Experience - 5+ years in SOC, Endpoint Detection & Incident Response
Work Mode - Office , Rotational Shift
Interview Process - Virtual
Role Objective
The L2 End Point Security Engineer is responsible for advanced threat investigation, incident leadership, root-cause analysis, and response strategy execution. This role acts as a technical escalation point and subject-matter expert (SME) for endpoint and NAC security domains.
Key Responsibilities
Advanced AV / EDR Incident Response
(Sentinel One / Trend Micro / Trellix)
• Lead response for high-severity (P1 / P2) endpoint incidents
• Perform deep forensic and behavioral analysis
• Analyze attack chains, lateral movement, and persistence mechanisms
• Develop and validate remediation strategies
• Coordinate containment and eradication across multiple endpoints
• Drive post-incident review and preventive recommendations
Trend Micro Deep Security (Advanced Use)
• Analyze advanced IPS, malware, and integrity violations
• Lead response for server-side threats and breaches
• Evaluate detection logic effectiveness
• Define tuning, exclusions, and policy hardening recommendations
• Support audits and compliance reporting (FIM & system integrity)
File Integrity Monitoring (FIM)
• Perform root-cause analysis for critical file change incidents
• Identify compromise indicators or privilege escalation patterns
• Enhance FIM baselines and alert accuracy
• Support regulatory and audit-driven investigations
Network Access Control ClearPass Aruba
- Investigate advanced NAC incidents and repeated violations
• Lead response for compromised or rogue endpoints
• Advise on posture policies, strategies, and improvements
• Correlate NAC events with endpoint and SIEM data
SOC Leadership & Continuous Improvement
• Serve as technical escalation authority for L1 teams
• Develop and improve SOPs, runbooks, and detection playbooks
• Support SOC maturity initiatives (use-case enhancement, automation inputs)
• Lead incident war rooms and stakeholder communication (technical bridge)
• Provide expert input for RFPs, audits, and customer reviews
Skills & Expertise
Technical
• Advanced endpoint threat analysis & IR
• Robust malware/ransomware understanding
• MITRE ATT&CK; mapping
• Endpoint forensic fundamentals
• Cross-domain correlation (Endpoint + NAC + SIEM)
Tools
• Multiple EDR platforms
• SIEM threat correlation
• Threat intelligence feeds
• Incident response documentation frameworks
Certifications (Strongly Preferred)
• CEH / GCED / GCIA
• Vendor Advanced EDR certifications
• Incident Response or Digital Forensics certifications
If Interested, Please share below details with updated CV, on
[email protected]
- Total Experience -
- Relevant experience L2 -
- Relevant experience SOC -
- Relevant experience Endpoint Detection & Incident Response -
- Current Company -
- Current Designation -
- Current CTC -
- Expected CTC -
- Notice Period -
- Current Location -
- Education -
- Reason for job change -
📌 Opening ForSecurity Operations Engineer End Point Security Mumbai
🏢 AIS Technolabs
📍 Mumbai