EDR Administration & Fleet Health: Oversee the deployment, lifecycle management, and configuration of multiple enterprise EDR platforms (e.g., CrowdStrike, SentinelOne, Microsoft Defender for Endpoint). Monitor and maintain agent health across all managed endpoints, troubleshooting failures and performance issues to maintain established service levels.
Policy & Detection Engineering: Develop and refine detection policies and indicators to improve detection rates and minimize false positive alerts. Translate threat intelligence into actionable endpoint rules to ensure high-fidelity alerting.
Cloud Workload Protection: Manage security deployments across multi-cloud environments (AWS, Azure, or GCP). Ensure consistent telemetry and protection for virtual machines and containerized workloads, utilizing cloud-native security services as required.
Systems Integration & Tooling Support: Work with engineering teams to maintain integrations between EDR consoles and existing SIEM/SOAR platforms. Provide secondary technical support for auxiliary security technologies, including Audit and DLP tools.
Incident Response Support: Assist IR analysts during active security incidents by performing endpoint containment, executing live response scripts, and conducting remote data collection. Assist in the restoration of systems and the hardening of endpoint policies post-incident.
Operational Reliability & Documentation: Adhere to formal change management processes for all policy modifications. Maintain clear technical documentation, Standard Operating Procedures (SOPs), and configuration baselines for internal stakeholders.