Paramount Computer Systems
Website:
paramountassure.com
Job details:
An L2 Engineer for Endpoint Protection and EDR (Endpoint Detection and Response) manages advanced security incidents, configures high-level security tools, and resolves complex endpoint threats.
Core Responsibilities (Primary Skill: Endpoint Protection & EDR)
- Incident Response: Investigate high-severity alerts and lead containment actions for advanced security breaches.
- Platform Administration: Manage, tune, and maintain enterprise EDR and endpoint protection agents (such as TrendMicro DSM, Symantec EPP, CrowdStrike EDR)
- Policy Management: Design, test, and deploy strict security policies, exclusion rules, enhancing the security posture and hardening guidelines across global endpoints.
- Threat Hunting: Proactively search environment telemetry for hidden adversary behaviours and indicators of compromise (IoCs).
- Malware Analysis: Inspects suspicious files, memory dumps, or scripts to understand attacker methods and build defenses.
- Root Cause Analysis: Perform deep-dive forensic analysis on compromised hosts and write comprehensive post-incident reports.
- Vendor Escalation: Partner with tier-4 vendor support to resolve software bugs, driver conflicts, or complex platform issues.
Policy & Safe Management
- Design safes: Establish safe structures, retention periods, and permissions.
- Tune policies: Optimize Master Policy rules and platform settings.
- Manage Endpoints: Onboard enforce EPP & EDR policies to meet compliance posture
- Enhance Security Posture : Ensure on Security Policy enforcement and effectiveness
Secondary Responsibilities (Secondary Skill: Vulnerability Management)
- Vulnerability Scanning: Schedule and oversee network and host-based vulnerability assessments using tools like Tenable, Qualys, or Rapid7.
- Risk Prioritization: Analyze vulnerability scan reports to prioritize remediation based on active threats and business impact.
- Remediation Tracking: Collaborate with IT and system administration teams to ensure timely patching of critical vulnerabilities.
- Compliance Reporting: Generate security posture metrics and compliance dashboards for leadership teams.
Required Qualifications
- Experience: 5+ years in IT security operations, with at least 3 years focused specifically on EDR and endpoint security.
- Certifications: Industry credentials like CISSP, CEH, GCIH, or vendor-specific EDR certifications.
- Technical Knowledge: Deep understanding of Windows, Linux, and macOS operating systems, Active Directory, and cloud environments.
Click on Apply to know more.