL Financial. Manage day-to-day operations and maintenance of critical security infrastructure including SIEM, EDR, DLP, vulnerability management, IAM systems, and network security appliances.… Drive continuous improvement initiatives, develop incident response playbooks, collaborate with engineering teams on security integration, and provide technical leadership and mentorship to junior engineers. Requires 10+ years in information security with at least 5 years in a security operations or engineering leadership role.

San DiegoLast seen 25 days ago
$117,000 – $130,000 · Posted 1 month ago

The Cybersecurity Analyst owns Bumble Bee's day-to-day security operations, investigating and responding to incidents, hunting threats, and tuning detection tooling to close coverage gaps. Responsibilities include managing the full incident response lifecycle, optimizing SIEM platforms, conducting vulnerability assessments, performing access control audits, and building incident response playbooks and procedures.… The role requires 4+ years of cybersecurity experience, proficiency with SIEM platforms, EDR tools, vulnerability management platforms, and hands-on knowledge of Windows/Linux, networking, and the MITRE ATT&CK framework. Success demands both technical operations expertise and cross-functional collaboration to strengthen security posture, ensure compliance, and assess third-party cyber risk.

San DiegoLast seen 1 month ago
Posted 1 month ago

Security Operations Analyst role monitoring and triaging alerts across endpoint, cloud, identity, network, and SaaS using enterprise SIEM and XDR platforms. Responsibilities include investigating alerts, performing root-cause analysis, tuning detections, owning initial response for mid-tier incidents, participating in on-call rotation, running targeted threat hunts, and contributing to playbooks and post-incident reviews.… Requires 2–5 years of hands-on SecOps, SOC, or incident response experience; proficiency with enterprise SIEM query languages, EDR tooling, and scripting in Python/PowerShell/Bash; and solid understanding of MITRE ATT&CK and network fundamentals.

San DiegoLast seen 1 month ago
$113,200 – $141,500 · Posted 1 month ago

This Cybersecurity Manager role owns vulnerability and exposure management, leads penetration testing, threat hunting, and threat intelligence programs. The position integrates AI and machine learning into security operations to enhance threat detection and anomaly identification, manages security tools and incident response, and ensures the security of AI/ML systems across the enterprise.… The candidate will develop automation scripts and SOAR workflows, conduct forensic investigations, and drive continuous improvement in the security posture. Required qualifications include 5+ years of cybersecurity experience, a relevant bachelor's degree, and an industry-recognized certification (Security+, SSCP, CCNP Security, CISSP, or equivalent).

San DiegoLast seen 1 month ago
Posted 1 month ago

This Systems Administrator role supports Trulioo's IT infrastructure across global locations, managing Mac and PC endpoint provisioning and patching via Jamf and Intune, administering identity platforms (Google Workspace, Azure/Entra ID, OneLogin), and providing day-to-day SaaS platform support including email security (Mimecast) and basic network troubleshooting (Meraki). The role requires 2+ years of IT support or systems administration experience, hands-on familiarity with endpoint management and identity/access tools, and the ability to manage tickets, maintain documentation, and support new-hire onboarding across time zones.… The candidate will use AI tools to enhance efficiency and contribute to continuous process improvement.

San DiegoLast seen 1 month ago
$159,650 – $266,049 · Posted 1 month ago

Lead a team of security engineers responsible for deploying, integrating, optimizing, and managing enterprise cybersecurity platforms including SIEM (Splunk, Elasticsearch), XDR, EDR, email gateways, and vulnerability management across on-premises and cloud environments. Develop and execute cybersecurity tooling strategy aligned with business objectives, regulatory requirements (NIST CSF, ISO 27001, SOC 2, PCI-DSS), and industry best practices.… Automate threat detection, response, compliance reporting, and operational workflows using Python, PowerShell, and Bash. Mentor security engineering teams while managing budgets, cross-functional partnerships, and executive reporting on security posture and tooling effectiveness.

San DiegoLast seen 24 days ago
Posted 1 month ago

Lead detection operations, incident response, and security operations maturation for a growing security team. Operate SIEM/XDR across endpoint, cloud, identity, network, and SaaS telemetry; conduct complex investigations; tune detections; and drive root-cause analysis and post-incident improvements.… Require 6+ years of hands-on security operations, detection engineering, or incident response experience with deep proficiency in SIEM/XDR query languages, EDR platforms, scripting (Python, PowerShell, Bash), and MITRE ATT&CK framework application. Mentor analysts, define playbooks and runbooks, lead threat hunts, and own SecOps metrics and operational-readiness reporting.

San DiegoLast seen 1 month ago
$70,000 – $85,000 · Posted 1 month ago

Support the implementation, monitoring, and maintenance of security controls across endpoint, identity, and Microsoft 365 environments at a pharmaceutical company. Responsibilities include monitoring security alerts, managing endpoint security in Microsoft Intune, maintaining device compliance policies, investigating security issues, and automating tasks with PowerShell.… The role requires a foundational background in IT support, system administration, or security operations, with 1+ years of experience and hands-on exposure to Microsoft Defender Portal, MDM/MAM policies, and security investigation.

San DiegoLast seen 24 days ago
$80,000 – $110,000 · Posted 1 month ago

This cybersecurity engineer role focuses on securing cloud infrastructure (AWS, Azure, GCP), containerized environments (Docker, Kubernetes), and applications through vulnerability management, risk assessment, and security architecture review. The position requires hands-on experience with SIEM, EDR, WAF configuration, and embedding security scanning (SAST, DAST, SCA) into CI/CD pipelines.… The engineer will conduct threat modeling, manage IAM policies, perform penetration testing coordination, support incident response and post-incident reviews, and partner with engineering teams to balance security with delivery. The role also includes compliance support, vendor risk assessments, and serving in an on-call rotation for after-hours security incidents.

San DiegoLast seen 26 days ago
$80,000 – $110,000 · Posted 1 month ago

This role is a hands-on cybersecurity engineer responsible for securing cloud infrastructure (AWS, Azure, GCP), containerized environments (Docker, Kubernetes), and applications. Key duties include vulnerability scanning and penetration testing, threat modeling, Web Application Firewall (WAF) deployment and tuning, CI/CD security integration (SAST, DAST, SCA), incident response, and compliance support.… The engineer will work closely with DevOps and application teams to embed security controls, conduct code and architecture reviews, and provide risk-based guidance. Required experience includes 3–5+ years in cybersecurity or security engineering, hands-on SIEM/EDR/vulnerability management tools, cloud platforms, WAF configuration, and scripting (Python, Bash, PowerShell).

San DiegoLast seen 1 month ago