Padmi

Senior SME - EndPoint (EDR)

BangalorePosted 1 month ago
CybersecurityUnspecified
Apply at Microland

Opens the source posting on careers.microland.com

Source description

About the role

View original

Skills Required:- Microsoft Sentinel Implementation – Incident management, KQL queries, detection rule tuning, automation (Logic Apps/Playbooks). Core Responsibilities Operate and monitor the Microsoft XDR stack : Perform incident triage, threat hunting, and root cause analysis using KQL and advanced hunting queries. Conduct containment & remediation : account disable, token revocation, IP/domain blocking, endpoint isolation. Build and enhance automation playbooks, detections, and dashboards . Provide incident reports, RCA, and hardening recommendations aligned with MITRE ATT&CK. Technical Requirements Deep hands-on expertise in Microsoft Sentinel & Defender suite. KQL proficiency for hunting and incident correlation. Knowledge of Azure AD/Entra security , Conditional Access, Identity Protection. Familiarity with threat intel, SOAR automation, MITRE ATT&CK mapping . Language & Communication Excellent English communication (verbal & written) is mandatory for client interaction, escalation handling, and executive reporting. Microsoft Sentinel – incident management, KQL queries, detection rule tuning, automation (Logic Apps/Playbooks). Defender for Endpoint – advanced hunting, device isolation, forensic collection. Defender for Identity – AD monitoring, lateral movement, credential theft detection. Defender for Office 365 – phishing/email attack analysis, safe attachments/links. Defender for Cloud Apps (MCAS) – SaaS discovery, shadow IT, DLP. Skills Required:- Microsoft Sentinel Implementation – Incident management, KQL queries, detection rule tuning, automation (Logic Apps/Playbooks). Core Responsibilities Operate and monitor the Microsoft XDR stack : Perform incident triage, threat hunting, and root cause analysis using KQL and advanced hunting queries. Conduct containment & remediation : account disable, token revocation, IP/domain blocking, endpoint isolation. Build and enhance automation playbooks, detections, and dashboards . Provide incident reports, RCA, and hardening recommendations aligned with MITRE ATT&CK. Technical Requirements Deep hands-on expertise in Microsoft Sentinel & Defender suite. KQL proficiency for hunting and incident correlation. Knowledge of Azure AD/Entra security , Conditional Access, Identity Protection. Familiarity with threat intel, SOAR automation, MITRE ATT&CK mapping . Language & Communication Excellent English communication (verbal & written) is mandatory for client interaction, escalation handling, and executive reporting. Microsoft Sentinel – incident management, KQL queries, detection rule tuning, automation (Logic Apps/Playbooks). Defender for Endpoint – advanced hunting, device isolation, forensic collection. Defender for Identity – AD monitoring, lateral movement, credential theft detection. Defender for Office 365 – phishing/email attack analysis, safe attachments/links. Defender for Cloud Apps (MCAS) – SaaS discovery, shadow IT, DLP. IND-KA-Bengaluru-Ecospace1B-ML 17-Apr-2026 Skills Required:- Microsoft Sentinel Implementation – Incident management, KQL queries, detection rule tuning, automation (Logic Apps/Playbooks). Core Responsibilities Operate and monitor the Microsoft XDR stack: Perform incident triage, threat hunting, and root cause analysis using KQL and advanced... ... Skills Required:- Microsoft Sentinel Implementation – Incident management, KQL queries, detection rule tuning, automation (Logic Apps/Playbooks). Core... Primary -> Technology | Network Security Fundamentals | Level 3 Support | 3 - Experienced,Primary -> Technology | Secured Configuration Management | Level 3 Support | 3 - Experienced,Secondary -> Technology | Endpoint Encryption | Level 2 Support | 2 - Knowledgeable,Secondary -> Technology | Incident and Breach Response | Level 2 Support | 2 - Knowledgeable,Tertiary -> Technology | Scripting and Automation | Level 2 Support | 2 - Knowledgeable

One address, no account. We’ll tell you when matching roles go live.

More at Microland

Related open roles

View all roles