EDR & Cloud Security Support Specialist
- Location : Cyberjaya
- Salary : Max RM11,000
- Employment Type: Full-time Employment
- Open for : Local/PR
Job Summary
We are seeking an experienced EDR & Cloud Security Support Specialist to provide monitoring, administration, troubleshooting, investigation, and operational support for EDR/XDR and cloud security platforms. The role will ensure endpoint and cloud security threats are detected, investigated, escalated, and remediated within defined SLAs.
Key Responsibilities
- Monitor and investigate EDR/XDR security alerts and incidents.
- Perform endpoint investigations covering processes, command lines, files, hashes, network connections, and user activity.
- Investigate malware, ransomware, PowerShell, persistence, lateral movement, and credential-related activities.
- Perform endpoint isolation, remediation, and other approved response actions.
- Monitor endpoint health, sensor/agent status, and protection coverage.
- Troubleshoot EDR agent deployment, connectivity, policy, and telemetry issues.
- Support EDR policy configuration, exclusions, and alert tuning.
- Coordinate with SOC, Infrastructure, and Endpoint teams for incident remediation.
- Track unresolved EDR issues and ensure timely closure within SLA.
- Monitor and investigate security alerts across Azure/AWS/GCP environments.
- Support Microsoft Defender for Cloud and cloud security monitoring.
- Investigate suspicious cloud authentication, privilege escalation, resource changes, and anomalous activity.
- Monitor cloud security posture, recommendations, and security alerts.
- Support Entra ID identity and authentication investigations.
- Support remediation of cloud security findings and assist with cloud security incident response and RCA.
- Support cloud security logging and SIEM integration.
Requirements
- 3–5+ years of experience in EDR, endpoint security, cloud security, or SOC operations.
- Hands-on experience with Microsoft Defender for Endpoint / Defender XDR or equivalent EDR/XDR.
- Good understanding of endpoint telemetry and security investigation.
- Experience investigating malware, ransomware, PowerShell, suspicious processes, and endpoint compromise.
- Good understanding of Azure security and Entra ID.
- Working knowledge of Microsoft Defender for Cloud.
- Understanding of cloud IAM, networking, security controls, and logging.
- Strong technical troubleshooting and investigation skills.
- Good understanding of incident management, escalation, and SLA processes.
Preferred
- Experience with AWS/GCP security.
- Knowledge of Defender for Identity, Defender Vulnerability Management, and Intune.
- Experience with Microsoft Sentinel and KQL.
- Knowledge of CSPM/CWPP concepts.
- Experience with Trellix, CrowdStrike, SentinelOne, or Palo Alto Cortex XDR.
- Knowledge of MITRE ATT&CK and Threat Hunting.
- Understanding of cloud security frameworks and CIS Benchmarks.
Pay: RM8,000.00 - RM11,000.00 per month
Experience:
- Endpoint Detection and Response (EDR): 3 years (Preferred)
- Microsoft Defender: 3 years (Preferred)
Work Location: In person