Job
Description
Description:
L3 Endpoint SME, SME will be responsible for the configuration, management, monitoring, analysis, and threat hunting related to our endpoint security suite, which includes Microsoft Defender for endpoint with advanced Hunting (MDE, MDI MDO), Microsoft BitLocker, and McAfee Trillix. This role requires a deep understanding of endpoint security best practices and the ability to translate them into robust endpoint protection strategies. Responsibilities:Configuration and Management:oDeep dive into the functionalities of Microsoft Defender (MDE, MDI MDO), Microsoft Defender Firewall, and Microsoft BitLocker. oCollaborate with security engineers to configure and optimize these tools for maximum protection against evolving threats. oLeverage Microsoft Defender (MDE, MDI MDO) to centrally manage and enforce endpoint security policies across the organization's devices. oStay updated on the latest threat intelligence and adjust configurations proactively to mitigate emerging risks. Monitoring and Analysis:oProactively monitor endpoint security alerts from Microsoft Defender (MDE, MDI MDO), identifying potential threats and incidents. oInvestigate security incidents related to endpoints, working with internal teams to understand the root cause, remediate the issue, and prevent future occurrences. oAnalyze endpoint security data to identify trends, suspicious activities, and potential vulnerabilities. oGenerate reports and provide insights into the effectiveness of your endpoint security posture. Threat Hunting:oUtilize advanced threat hunting techniques within MDE to proactively identify and respond to hidden threats within the network. oCollaborate with security analysts to develop and implement effective threat hunting strategies. Collaboration and Communication:oWork closely with security engineers, system administrators, and IT operations to ensure seamless integration of endpoint security solutions with existing infrastructure. oParticipate in security awareness training programs to educate employees on endpoint security best practices. oMaintain clear and concise documentation of endpoint security configurations, policies, and procedures for knowledge sharing and future reference. Qualifications:Minimum 8-10 years of experience in information security or a related field, with a focus on endpoint security. Proven experience in configuring, managing, and monitoring endpoint security solutions Microsoft Defender suite (AV, Firewall). Experience with endpoint management tools. Strong understanding of endpoint threats, vulnerabilities, and malware analysis techniques. Excellent analytical, problem-solving, and critical thinking skills. Experience with threat hunting methodologies and tools is a plus. Strong written and verbal communication skills. Ability to work independently and as part of a team in a fast-paced environment. Preferred Skills:Experience with scripting languages (KQL, PowerShell) is a plus. Experience with security frameworks (NIST CSF, PCI DSS) is a plus. Strong understanding of network protocols and data exfiltration techniques. Certifications in security (CISSP, Security+, CCNA Security) are a plus. Named Job Posting? (if Yes - needs to be approved by SCSC)Additional Details Global Grade :CLevel :To Be DefinedNamed Job Posting? (if Yes - needs to be approved by SCSC) :NoRemote work possibility :NoGlobal Role Family :To be definedLocal Role Name :To be definedLocal Skills :McAfee VirusScan Enterprise for Storage;Cisco Email GatewayLanguages Required::ENGLISHRole Rarity :To Be Defined