03 Sep
|
Indecomm global services
|
Bengaluru
03 Sep
Indecomm global services
Bengaluru
Bangalore
Job Brief
We are seeking a highly motivated and detail-oriented Senior Security Administrator to join our Cybersecurity team. The candidate will be responsible for the end-to-end administration, monitoring, and optimization of the organization’s endpoint security, vulnerability management, patch management, and web security infrastructure. This role will oversee the day-to-day operations, configuration, tuning, and lifecycle management of Antivirus, EDR/XDR, vulnerability assessment, patch management, and Secure Web Gateway/SASE platforms. The successful candidate will play a critical role in ensuring that endpoints, servers, and internet-facing traffic remain secure, compliant, and protected against evolving cyber threats.
Roles & Responsibilities
- Administer, configure, and maintain Endpoint Detection and Response (EDR), Extended Detection and Response (XDR), and Antivirus platforms, including CrowdStrike Falcon and Trend Micro Apex One/Vision One, across desktops, servers, and cloud workloads.
- Monitor EDR/XDR and Antivirus consoles for malware detections, policy violations, and suspicious endpoint activities.
- Investigate, contain, and remediate security incidents involving compromised or infected endpoints.
- Manage agent deployment, health monitoring, tamper protection, policy enforcement, exclusions, and platform tuning to reduce false positives while maintaining optimal protection.
- Own and manage the complete vulnerability management lifecycle using Qualys VMDR, including asset discovery, authenticated scanning, risk assessment, vulnerability prioritization, exception handling, and remediation tracking.
- Analyze vulnerabilities using CVSS, TruRisk, and other risk-based methodologies to prioritize remediation efforts.
- Coordinate with infrastructure and system administration teams to plan, schedule, and monitor operating system and third-party application patch deployments.
- Track patch compliance and ensure timely closure of critical and high-severity vulnerabilities within defined SLAs.
- Administer and maintain Secure Web Gateway and SASE platforms such as Forcepoint Web Security and Fortinet FortiSASE.
- Configure and manage URL filtering, web content controls, SSL inspection policies, internet access governance, and application access policies.
- Implement and maintain Zero Trust Secure Access (ZTSA/ZTNA) policies to enforce identity-based, least-privilege access for remote and hybrid users.
- Investigate web security incidents, including malicious URL access, command-and-control (C2) communications, and policy circumvention attempts, and coordinate remediation activities.
- Generate dashboards, executive reports, and operational metrics related to endpoint security health, vulnerability posture, patch compliance, and web security.
- Perform regular platform health checks, upgrades, configuration reviews, and license management activities.
- Support internal and external audits, regulatory assessments, and compliance reviews related to endpoint, vulnerability, and web security controls.
- Develop, maintain, and continuously improve security SOPs, operational runbooks, and incident response playbooks.
- Coordinate with vendors and OEM support teams for issue resolution, product upgrades, and escalations.
- Participate in on-call and rotational shift support to ensure continuous 24×7 security operations coverage.
Requirements
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- 3-6 years of hands-on experience in endpoint security, vulnerability management, patch management, and web security administration.
Technical Skills
Endpoint Security
- CrowdStrike Falcon
- Trend Micro Apex One, Vision One, and Deep Security
Vulnerability & Patch Management
- Qualys VMDR, TruRisk, and CyberSecurity Asset Management (CSAM)
- WSUS or equivalent patch management solutions
Web Security & SASE
- Forcepoint Web Security
- Fortinet FortiSASE
- Zero Trust Secure Access (ZTSA/ZTNA)
Infrastructure & Security Knowledge
- Strong understanding of Windows and Linux/Unix security administration
- Working knowledge of networking concepts and protocols
- Familiarity with cloud security controls in Azure and AWS environments
- Knowledge of malware analysis fundamentals, Indicators of Compromise (IOCs), and endpoint forensics
- Solid understanding of CVEs, CVSS scoring, vulnerability prioritization, and risk-based remediation strategies
Soft Skills
- Strong analytical and problem-solving abilities.
- Excellent troubleshooting and incident resolution skills.
- Effective verbal and written communication skills.
- Ability to collaborate across technical and business teams.
- Strong organizational skills with the ability to manage multiple priorities.
- High level of ownership, accountability, and attention to detail.
- Flexibility to work in rotational shifts supporting a 24×7 operational environment.
Preferred Certifications
At least one of the following certifications is mandatory:
- CrowdStrike Certified Falcon Administrator (CCFA)
- Trend Micro Certified Professional
- Qualys Certified Specialist (VM/VMDR)
- CompTIA Security+
- EC-Council Certified Incident Handler (ECIH)
- EC-Council Certified SOC Analyst (CSA)
📌 Senior Security Administrator (Bengaluru)
🏢 Indecomm global services
📍 Bengaluru