
MEDR Threat Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in India.
• Serve as the Subject Matter Expert (SME) for projects aimed at improving EDR visibility, detection, and prevention across Windows, macOS, and Linux platforms.
• Develop and refine SOAR workflows and playbooks, ensuring their integration with EDR systems to enhance incident response and threat management effectiveness.
• Create and implement advanced SOAR solutions, including tailored automated workflows and orchestration that tackle significant security challenges.
• Establish and uphold the strategy and roadmap for detection functionalities involving Carbon Black, CrowdStrike, and Sentinel One in collaboration with team members and other departments.
• Work closely with SOC and Managed/Hosted SIEM teams to gain insights into threat and attack patterns.
• Recognize unmet customer needs, clarify use cases, and enhance the functional capabilities of the service offering.
• Manage, administer, and provide endpoint security management tools, such as antivirus, data loss prevention, and web/spam filtering solutions.
• Support customers with issues related to viruses and system vulnerabilities/threats.
• Implement efficiencies and develop strategies to improve the detection and response to cyber incidents, alerts, and other detections.
• Escalate detections, incidents, and alerts to customers utilizing ITSM/ITIL tools.
• Over 4 years of experience in IT within a professional work environment.
• More than 3 years of experience in deploying, configuring, or maintaining enterprise EDR solutions, including CrowdStrike Falcon, Microsoft Defender, and/or Sentinel One.
• Additional experience with Cisco Secure Endpoint and Sophos is advantageous.
• At least 3 years of experience in EDR and/or antivirus, with a strong emphasis on malware and attack analysis, research, investigation, and response.
• A minimum of 1 year of experience in systems administration, which includes troubleshooting, installation, performance or availability monitoring, and security upgrades.
• Familiarity with network security architecture concepts, including topology, protocols, components, and principles.
• Understanding of enterprise operating system configurations and management tools for EDR deployment, configuration, and management.
• Experience in a SOC environment, particularly in incident response, vulnerability scanning, threat hunting, network monitoring/log management, or compliance management, is beneficial.
• Familiarity with enterprise security tools such as SIEM, threat intelligence platforms, or network monitoring tools is a plus.
• Experience in triaging security events within a SOC environment using data from enterprise security solutions.
• Understanding of intrusion detection methodologies and techniques for both host- and network-based intrusions.
• Ability to integrate cybersecurity data using either enterprise or custom aggregation and analysis tools, including Splunk and Elastic.
• Opportunity to be part of a forward-thinking organization with structured training and a roadmap for success.
• Reimbursement programs for meals, gym, internet, and other expenses.
• Experience in one of the most dynamic IT sectors today.
Highland Electric Fleets
Falconwood, Incorporated
Aira
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.