
MEDR Threat Engineer
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in India.
• Serve as the Subject Matter Expert (SME) for projects aimed at improving EDR visibility, detection, and prevention across Windows, macOS, and Linux platforms.
• Design and refine SOAR workflows and playbooks, seamlessly integrating them with EDR systems to enhance incident response and threat management capabilities.
• Create and deploy advanced SOAR solutions, incorporating custom automated workflows and orchestration to tackle complex security challenges.
• Establish and uphold the strategy and roadmap for detection functionalities within Carbon Black, CrowdStrike, and Sentinel One.
• Work in collaboration with SOC and Managed/Hosted SIEM teams to gain insights into emerging threat and attack trends.
• Recognize unmet customer needs, articulate use cases, and enhance the functional capabilities of the solution offered.
• Oversee, manage, and support endpoint security management tools, including antivirus, data loss prevention, and web/spam filtering solutions.
• Assist clients in addressing viruses and system vulnerabilities or threats.
• Implement strategies and efficiencies to improve the detection and response to cyber incidents, alerts, and detections.
• Elevate detections, incidents, and alerts to clients utilizing ITSM/ITIL tools.
• A minimum of 4 years of experience in IT within a professional setting.
• At least 3 years of experience in deploying, configuring, or maintaining enterprise EDR solutions, such as CrowdStrike Falcon, Microsoft Defender, and/or Sentinel One.
• Additional experience with Cisco Secure Endpoint and Sophos is advantageous.
• Over 3 years of experience in EDR and/or antivirus.
• Prior experience in malware and attack analysis, research, investigation, and response is highly sought after.
• At least 1 year of experience in systems administration, including basic troubleshooting, installation, system performance monitoring, and security upgrades.
• Familiarity with network security architecture concepts, encompassing topology, protocols, components, and principles.
• Understanding of enterprise operating system configurations and management tools relevant for EDR deployment, configuration, and management.
• Experience in a SOC environment involving incident response, vulnerability scanning, threat hunting, network monitoring/log management, or compliance management is a plus.
• Proficiency with enterprise security tools such as SIEM, threat intelligence platforms, or network monitoring tools is beneficial.
• Experience in triaging security events within a SOC environment using data from enterprise security solutions.
• Knowledge of intrusion detection methodologies and techniques applicable to both host- and network-based intrusions.
• Capability to integrate cybersecurity data using enterprise or custom data aggregation and analysis tools, including Splunk and Elastic.
• Opportunity to be part of a forward-thinking organization with structured training and a clear roadmap for success.
• Reimbursement programs for meals, gym memberships, internet, and other expenses.
• Gain experience in one of the most dynamic IT industries today.
Highland Electric Fleets
Falconwood, Incorporated
Aira
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.