Padmi

EDR Testing Specialist

HyderabadPosted 1 month ago
CybersecuritySeniorFull Time, Permanent

Source description

About the role

View original

Job Title: EDR Testing Specialist Department: Information Security Team Location: India/UAE Reports To: Head of Security Assurance Role Summary: We are seeking a skilled and detail-oriented EDR Testing Specialist to conduct and manage threat simulation exercises using predefined test cases based on the MITRE ATTCK framework. The specialist will be responsible for validating the detection and response capabilities of our Endpoint Detection and Response (EDR) solutions across a range of attack tactics, techniques, and procedures (TTPs). Key Responsibilities: Execute technical test cases mapped to MITRE ATTCK techniques including but not limited to: Execution : PowerShell, CMD scripts, VBA macros, WMI, Scheduled Tasks Defense Evasion : Obfuscation, event log clearing, masquerading Credential Access : Mimikatz, LSASS dumps, brute-force attacks Command and Control : HTTP/HTTPS C2, tunneling, protocol evasion Lateral Movement : SMB, RDP, WMI, DCOM, SSH Persistence, Discovery, Collection, Exfiltration, and Impact techniques Work closely with SOC and Threat Hunting teams to validate detections and tune EDR alerts. Document test results, detection coverage, gaps, and recommended remediations. Update and maintain test case repositories and test scripts (e.g., PowerShell, Python, BAT, etc.). Assist in red/purple team exercises and post-incident simulation testing. Qualifications Skills: 7+ years in cybersecurity operations, threat detection, or red/purple teaming. Hands-on experience with EDR tools (e.g., Microsoft Defender for Endpoint, Cyber reason, Fortinet, SentinelOne). Familiarity with the MITRE ATTCK framework and cyber kill chain methodology. Scripting skills in PowerShell, Python, or Bash for testing automation. Experience with virtual lab environments for safe threat simulation. Strong analytical and documentation skills. Preferred Certifications: GIAC Cyber Threat Intelligence (GCTI), GIAC Red Teaming (GRT), or equivalent Offensive Security Certified Professional (OSCP) or Purple Team certifications MITRE ATTCK Defender (MAD) certifications Work Environment: Hybrid or remote options available depending on team structure. Requires occasional after-hours testing or support. Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

One address, no account. We’ll tell you when matching roles go live.

More at Technohandz Global Information Technology Consultants L.l.c

Related open roles

View all roles