Role Description Senior Endpoint Security Engineer (SentinelOne EDR & CyberArk PAM) Job Summary We are seeking an experienced Senior Endpoint Security Engineer with 8-10+ years of experience in Information/Cyber Security to support enterprise-scale security operations within a SOC/MSS workplace. The role focuses on endpoint protection, privileged access management, email security, incident response, threat hunting, and security platform optimization. The successful candidate will collaborate with SOC, Infrastructure, Identity, Cloud, and Application Security teams to strengthen the organization's security posture and operational effectiveness.
Key Responsibilities Provide L2+ operational support for enterprise endpoint security platforms with a focus on SentinelOne EDR, Palo Alto Cortex XDR, and CyberArk PAM.
Administer, manage, and optimize SentinelOne EDR deployments, agent lifecycle management, policy tuning, exclusions, threat hunting, rollout activities, and forensic investigations.
Support Palo Alto Cortex XDR operations including incident investigation, behavioral analytics, malware detection, IOC management, and response actions.
Investigate and respond to malware, ransomware, phishing attempts, insider threats, and suspicious endpoint activities.
Perform root cause analysis and coordinate containment, eradication, and recovery activities for security incidents.
Administer CyberArk PAM components including PVWA, CPM, and PSM, account onboarding, password vaulting, password rotation, privileged session management, and troubleshooting.
Manage and support Microsoft Defender for Office 365 and Exchange Online Protection for anti-phishing, anti-spam, and email security operations.
Conduct proactive threat hunting using endpoint telemetry, IOC searches, and security analytics.
Support endpoint hardening initiatives including BitLocker, device control, application control, and vulnerability remediation.
Manage operating system security across Windows and Linux environments, ensuring adherence to security standards and hardening practices.
Coordinate maintenance activities, upgrades, emergency changes, and disaster recovery testing.
Collaborate with SOC teams to improve detection capabilities, reduce false positives, and enhance incident response effectiveness.
Develop and maintain SOPs, knowledge base articles, operational runbooks, and RCA documentation.
Participate in security assessments, compliance activities, and vulnerability remediation programs.
Mentor junior engineers and provide technical guidance on endpoint security technologies and operational best practices.
Required Skills Proficient SentinelOne EDR
Palo Alto Cortex XDR
Windows Server (2012–2025)
Windows 10/11 Administration & Troubleshooting
Linux (RHEL, CentOS, Ubuntu)
Active Directory
Entra ID/Azure AD
Group Policy
DNS
DHCP
PowerShell
CyberArk PAM (PVWA, CPM, PSM)
Microsoft Defender for Office 365
Exchange Online Protection
Incident Response
Endpoint Security Operations
Threat Hunting
Endpoint Hardening Intermediate BitLocker
USB/Device Control
Application Control
Vulnerability Remediation
SPF
DKIM
DMARC
Malware Analysis
Forensic Investigation
SIEM Integration (Chronicle, Splunk, Microsoft Sentinel OR QRadar)
XQL Basics
Python Automation Basic Windows Event Logs
Sysmon
Registry
Services
Scheduled Tasks
TCP/IP
HTTP/HTTPS
SMTP
LDAP
Kerberos
Zero Trust
MFA
Conditional Access Knowledge MITRE ATT&CK;
Cyber Kill Chain
IOC
IOA
Malware Lifecycle
Compliance Audits
Security Assessments
Disaster Recovery (DR) Testing
Operational Runbook Documentation
Root Cause Analysis (RCA) Documentation Experience 8-10+ years of experience in Information Security / Cyber Security.
Experience supporting Enterprise SOC, MSS, or 24x7 Security Operations environments.
Proven experience working with EDR, PAM, endpoint protection, incident response, and enterprise security technologies.
Skills Windows Server, Linux, Active Directory, DNS
📌 Senior Endpoint Security Engineer (SentinelOne EDR & CyberArk PAM) (Mumbai)
🏢 UST
📍 Mumbai