EDR & Cloud Security Support (End point detection and response)
Atos India- Posted an hour ago
- Be among the first 10 applicants
Job Description
EDR & Cloud Security Support
Experience: 3–5+ years
Role Summary
Responsible for monitoring, administration, troubleshooting, investigation, and operational support of EDR/XDR and cloud security platforms. The role ensures endpoint and cloud threats are detected, investigated, escalated, and remediated within defined service-level agreements.
Key Responsibilities
- Monitor and investigate EDR/XDR alerts and incidents.
- Perform endpoint investigations covering processes, command lines, files, hashes, network connections, and user activity.
- Investigate malware, ransomware, suspicious PowerShell activity, persistence, lateral movement, and credential-related activity.
- Perform endpoint isolation, remediation, and other approved response actions.
- Review endpoint health, sensor or agent status, and protection status.
- Troubleshoot EDR agent deployment, connectivity, policy, and telemetry issues.
- Support EDR policy configuration, exclusions, and alert tuning.
- Coordinate with SOC, infrastructure, and endpoint teams to complete remediation.
- Track unresolved EDR issues and ensure closure within agreed SLAs.
- Monitor and investigate security alerts across Azure, AWS, and GCP, as applicable.
- Support Microsoft Defender for Cloud and broader cloud security monitoring.
- Investigate suspicious cloud authentication, privilege escalation, resource changes, and anomalous activity.
- Monitor cloud security posture, recommendations, security alerts, identities, network activity, resources, and security configurations.
- Support investigations involving Microsoft Entra ID identity and authentication events.
- Coordinate remediation of cloud security findings with cloud and platform teams.
- Assist with cloud security incident response and root-cause analysis.
- Support cloud security logging and integration with SIEM platforms.
Required Qualifications and Experience
- 3–5+ years of experience in EDR, endpoint security, cloud security, or SOC operations.
- Hands-on experience with Microsoft Defender for Endpoint, Defender XDR, or an equivalent EDR/XDR platform.
- Good understanding of endpoint telemetry and investigation techniques.
- Experience investigating malware, ransomware, suspicious PowerShell activity, suspicious processes, and endpoint compromise.
- Good understanding of Azure security and Microsoft Entra ID.
- Working knowledge of Microsoft Defender for Cloud.
- Good understanding of cloud identity and access management, networking, security controls, and logging.
- Ability to perform technical troubleshooting and security investigations.
- Good understanding of incident management, escalation, and SLA processes.
Preferred Qualifications
- Experience with AWS or GCP security.
- Knowledge of Defender for Identity, Defender Vulnerability Management, and Microsoft Intune.
- Experience with Microsoft Sentinel and Kusto Query Language.
- Knowledge of cloud security posture management and cloud workload protection platform concepts.
- Experience with EDR platforms such as Trellix, CrowdStrike, SentinelOne, or Palo Alto Cortex XDR.
- Knowledge of MITRE ATT&CK and threat hunting.
- Understanding of cloud security frameworks and CIS benchmarks.
Preferred Certifications
SC-200, AZ-500, AZ-104, GCIH, or CompTIA Security+.
Key Success Measures
- Timely investigation and resolution of EDR and cloud security alerts.
- Improved endpoint and cloud security health and coverage.
- SLA compliance for security incidents and technical issues.
- Reduction in recurring endpoint and cloud security incidents.
- Timely remediation of cloud security findings.
- Effective coordination with SOC, cloud, infrastructure, and endpoint teams.
- Continuous improvement of the overall EDR and cloud security posture.
More Info
Key Skills
Trellix
Palo Alto Cortex XDR
Defender for Identity
Microsoft Entra ID
XDR
Kusto Query Language
Defender Vulnerability Management
Microsoft Defender for Cloud
SentinelOne
Microsoft Defender for Endpoint
