Endpoint Detection and Response Subject Matter

7 - 10 years

7 - 15 Lacs

Posted:1 day ago| Platform: Naukri logo

Apply

Work Mode

Work from Office

Job Type

Full Time

Job Description

Role & responsibilities

  • Continuous Endpoint Monitoring:

    Monitor endpoint telemetry in real-time to detect Indicators of Attack (IOAs) and Indicators of Compromise (IOCs).
  • Alert Triage and Escalation:

    Validate and triage alerts generated by CrowdStrike Falcon Insight, escalating confirmed threats to Level 2/Level 3 SOC teams.
  • Real-Time Threat Investigation and Remediation:

    Utilize Real Time Response (RTR) capabilities to investigate and remediate threats directly on endpoints without impacting operations.
  • Sensor Issue Troubleshooting:

    Assist in troubleshooting sensor-related problems, including collecting logs and performing root cause analysis.
  • Vendor Support Management:

    Raise and manage support cases with CrowdStrike for unresolved technical issues, ensuring timely resolution.
  • Documentation and Knowledge Management:

    Maintain documentation of known issues, fixes, and best practices for EDR deployment and maintenance.
  • Proactive Threat Hunting:

    Conduct proactive threat hunting activities using both historical and real-time data from CrowdStrike Falcon.
  • Leveraging Threat Intelligence:

    Use CrowdStrike Adversary Intelligence to correlate endpoint behavior with known attacker tactics, techniques, and procedures (TTPs).
  • Collaboration with Security Teams:

    Work closely with threat intelligence teams to enhance detection logic and improve incident response workflows.
  • Governance and Reporting:

    Participate in governance forums and SLA reviews; report on EDR performance, coverage, and incident metrics.
  • Compliance and Security Posture:

    Ensure endpoint security practices comply with internal policies and external regulatory requirements.
  • Executive Reporting and Auditing:

    Contribute to executive dashboards and audit documentation to communicate endpoint security posture.
  • Cross-Functional Security Integration:

    Collaborate with SOC, SIEM, DLP, and Cloud Security teams to integrate endpoint telemetry into broader detection and response strategies.
  • Automation and Enrichment Support:

    Support CDC operations by aligning EDR capabilities with automation playbooks and GenAI-driven enrichment processes.

Preferred candidate profile

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now
T&m logo
T&m

Engineering, Environmental Services

Cherry Hill

RecommendedJobs for You