Job
Description
About The Role
Project Role :Security Architect
Project Role Description :Define the cloud security framework and architecture, ensuring it meets the business requirements and performance goals. Document the implementation of the cloud security controls and transition to cloud security-managed operations.
Must have skills :Endpoint Extended Detection and Response
Good to have skills :NA
Minimum 5 year(s) of experience is required
Educational Qualification :15 years full time education
Summary:The EDR (Endpoint Detection and Response) Lead will be responsible for managing, optimizing, and maintaining the organization's endpoint security posture using CrowdStrike Falcon. This role involves leading the EDR operations team, ensuring proactive threat detection and response, and driving continuous improvement of endpoint protection capabilities across the enterprise
Roles & Responsibilities:-EDR Operations & Management-Lead day-to-day operations of the CrowdStrike Falcon platform, including monitoring, tuning, and policy management.-Manage alert triage, investigation, and response to endpoint-related security incidents.-Coordinate with SOC and Incident Response teams for end-to-end handling of EDR detections.-Oversee onboarding, configuration, and maintenance of endpoints in CrowdStrike.-Threat Detection & Response-Develop and fine-tune detection rules, custom IOCs, and response playbooks.-Ensure timely containment, remediation, and recovery of compromised endpoints.-Conduct deep-dive investigations and root cause analysis for critical incidents.-Collaborate with Threat Intelligence teams to improve detection efficacy.
Governance & Process Improvement-Define and implement EDR operational procedures, KPIs, and reporting mechanisms.-Ensure alignment with enterprise cybersecurity policies and regulatory compliance standards.-Conduct periodic reviews of endpoint security coverage, gaps, and improvement opportunities.-Coordinate platform upgrades, integrations, and automation initiatives. Stakeholder & Team ManagementLead and mentor a team of EDR analysts and engineers.Collaborate with IT, Infrastructure, and Security Architecture teams for endpoint security enhancements.Engage with vendors and partners for support, roadmap discussions, and best practices.-Prepare regular executive summaries and dashboards on EDR performance and threat metrics.
Professional & Technical
Skills: -Experience in Information Security, with at least 56years in EDR management.-Proven expertise in CrowdStrike Falcon " administration, threat hunting, and response workflows.-Strong understanding of endpoint security, threat detection, malware analysis, and incident response.-Experience integrating EDR with SIEM, SOAR, and vulnerability management tools.-Familiarity with MITRE ATT&CK framework and modern adversary tactics, techniques, and procedures (TTPs).-Working knowledge of scripting/automation (PowerShell, Python) for EDR orchestration is an advantage.-Excellent analytical, communication, and leadership skills.-CrowdStrike Certified Falcon Administrator (CCFA) or CrowdStrike Certified Falcon Responder (CCFR)-GIAC Certified Incident Handler (GCIH), CEH, or CISSP-ITIL Foundation (for operational process alignment)
Additional Information: The candidate should have minimum 5 years of experience in Endpoint Extended Detection and Response. This position is based at our Bengaluru office. A 15 years full time education is required.
Qualification15 years full time education