Padmi

Flex XSIAM / EDR / Automation Engineer

Delhi NCRPosted 1 month ago
CybersecuritySeniorFull Time; Regular
Apply at Lumen Technologies

Opens the source posting on shine.com

Source description

About the role

View original

Summary The Flex XSIAM / EDR / Automation Engineer is responsible for supporting multiple security engineering functions across Cortex XSIAM, endpoint detection and response platforms, and SOC automation workflows. This role provides flexible engineering support for customer onboarding, platform operations, EDR tuning, telemetry validation, detection support, and automation development. The role has a specific focus on CrowdStrike Falcon while also supporting XSIAM and broader AMDR automation needs. Key Responsibilities Administer and support CrowdStrike Falcon environments, including sensor health, policy review, alert tuning, and operational support.Support EDR onboarding, endpoint telemetry validation, prevention policy review, and detection visibility.Assist with Cortex XSIAM data source onboarding, parsing validation, dashboard creation, and alert tuning.Support integrations between CrowdStrike, XSIAM, Sentinel, ServiceNow, and other security platforms.Develop and maintain automation workflows for enrichment, alert routing, reporting, and incident support.Assist SOC analysts with complex endpoint investigations, alert validation, and escalation support.Validate data quality, telemetry coverage, and integration health across EDR and SIEM/XDR platforms.Support customer onboarding, proof-of-value activities, technical validation, and platform readiness.Maintain documentation, operational procedures, data dictionaries, and handoff materials.Collaborate with SOC, SIEM, EDR, automation, IT, and customer teams to support evolving AMDR platform needs. Required Qualifications 7-12 years of hands-on experience in security operations, EDR administration, SIEM engineering, or automation.Experience with CrowdStrike Falcon or another EDR platform such as Microsoft Defender, SentinelOne, Carbon Black, or Cortex XDR.Familiarity with Cortex XSIAM, Microsoft Sentinel, Splunk, QRadar, or similar SIEM/XDR platforms.Basic scripting skills using Python, PowerShell, Bash, or similar.Familiarity with REST APIs, JSON, log formats, endpoint telemetry, and detection workflows.Strong troubleshooting, investigation, documentation, and cross-functional communication skills. Preferred Certifications CrowdStrike Falcon AdministratorCrowdStrike Falcon ResponderMicrosoft SC-200 Security Operations AnalystPalo Alto Cortex XSIAM or Cortex XDR certificationCompTIA Security+ We are an equal opportunity employer committed to fair and ethical hiring practices. We do not charge any fees or accept any payment from candidates at any stage of the recruitment process. SIEM, Infosec .

One address, no account. We’ll tell you when matching roles go live.

More at Lumen Technologies

Related open roles

View all roles