
Endpoint Security Engineer
- Koramangala, Karnataka Bangalore, Karnataka
- Permanent
- Full-time
- Full management of the endpoint protection platform for all tenants.
- Proactive testing of new product features and agent versions released.
- Proactive threat hunting within the admin console.
- Conduct attack and defend exercises within our lab environments to evaluate protection capabilities based on latest endpoint security threats.
- Responsible for supporting incident response efforts pertaining to endpoint security incidents.
- Ongoing development of rules within the XDR platform to alert customers of endpoint threat detections.
- Execute and automate remediation actions based on endpoint security threats detected within the XDR platform.
- Manage device policies to ensure optimal security settings are applied to best fit each tenant.
- Implement changes as requested by customers. Changes include but are not limited to:
- Exclusions
- Block-listing
- Policy changes
- Device updates
- Troubleshoot any issues that may arise within the given tenants. This typically requires remote sessions working with customers in real-time.
- Regularly meet with vendor representatives to manage support cases, updates, etc.
- Support on-call schedule for the endpoint security team.
- Conduct knowledge-share and training for the GSOC team as a whole on endpoint protection updates.
- Ensure the customer security dashboard displays visualizations and reports of all relevant endpoint protection data to the customers.
- Hands-on experience working with and managing advanced endpoint protection tools such as:
- Carbon Black
- CrowdStrike
- Cylance
- SentinelOne
- Experience working in a security operations center.
- Security analysis and incident response skills pertaining specifically to endpoint security threats such as malware, ransomware, etc.
- Experience conducting testing within lab/sandbox environments.
- Knowledgeable in conducting cybersecurity threat hunting.
- Strong customer service skills.
- Knowledge and understanding of corporate IT environments: networking, cloud, etc.
- Bachelor's/Master's degree in cybersecurity or relevant field is preferred.
- CEH, CompTIA Security+, and similar certifications or cybersecurity bootcamps are preferred.