Skip to main content
Proficio

MEDR Threat Engineer US work hours

RemoteIndia only
Published
Role
Security
Experience
Mid
Salary not disclosed
Check eligibility

Open to IN only. Set where you work from to check your eligibility.

No BS summary

Experienced endpoint security engineer for US work hours in India. Needs 3+ years hands-on enterprise EDR, at least two MDR/EDR platforms, XDR, policy tuning, detections, integrations, and Windows/macOS/Linux security.

Core skills

EDRXDREndpoint Security

Required skills

WindowsmacOSLinuxCrowdStrike Falcon/SentinelOne/Microsoft Defender for Endpoint/Carbon Black/Cortex XDR/Cisco XDR/Trend MicroAPIsSIEMSOARITSM

Optional skills

CrowdStrike FusionSentinelOne automationCisco XDR workflowsCortex XDR automationMicrosoft Defender automationVirusTotalAlienVault OTXAbuseIPDB

What you'll do

  • Act as a subject matter expert for enterprise EDR/XDR technologies and endpoint security solutions across Windows, macOS, and Linux.
  • Design, configure, and maintain EDR/XDR security policies, including prevention controls, detection policies, exclusions, application controls, and other endpoint security configurations.
  • Manage EDR deployments, agent/sensor upgrades, endpoint health, policy assignments, and troubleshooting across customer environments.
  • Create and maintain custom detections, behavioral rules, IOCs, blocklists, and other detection use cases based on emerging threats and customer requirements.
  • Perform threat hunting and advanced investigation of security events involving malware, ransomware, phishing, PowerShell, scripts, lateral movement, persistence, privilege escalation, credential attacks, and other MITRE ATT&CK techniques.
  • Design and maintain integrations between EDR/XDR platforms and SIEM, SOAR, ticketing, identity, email security, threat intelligence, and other security platforms.
  • Work closely with SOC and MDR teams to improve detection coverage, alert quality, investigation processes, and incident response capabilities.
  • Work with customers to understand security requirements, identify use cases, and translate those requirements into EDR/XDR policies, detections, automations, and security controls.
  • Analyze email security events, including phishing attempts, malicious URLs, attachments, suspicious senders, and related endpoint activity.
  • Maintain and administer endpoint security technologies including EDR, antivirus, DLP, web filtering, and email security solutions.
  • Escalate security incidents, detections, and alerts to customers through ITSM and ticketing platforms and provide appropriate investigation details and recommendations.
  • Prepare technical documentation, security assessments, operational reports, and customer-facing security reports.
  • Collaborate with internal security, infrastructure, and engineering teams to troubleshoot complex endpoint security and integration issues.

What they require

  • The Managed Infrastructure Services team is seeking an experienced MEDR Threat Engineer who is technical, collaborative, and truly excited about working on endpoint products.
  • Bring your in-depth knowledge of the endpoint and detection response tasks to help guide the evolution of Proficio's Managed EDR visibility, detection, and prevention technologies.
  • Ability to interface and influence cross-functional teams throughout the company.
  • 3+ years of hands-on experience with enterprise EDR solutions, including deployment, configuration, administration, troubleshooting, and ongoing management.
  • Hands-on experience with at least two enterprise MDR platforms such as CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Carbon Black, Cortex XDR, Cisco XDR, or Trend Micro.
  • Experience with at least one XDR and an understanding of how security telemetry from different sources can be correlated.
  • Strong experience with EDR/XDR policy configuration, deployment, tuning, exclusions, prevention controls, and endpoint management.
  • Experience developing or tuning custom detections, detection rules, indicators, blocklists, and automated response actions.
  • Experience integrating security platforms using APIs, connectors, or other integration methods, including integrations with SIEM, SOAR, ITSM, identity, email security, and threat intelligence platforms.
  • Experience troubleshooting endpoint agents, deployment issues, policy conflicts, connectivity problems, and security tool configuration issues.
  • Knowledge of Windows, macOS, and Linux operating systems and their security configurations and management tools.
  • Knowledge of network security concepts, including network topology, protocols, components, and common security controls.
  • Experience working in a SOC, MDR, MSSP, or customer-facing security environment is highly desirable.
  • Ability to analyze security events and correlate endpoint, network, identity, email, and other security telemetry.
  • Preferred: Experience with security automation platforms and workflows such as CrowdStrike Fusion, SentinelOne automation, Cisco XDR workflows, Cortex XDR automation, Microsoft Defender automation, or similar technologies.
  • Preferred: Experience with threat intelligence platforms such as VirusTotal, AlienVault OTX, AbuseIPDB, Cisco Talos, or similar tools.
  • Preferred: Experience with scripting and automation using PowerShell, Python, or similar languages.
  • Preferred: Experience with Microsoft security technologies including Microsoft Entra ID, Intune, Microsoft Defender, and related security services.
  • Preferred: Experience creating security dashboards, detection coverage metrics, customer assessments, QBRs, or monthly security reports.
  • Preferred: Knowledge of vulnerability management, compliance, security frameworks, and security operations processes.

Benefits

  • Opportunity to work in a progressive organization with structured training and roadmap for success
  • Meals, Gym, Internet and other reimbursement programs
  • Experience in one of the hottest IT industries today

Proficio is an award-winning managed detection and response (MDR) services provider. We provide 24/7 security monitoring, investigation, alerting and response services to organizations in healthcare, financial services, manufacturing, retail and other industries.

Cybersecurity
Salary not disclosed