jobs in Atos

全职 EDR - Cloud Security Support (End point detection and response) 工作, 薪水, Atos Selangor 公司招聘中 - Ricebowl

EDR - Cloud Security Support (End point detection and response)

分享
保存

工作地点

  • Cyberjaya Selangor Malaysia

职位描述

岗位职责

EDR & Cloud Security Support


Experience: 3–5+ years


Role Summary

Responsible for monitoring, administration, troubleshooting, investigation, and operational support of EDR/XDR and cloud security platforms. The role ensures endpoint and cloud threats are detected, investigated, escalated, and remediated within defined service-level agreements.


Key Responsibilities

  • Monitor and investigate EDR/XDR alerts and incidents.
  • Perform endpoint investigations covering processes, command lines, files, hashes, network connections, and user activity.
  • Investigate malware, ransomware, suspicious PowerShell activity, persistence, lateral movement, and credential-related activity.
  • Perform endpoint isolation, remediation, and other approved response actions.
  • Review endpoint health, sensor or agent status, and protection status.
  • Troubleshoot EDR agent deployment, connectivity, policy, and telemetry issues.
  • Support EDR policy configuration, exclusions, and alert tuning.
  • Coordinate with SOC, infrastructure, and endpoint teams to complete remediation.
  • Track unresolved EDR issues and ensure closure within agreed SLAs.
  • Monitor and investigate security alerts across Azure, AWS, and GCP, as applicable.
  • Support Microsoft Defender for Cloud and broader cloud security monitoring.
  • Investigate suspicious cloud authentication, privilege escalation, resource changes, and anomalous activity.
  • Monitor cloud security posture, recommendations, security alerts, identities, network activity, resources, and security configurations.
  • Support investigations involving Microsoft Entra ID identity and authentication events.
  • Coordinate remediation of cloud security findings with cloud and platform teams.
  • Assist with cloud security incident response and root-cause analysis.
  • Support cloud security logging and integration with SIEM platforms.


Required Qualifications and Experience

  • 3–5+ years of experience in EDR, endpoint security, cloud security, or SOC operations.
  • Hands-on experience with Microsoft Defender for Endpoint, Defender XDR, or an equivalent EDR/XDR platform.
  • Good understanding of endpoint telemetry and investigation techniques.
  • Experience investigating malware, ransomware, suspicious PowerShell activity, suspicious processes, and endpoint compromise.
  • Good understanding of Azure security and Microsoft Entra ID.
  • Working knowledge of Microsoft Defender for Cloud.
  • Good understanding of cloud identity and access management, networking, security controls, and logging.
  • Ability to perform technical troubleshooting and security investigations.
  • Good understanding of incident management, escalation, and SLA processes.


Preferred Qualifications

  • Experience with AWS or GCP security.
  • Knowledge of Defender for Identity, Defender Vulnerability Management, and Microsoft Intune.
  • Experience with Microsoft Sentinel and Kusto Query Language.
  • Knowledge of cloud security posture management and cloud workload protection platform concepts.
  • Experience with EDR platforms such as Trellix, CrowdStrike, SentinelOne, or Palo Alto Cortex XDR.
  • Knowledge of MITRE ATT&CK and threat hunting.
  • Understanding of cloud security frameworks and CIS benchmarks.


Preferred Certifications

SC-200, AZ-500, AZ-104, GCIH, or CompTIA Security+.


Key Success Measures

  • Timely investigation and resolution of EDR and cloud security alerts.
  • Improved endpoint and cloud security health and coverage.
  • SLA compliance for security incidents and technical issues.
  • Reduction in recurring endpoint and cloud security incidents.
  • Timely remediation of cloud security findings.
  • Effective coordination with SOC, cloud, infrastructure, and endpoint teams.
  • Continuous improvement of the overall EDR and cloud security posture.


重要安全守则

申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。

了解更多