Senior Security Engineer - EDR & NDR
Indexed description
The engineer will work closely with SOC Analysts, Incident Response, Threat Intelligence, SIEM Engineering, Solution Architects, and customers to deliver high-quality Managed Security Services and support strategic cybersecurity initiatives.
Responsibilities
- EDR Platform Administration
- Deploy, configure, administer, and maintain enterprise EDR platforms including:
- Microsoft Defender for Endpoint
- CrowdStrike Falcon
- Carbon Black
- Trend Micro Vision One / Apex One
- Perform health checks, upgrades, troubleshooting, and lifecycle management.
- Configure prevention policies, detection rules, IOC/IOA indicators, device control, and endpoint security baselines.
- Fine-tune EDR policies to minimize false positives while maintaining effective detection coverage.
- Perform endpoint containment, host isolation, malware remediation, and forensic support during security incidents.
- Support endpoint onboarding, offboarding, RBAC configuration, and policy management.
- Integrate EDR platforms with SIEM, SOAR, Identity, and Threat Intelligence solutions.
- NDR Platform Administration
- Deploy, configure, administer, and maintain Network Detection & Response platforms including:
- Vectra AI
- ExtraHop Reveal(x)
- Configure sensors, packet capture, metadata collection, and monitoring infrastructure.
- Tune AI-based detections and behavioural analytics.
- Investigate suspicious network activities including lateral movement, command-and-control communications, ransomware, insider threats, and credential abuse.
- Integrate NDR platforms with SIEM, SOAR, EDR, and Threat Intelligence platforms.
- Perform platform health monitoring, upgrades, and capacity management.
- Engineering & Integration
- Design and implement integrations between EDR, NDR, SIEM, SOAR, Threat Intelligence Platforms, Active Directory, Microsoft Entra ID, and ITSM platforms.
- Develop automation workflows using APIs and scripting to improve operational efficiency.
- Create and maintain architecture diagrams, technical documentation, SOPs, and operational runbooks.
- Support customer onboarding, migration, and platform integration projects.
- Validate telemetry collection, data quality, and event visibility across integrated security platforms.
- Threat Detection & Security Operations
- Work closely with SOC and Incident Response teams to investigate and respond to security incidents.
- Conduct threat hunting using endpoint, network, and SIEM telemetry.
- Develop and improve detection use cases aligned with the MITRE ATT&CK framework.
- Participate in purple team exercises, adversary emulation, and continuous improvement initiatives.
- Recommend security improvements based on emerging threats and incident findings.
- Operational Responsibilities
- Perform platform upgrades, patching, backup validation, and preventive maintenance.
- Monitor platform health, licensing, storage, and overall performance.
- Maintain technical documentation, SOPs, and knowledge base articles.
- Provide technical mentoring and guidance to junior engineers and SOC analysts.
- Participate in after-hours maintenance and critical incident support when required.
- Minimum 5–7 years of experience in cybersecurity engineering or security operations.
- Minimum 4 years of hands-on experience administering enterprise EDR platforms.
- Minimum 3 years of experience administering NDR platforms.
- Preferred Certifications
- CrowdStrike Falcon Administrator / Responder
- Microsoft Defender for Endpoint Administrator
- VMware Carbon Black Administrator
- Trend Micro Vision One Professional
- Vectra AI Certified Administrator
- ExtraHop Reveal(x) Certified Engineer
- Microsoft Certified: Security Operations Analyst (SC-200)
- Microsoft Certified: Azure Security Engineer (AZ-500)
- Splunk Core Certified Power User, Enterprise Security Admin, or Microsoft Sentinel certification (preferred)
- CISSP, GCIH, GCED, CySA+, Security+, or equivalent
- Working knowledge of SIEM platforms, preferably Splunk Enterprise Security and/or Microsoft Sentinel, including data onboarding, alert tuning, dashboards, and investigations.
- Experience supporting enterprise security platforms within a SOC or Managed Security Services (MSS) environment.
- EDR
- Microsoft Defender for Endpoint
- CrowdStrike Falcon
- VMware Carbon Black Cloud
- Trend Micro Vision One / Apex One
- NDR
- Vectra AI
- ExtraHop Reveal(x)
- SIEM
- Splunk Enterprise / Splunk Enterprise Security
- Microsoft Sentinel
- Basic knowledge of KQL and SPL
- Log onboarding and normalization
- Correlation rule development
- Dashboard creation
- Alert tuning
- Data connector troubleshooting
- Strong understanding of:
- Endpoint Security
- Network Security
- Incident Response
- Threat Hunting
- Detection Engineering
- MITRE ATT&CK Framework
- IOC/IOA Management
- Malware Analysis
- Windows and Linux Security
- Active Directory & Microsoft Entra ID
- Networking (TCP/IP, DNS, VPN, Firewalls)
- REST APIs
- PowerShell and/or Python scripting
- Health insurance with one of the leading global providers for medical insurance.
- Career progression and growth through challenging projects and work.
- Employee engagement and wellness campaigns activities throughout the year.
- Excellent learning and development opportunities.
- Inclusive and diverse working environment.
- Flexible/Hybrid working environment.
- Open door policy.
Help AG has firmly established itself as the region's trusted IT security advisor by remaining vendor-agnostic, trustworthy, independent, and maintaining its focus on all aspects of cybersecurity.
With best of breed technologies from industry-leading vendor partners, expertly qualified service delivery teams and a state-of-the-art consulting practice, Help AG delivers unmatched value to its customers by strengthening their cyber defenses and safeguarding their business.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search