Assistant Manager-IT Ops (Gurugram)

Assistant Manager-IT Ops (Gurugram)

24 Sep
|
Delhivery
|
Gurugram

24 Sep

Delhivery

Gurugram

Role & responsibilities

Job Role The Assistant Manager - IT Security Operations will be responsible for the day-to-day management, implementation, monitoring, and optimization of the organization's endpoint and IT security controls. The role will have a strong technical focus on EDR/XDR, endpoint protection, vulnerability and patch management, security hardening, incident response, security tools, and implementation of cybersecurity controls across the IT setting.

The individual will work closely with IT Infrastructure, Network, Cloud, Engineering, Application, IAM, GRC, and other stakeholders to identify security gaps, implement remediation measures, respond to security incidents, and continuously improve the organization's security posture.

Experience

Experience: 69 years in IT Security / Cybersecurity / Security Operations, with strong hands-on experience in endpoint and security technologies.

Key Technical Responsibilities

1. EDR / XDR Operations & Management

- Own the day-to-day administration, monitoring, and operational management of EDR/XDR platforms across enterprise endpoints and servers.
- Manage EDR/XDR deployment, agent health, policy configuration, exclusions, prevention controls, detection rules, and security profiles.
- Monitor endpoint security posture and ensure adequate EDR/XDR coverage across Windows, macOS, Linux, and other supported platforms.
- Investigate and respond to endpoint alerts, suspicious activities, malware detections, behavioral detections, and security incidents.
- Perform detailed analysis of endpoint telemetry including processes, command lines, network connections, file activities, registry changes, persistence mechanisms, and user activity.
- Develop and maintain EDR/XDR detection and prevention policies based on emerging threats and organizational requirements.
- Tune EDR/XDR policies and detection rules to minimize false positives while maintaining appropriate security coverage.
- Coordinate with vendors for complex incidents, product issues, detection gaps, and technical escalations.
- Track EDR/XDR agent health, outdated agents, inactive devices, policy mismatches, and deployment failures.
- Prepare operational dashboards and reports covering EDR coverage, detections, incidents, agent health, and remediation status.
- Evaluate and implement advanced EDR/XDR capabilities such as behavioral protection, application control, exploit prevention, ransomware protection, attack surface reduction, and threat hunting.

2. Endpoint Security

- Implement and maintain endpoint security controls across corporate devices and servers.
- Define and enforce endpoint security baselines and hardening standards.
- Manage Antivirus/NGAV, EDR/XDR, host firewall, device control, application control, encryption, and endpoint protection policies.
- Identify gaps in endpoint security configurations and drive remediation with relevant IT teams.
- Support secure device provisioning, endpoint onboarding, security configuration, and decommissioning.
- Investigate endpoint-related security events and perform root-cause analysis.

3. Vulnerability & Patch Management

- Own and coordinate the organization's vulnerability and patch management lifecycle.
- Identify vulnerabilities across endpoints, servers, applications, and infrastructure using vulnerability management tools.
- Analyze vulnerabilities based on severity, exploitability, business impact, asset criticality, and exposure.
- Define patching priorities and remediation timelines based on organizational risk.
- Coordinate with IT Infrastructure, Desktop Engineering, Server, Application, and Cloud teams for timely remediation.
- Track critical, high, and medium vulnerabilities through closure.
- Manage patch deployment activities, patch compliance, exceptions, and remediation validation.
- Develop dashboards and management reports covering patch compliance, vulnerability aging, critical vulnerabilities,



and remediation status.
- Investigate failed patches and coordinate corrective actions.
- Establish patch compliance targets and continuously improve endpoint/server patching processes.
- Support emergency patching activities for actively exploited or zero-day vulnerabilities.

4. Security Incident Response

- Participate in and lead technical response to cybersecurity incidents involving endpoints, servers, applications, and infrastructure.
- Perform initial triage, investigation, containment, eradication, and recovery activities.
- Analyze EDR/XDR telemetry to identify attack vectors, affected assets, indicators of compromise, lateral movement, and persistence.
- Coordinate endpoint isolation, malicious file remediation, account containment, process termination, and other response actions as required.
- Perform root-cause analysis and document incident timelines.
- Develop and maintain technical incident response playbooks.
- Support threat hunting activities based on IOCs, TTPs, vulnerabilities, and emerging threats.
- Coordinate with SOC/MDR teams and security vendors during major incidents.

5. Security Tool Implementation & Administration

- Lead the technical implementation, configuration, and operationalization of cybersecurity products.
- Manage security tools across endpoint, network, vulnerability management, DLP, encryption, application control, and security monitoring domains.
- Evaluate security products based on technical requirements, security capabilities, scalability, integration, and operational effectiveness.
- Conduct Proof of Concept (PoC), testing, technical validation, and deployment planning for new security technologies.
- Integrate security tools with existing infrastructure, SIEM, IAM, ticketing systems, and other security platforms.
- Maintain product configurations, policies, integrations, certificates, agents, and operational documentation.
- Identify opportunities for automation and process improvement across security operations.

6. Security Hardening & Technical Controls

- Define and implement endpoint and server security hardening standards.
- Review security configurations against industry best practices and organizational security requirements.
- Implement controls such as application control, attack surface reduction, endpoint firewall, device control, encryption, and privileged access restrictions.
- Identify misconfigurations and security weaknesses and coordinate remediation.
- Conduct periodic security posture reviews across endpoints and infrastructure.
- Support implementation of security controls aligned with ISO 27001, CIS benchmarks, NIST, and organizational security standards.

7. Google Workspace & Cloud Security Support

- Support implementation and monitoring of security controls within Google Workspace and cloud environments.
- Review endpoint access, device posture, application access, data protection, and security policies.
- Work with IAM and IT teams to implement appropriate access and endpoint security controls.
- Support investigations involving compromised accounts, suspicious authentication activity, and unauthorized access.

8. Security Operations & Monitoring

- Monitor security dashboards and operational metrics to identify security gaps and potential incidents.
- Track security alerts, incidents, vulnerabilities, patch compliance, endpoint coverage, and remediation activities.
- Establish operational KPIs/KRIs for endpoint and security operations.




- Identify recurring security issues and implement permanent corrective actions.
- Maintain operational documentation, SOPs, runbooks, and troubleshooting guides.

9. Security Projects & Technical Implementation

- Drive cybersecurity projects from requirement gathering through implementation and operational handover.
- Prepare technical requirements, implementation plans, test cases, rollout strategies, and rollback plans.
- Coordinate with internal teams and vendors for enterprise-wide security deployments.
- Manage pilot deployments and phased rollouts to minimize business disruption.
- Ensure security solutions are properly integrated into existing IT infrastructure.
- Track project milestones, risks, dependencies, and technical issues.

10. Audit, Compliance & Risk Support

- Provide technical support for ISO 27001, SOC 2, ITGC, internal audits, and other security assessments.
- Provide evidence related to EDR/XDR coverage, patch compliance, vulnerability remediation, endpoint security, and security configurations.
- Support remediation of audit findings and security control gaps.
- Ensure security tools and operational processes meet defined policies and compliance requirements.
- Assist in third-party security assessments and technical evaluations where required.

Key Deliverables / KPIs The role will be measured on technical security operations and implementation effectiveness, including:

- EDR/XDR endpoint and server coverage
- EDR/XDR agent health and deployment compliance
- Critical/high security incident response and containment
- Endpoint security policy compliance
- Vulnerability remediation percentage
- Critical and high vulnerability aging
- Patch compliance percentage
- Emergency/zero-day patch deployment
- Antivirus/NGAV/EDR detection and prevention effectiveness
- Security incident MTTR
- False-positive reduction through EDR/XDR tuning
- Security tool availability and operational health
- Endpoint hardening compliance
- Security project implementation timelines
- Closure of security audit findings
- Security control effectiveness and continuous improvement

Qualifications & Skills

Mandatory

- 6–9 years of experience in IT Security, Cybersecurity, SOC, Endpoint Security, or Security Operations.
- Strong hands-on experience with EDR/XDR platforms.
- Experience in endpoint security administration and enterprise-scale security deployments.
- Strong understanding of Windows operating systems, Active Directory, networking, and endpoint architecture.
- Hands-on experience with vulnerability and patch management.
- Experience with security incident investigation and response.
- Experience in security product implementation, configuration, troubleshooting, and policy management.
- Strong understanding of malware, ransomware, endpoint attacks, persistence techniques, and common MITRE ATT&CK; techniques.
- Experience working with enterprise security tools and security vendors.
- Ability to troubleshoot technical security issues and perform root-cause analysis.
- Strong documentation, communication, and stakeholder-management skills.

Preferred

- Experience with CrowdStrike, SentinelOne, Microsoft Defender for Endpoint or equivalent EDR/XDR platforms.
- Experience with vulnerability management platforms such as Tenable, Qualys, Rapid7, or equivalent.
- Experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or equivalent.
- Knowledge of DLP, encryption, application control, device control, and endpoint hardening.
- Knowledge of PowerShell and security automation.
- Understanding of MITRE ATT&CK;, NIST, CIS Controls, and ISO 27001.
- Experience with cloud and SaaS security, particularly Google Workspace.
- Experience supporting ISO 27001, SOC 2, ITGC, or other security audits.
- Relevant certifications such as Security+, CEH, CySA+, CISSP, CISM, or vendor-specific security certifications would be an advantage.

Preferred candidate profile

📌 Assistant Manager-IT Ops (Gurugram)
🏢 Delhivery
📍 Gurugram

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: assistant manager-it ops (gurugram) / gurugram

Subscribe to this job alert:

Get the latest job offers by email for: assistant manager-it ops (gurugram) / gurugram