Role description
Senior Endpoint Security Engineer (SentinelOne EDR & CyberArk PAM) Job Summary
We are seeking an experienced Senior Endpoint Security Engineer with 8-10+ years of experience in Information/Cyber Security to support enterprise-scale security operations within a SOC/MSS workplace. The role focuses on endpoint protection, privileged access management, email security, incident response, threat hunting, and security platform optimization. The successful candidate will collaborate with SOC, Infrastructure, Identity, Cloud, and Application Security teams to strengthen the organization's security posture and operational effectiveness.
Key Responsibilities
- Provide L2+ operational support for enterprise endpoint security platforms with a focus on SentinelOne EDR, Palo Alto Cortex XDR, and CyberArk PAM.
- Administer, manage, and optimize SentinelOne EDR deployments, agent lifecycle management, policy tuning, exclusions, threat hunting, rollout activities, and forensic investigations.
- Support Palo Alto Cortex XDR operations including incident investigation, behavioral analytics, malware detection, IOC management, and response actions.
- Investigate and respond to malware, ransomware, phishing attempts, insider threats, and suspicious endpoint activities.
- Perform root cause analysis and coordinate containment, eradication, and recovery activities for security incidents.
- Administer CyberArk PAM components including PVWA, CPM, and PSM, account onboarding, password vaulting, password rotation, privileged session management, and troubleshooting.
- Manage and support Microsoft Defender for Office 365 and Exchange Online Protection for anti-phishing, anti-spam, and email security operations.
- Conduct proactive threat hunting using endpoint telemetry, IOC searches, and security analytics.
- Support endpoint hardening initiatives including BitLocker, device control, application control, and vulnerability remediation.
- Manage operating system security across Windows and Linux environments, ensuring adherence to security standards and hardening practices.
- Coordinate maintenance activities, upgrades, emergency changes, and disaster recovery testing.
- Collaborate with SOC teams to improve detection capabilities, reduce false positives, and enhance incident response effectiveness.
- Develop and maintain SOPs, knowledge base articles, operational runbooks, and RCA documentation.
- Participate in security assessments, compliance activities, and vulnerability remediation programs.
- Mentor junior engineers and provide technical guidance on endpoint security technologies and operational best practices.
Required Skills
Proficient
- SentinelOne EDR
- Palo Alto Cortex XDR
- Windows Server (2012–2025)
- Windows 10/11 Administration & Troubleshooting
- Linux (RHEL, CentOS, Ubuntu)
- Active Directory
- Entra ID/Azure AD
- Group Policy
- DNS
- DHCP
- PowerShell
- CyberArk PAM (PVWA, CPM, PSM)
- Microsoft Defender for Office 365
- Exchange Online Protection
- Incident Response
- Endpoint Security Operations
- Threat Hunting
- Endpoint Hardening
Intermediate
- BitLocker
- USB/Device Control
- Application Control
- Vulnerability Remediation
- SPF
- DKIM
- DMARC
- Malware Analysis
- Forensic Investigation
- SIEM Integration (Chronicle, Splunk, Microsoft Sentinel OR QRadar)
- XQL Basics
- Python Automation
Basic
- Windows Event Logs
- Sysmon
- Registry
- Services
- Scheduled Tasks
- TCP/IP
- HTTP/HTTPS
- SMTP
- LDAP
- Kerberos
- Zero Trust
- MFA
- Conditional Access
Knowledge
- MITRE ATT&CK;
- Cyber Kill Chain
- IOC
- IOA
- Malware Lifecycle
- Compliance Audits
- Security Assessments
- Disaster Recovery (DR) Testing
- Operational Runbook Documentation
- Root Cause Analysis (RCA) Documentation
Experience
- 8-10+ years of experience in Information Security / Cyber Security.
- Experience supporting Enterprise SOC, MSS, or 24x7 Security Operations environments.
- Proven experience working with EDR, PAM, endpoint protection, incident response, and enterprise security technologies.
Skills Windows Server, Linux, Active Directory, DNS
About UST
UST is a global digital transformation solutions provider. For more than 20 years, UST has worked side by side with the world’s best companies to make a real impact through transformation. Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation.
With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients’ organizations. With over 30,000 employees in 30 countries, UST builds for boundless impact—touching billions of lives in the process.
📌 Senior Endpoint Security Engineer (SentinelOne EDR & CyberArk PAM) (Mumbai)
🏢 UST
📍 Mumbai