Перейти к основному содержимому
Proficio

MEDR Threat Engineer US work hours

УдалённоIndia только
Опубликовано
Роль
Безопасность
Опыт
Мидл
Зарплата не указана
Проверьте доступность

Доступно для: IN only. Укажите, откуда вы работаете, чтобы проверить доступность.

Коротко по делу

Experienced endpoint security engineer for US work hours in India. Needs 3+ years hands-on enterprise EDR, at least two MDR/EDR platforms, XDR, policy tuning, detections, integrations, and Windows/macOS/Linux security.

Ключевые навыки

EDRXDREndpoint Security

Обязательные навыки

WindowsmacOSLinuxCrowdStrike Falcon/SentinelOne/Microsoft Defender for Endpoint/Carbon Black/Cortex XDR/Cisco XDR/Trend MicroAPIsSIEMSOARITSM

Желательные навыки

CrowdStrike FusionSentinelOne automationCisco XDR workflowsCortex XDR automationMicrosoft Defender automationVirusTotalAlienVault OTXAbuseIPDB

Чем предстоит заниматься

  • Act as a subject matter expert for enterprise EDR/XDR technologies and endpoint security solutions across Windows, macOS, and Linux.
  • Design, configure, and maintain EDR/XDR security policies, including prevention controls, detection policies, exclusions, application controls, and other endpoint security configurations.
  • Manage EDR deployments, agent/sensor upgrades, endpoint health, policy assignments, and troubleshooting across customer environments.
  • Create and maintain custom detections, behavioral rules, IOCs, blocklists, and other detection use cases based on emerging threats and customer requirements.
  • Perform threat hunting and advanced investigation of security events involving malware, ransomware, phishing, PowerShell, scripts, lateral movement, persistence, privilege escalation, credential attacks, and other MITRE ATT&CK techniques.
  • Design and maintain integrations between EDR/XDR platforms and SIEM, SOAR, ticketing, identity, email security, threat intelligence, and other security platforms.
  • Work closely with SOC and MDR teams to improve detection coverage, alert quality, investigation processes, and incident response capabilities.
  • Work with customers to understand security requirements, identify use cases, and translate those requirements into EDR/XDR policies, detections, automations, and security controls.
  • Analyze email security events, including phishing attempts, malicious URLs, attachments, suspicious senders, and related endpoint activity.
  • Maintain and administer endpoint security technologies including EDR, antivirus, DLP, web filtering, and email security solutions.
  • Escalate security incidents, detections, and alerts to customers through ITSM and ticketing platforms and provide appropriate investigation details and recommendations.
  • Prepare technical documentation, security assessments, operational reports, and customer-facing security reports.
  • Collaborate with internal security, infrastructure, and engineering teams to troubleshoot complex endpoint security and integration issues.

Что требуется

  • The Managed Infrastructure Services team is seeking an experienced MEDR Threat Engineer who is technical, collaborative, and truly excited about working on endpoint products.
  • Bring your in-depth knowledge of the endpoint and detection response tasks to help guide the evolution of Proficio's Managed EDR visibility, detection, and prevention technologies.
  • Ability to interface and influence cross-functional teams throughout the company.
  • 3+ years of hands-on experience with enterprise EDR solutions, including deployment, configuration, administration, troubleshooting, and ongoing management.
  • Hands-on experience with at least two enterprise MDR platforms such as CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Carbon Black, Cortex XDR, Cisco XDR, or Trend Micro.
  • Experience with at least one XDR and an understanding of how security telemetry from different sources can be correlated.
  • Strong experience with EDR/XDR policy configuration, deployment, tuning, exclusions, prevention controls, and endpoint management.
  • Experience developing or tuning custom detections, detection rules, indicators, blocklists, and automated response actions.
  • Experience integrating security platforms using APIs, connectors, or other integration methods, including integrations with SIEM, SOAR, ITSM, identity, email security, and threat intelligence platforms.
  • Experience troubleshooting endpoint agents, deployment issues, policy conflicts, connectivity problems, and security tool configuration issues.
  • Knowledge of Windows, macOS, and Linux operating systems and their security configurations and management tools.
  • Knowledge of network security concepts, including network topology, protocols, components, and common security controls.
  • Experience working in a SOC, MDR, MSSP, or customer-facing security environment is highly desirable.
  • Ability to analyze security events and correlate endpoint, network, identity, email, and other security telemetry.
  • Preferred: Experience with security automation platforms and workflows such as CrowdStrike Fusion, SentinelOne automation, Cisco XDR workflows, Cortex XDR automation, Microsoft Defender automation, or similar technologies.
  • Preferred: Experience with threat intelligence platforms such as VirusTotal, AlienVault OTX, AbuseIPDB, Cisco Talos, or similar tools.
  • Preferred: Experience with scripting and automation using PowerShell, Python, or similar languages.
  • Preferred: Experience with Microsoft security technologies including Microsoft Entra ID, Intune, Microsoft Defender, and related security services.
  • Preferred: Experience creating security dashboards, detection coverage metrics, customer assessments, QBRs, or monthly security reports.
  • Preferred: Knowledge of vulnerability management, compliance, security frameworks, and security operations processes.

Преимущества

  • Opportunity to work in a progressive organization with structured training and roadmap for success
  • Meals, Gym, Internet and other reimbursement programs
  • Experience in one of the hottest IT industries today

Proficio is an award-winning managed detection and response (MDR) services provider. We provide 24/7 security monitoring, investigation, alerting and response services to organizations in healthcare, financial services, manufacturing, retail and other industries.

Cybersecurity
Зарплата не указана