15 Sep
|
HTS Consulting
|
Bengaluru
15 Sep
HTS Consulting
Bengaluru
SentinelOne Specialist
Location: Bengaluru, Karnataka
Experience: 2+ Years
Employment Type: Full-Time
Work Mode: 5 Days Work From Office
Department: Cybersecurity / Endpoint Security
Industry Focus: Endpoint Security | EDR / XDR | Managed Security
Client-Site: Willingness to commute to client locations as required
About the Role
We are looking for a SentinelOne Specialist with 2+ years of hands-on experience in endpoint security, EDR/XDR platform administration, threat detection, and incident response.
The ideal candidate will be responsible for administering and tuning SentinelOne across client environments, monitoring endpoint security operations, investigating endpoint threats, performing threat hunting, and supporting containment and remediation activities.
Key Responsibilities
SentinelOne Platform Administration
- Administer and maintain SentinelOne EDR/XDR deployments across Windows, Linux, and macOS environments.
- Configure, maintain, and tune detection policies, exclusions, response actions, and security controls.
- Monitor endpoint health, agent status, security detections, and platform operational metrics.
- Support endpoint onboarding, agent deployment, policy changes, and troubleshooting.
- Manage endpoint security configurations in accordance with client security requirements and operational policies.
- Identify and resolve SentinelOne platform and agent-related issues.
Threat Detection &
- Response
- Investigate endpoint detections, suspicious processes, malware, and anomalous behaviours.
- Perform proactive threat hunting using SentinelOne telemetry and endpoint activity.
- Conduct endpoint-based investigations to identify the root cause and scope of security incidents.
- Support containment and remediation activities, including endpoint isolation and response actions.
- Perform basic malware analysis and investigate suspicious files, processes, and behaviours.
- Correlate endpoint telemetry with SIEM data, threat intelligence, and other security sources.
- Escalate critical security incidents and provide appropriate remediation recommendations.
Integration &
- Security Operations
- Integrate SentinelOne telemetry with SIEM and other security platforms where required.
- Support log forwarding, alert correlation, and security event monitoring.
- Troubleshoot integration and telemetry-related issues.
- Support security operations teams with endpoint investigation and incident response activities.
- Maintain endpoint security dashboards, operational metrics, and security reports.
Reporting &
- Client Engagement
- Prepare endpoint investigation reports, incident summaries, and technical findings.
- Document security incidents, investigation timelines, response actions, and recommendations.
- Communicate technical findings and security risks clearly to technical and non-technical stakeholders.
- Participate in client security discussions and provide technical support related to SentinelOne operations.
Required Qualifications &
- Experience
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
- 2+ years of hands-on experience with SentinelOne, EDR/XDR, or endpoint security technologies.
- Strong practical experience in SentinelOne platform administration and endpoint threat response.
- Hands-on experience with detection policies, exclusions, response rules, agent management, and endpoint investigations.
- Valuable understanding of Windows, Linux, and macOS operating systems.
- Experience with SIEM integration, log forwarding, and event correlation.
- Good understanding of endpoint security concepts, malware behaviour, threat detection, and incident response.
- Knowledge of Python or PowerShell scripting is preferred.
- Relevant vendor or cybersecurity certifications will be an advantage.
Technical Skills
- Endpoint Security: SentinelOne EDR / XDR
- Platform Administration: Policies, exclusions, response rules, agent management, endpoint health monitoring
- Threat Detection: Endpoint detections, suspicious processes, malware, anomalous behaviour, IOC analysis
- Threat Response: Threat hunting, endpoint investigation, containment, isolation, remediation
- Operating Systems: Windows, Linux, macOS
- SIEM &
- Integration:
SIEM integration, log forwarding, event correlation, security telemetry
- Malware Analysis: Basic malware analysis and behavioural investigation
- Scripting: Python / PowerShell – preferred
- Reporting: Investigation reports, incident summaries, operational dashboards, and security metrics.
Behavioral Competencies
- Strong troubleshooting and analytical skills with an endpoint-security mindset.
- Ability to investigate security threats systematically and identify root cause and impact.
- Strong attention to detail when analysing endpoint telemetry and security detections.
- Ability to document technical findings clearly and accurately.
- Strong communication and stakeholder-management skills.
- Ability to work independently as well as collaboratively with SOC, infrastructure, network, and application security teams.
- Strong ownership and ability to manage multiple security investigations and operational priorities.
- Willingness to work from office 5 days a week.
- Willingness to commute to client locations whenever project requirements demand it.
Why Join Us?
- Opportunity to work on diverse endpoint security and managed security engagements.
- Hands-on exposure to SentinelOne EDR/XDR across enterprise client environments.
- Opportunity to work on real-world threat detection, hunting, investigation, and incident response activities.
- Exposure to SIEM, threat intelligence, and broader cybersecurity technologies.
- Opportunity to work directly with technical teams and client stakeholders.
- Scope to build deeper expertise in Endpoint Detection &
- Response and Cyber Defense
.
Interested candidates can apply with their updated resume.
📌 SentinelOne Specialist (Bengaluru)
🏢 HTS Consulting
📍 Bengaluru