EDR & Cloud Security Support
Experience: 3–5+ years
Role Summary
Responsible for monitoring, administration, troubleshooting, investigation, and operational support of EDR/XDR and cloud security platforms. The role ensures endpoint and cloud threats are detected, investigated, escalated, and remediated within defined service-level agreements.
Key Responsibilities
- Monitor and investigate EDR/XDR alerts and incidents.
- Perform endpoint investigations covering processes, command lines, files, hashes, network connections, and user activity.
- Investigate malware, ransomware, suspicious PowerShell activity, persistence, lateral movement, and credential-related activity.
- Perform endpoint isolation, remediation, and other approved response actions.
- Review endpoint health, sensor or agent status, and protection status.
- Troubleshoot EDR agent deployment, connectivity, policy, and telemetry issues.
- Support EDR policy configuration, exclusions, and alert tuning.
- Coordinate with SOC, infrastructure, and endpoint teams to complete remediation.
- Track unresolved EDR issues and ensure closure within agreed SLAs.
- Monitor and investigate security alerts across Azure, AWS, and GCP, as applicable.
- Support Microsoft Defender for Cloud and broader cloud security monitoring.
- Investigate suspicious cloud authentication, privilege escalation, resource changes, and anomalous activity.
- Monitor cloud security posture, recommendations, security alerts, identities, network activity, resources, and security configurations.
- Support investigations involving Microsoft Entra ID identity and authentication events.
- Coordinate remediation of cloud security findings with cloud and platform teams.
- Assist with cloud security incident response and root-cause analysis.
- Support cloud security logging and integration with SIEM platforms.
Required Qualifications and Experience
- 3–5+ years of experience in EDR, endpoint security, cloud security, or SOC operations.
- Hands-on experience with Microsoft Defender for Endpoint, Defender XDR, or an equivalent EDR/XDR platform.
- Good understanding of endpoint telemetry and investigation techniques.
- Experience investigating malware, ransomware, suspicious PowerShell activity, suspicious processes, and endpoint compromise.
- Good understanding of Azure security and Microsoft Entra ID.
- Working knowledge of Microsoft Defender for Cloud.
- Good understanding of cloud identity and access management, networking, security controls, and logging.
- Ability to perform technical troubleshooting and security investigations.
- Good understanding of incident management, escalation, and SLA processes.
Preferred Qualifications
- Experience with AWS or GCP security.
- Knowledge of Defender for Identity, Defender Vulnerability Management, and Microsoft Intune.
- Experience with Microsoft Sentinel and Kusto Query Language.
- Knowledge of cloud security posture management and cloud workload protection platform concepts.
- Experience with EDR platforms such as Trellix, CrowdStrike, SentinelOne, or Palo Alto Cortex XDR.
- Knowledge of MITRE ATT&CK and threat hunting.
- Understanding of cloud security frameworks and CIS benchmarks.
Preferred Certifications
SC-200, AZ-500, AZ-104, GCIH, or CompTIA Security+.
Key Success Measures
- Timely investigation and resolution of EDR and cloud security alerts.
- Improved endpoint and cloud security health and coverage.
- SLA compliance for security incidents and technical issues.
- Reduction in recurring endpoint and cloud security incidents.
- Timely remediation of cloud security findings.
- Effective coordination with SOC, cloud, infrastructure, and endpoint teams.
- Continuous improvement of the overall EDR and cloud security posture.