Responsibilities
- Operate and maintain Endpoint Detection and Response (EDR) systems, handling alert evaluation, threat isolation, and continuous monitoring of endpoint integrity across all organizational devices.
- Enforce standardized endpoint security configurations, compliance audits, and system hardening requirements throughout the infrastructure.
- Oversee anti-malware solutions, including policy setup, update coordination, and response to malware-related alerts.
- Configure and administer firewall and Web Application Firewall (WAF) settings, network segmentation policies, and secure remote access mechanisms.
- Collaborate with the Service Desk and Workspace teams to uphold consistent security baselines in endpoint environments.
- Manage email security measures such as spam filtering, phishing protection, DMARC/DKIM/SPF configurations, and file attachment scanning.
- Implement and supervise web filtering systems, proxy policies, and defenses against malicious URLs and content.
- Administer multi-factor authentication (MFA) and single sign-on (SSO) platforms across the organization.
- Oversee Privileged Access Management (PAM/PIM) systems, including platform administration and monitoring of privileged sessions.
- Lead joiner, mover, and leaver (JML) processes across all platforms, ensuring prompt and accurate provisioning and deprovisioning of access.
- Conduct regular access reviews and recertification campaigns to enforce least-privilege principles across systems.
- Support authentication governance and access controls for customer-facing systems.
- Manage Data Loss Prevention (DLP) systems, including rule configuration, alert analysis, and response to potential data exfiltration incidents.
- Oversee data handling policies such as classification, retention, archiving, and secure disposal within M365 and other systems.
- Assist in monitoring for insider threats and managing escalation protocols when suspicious behavior is detected.
- Maintain encryption standards and manage the lifecycle of digital certificates, including renewal and revocation.
- Evaluate and analyze security alerts from various tools, working with the SOC to ensure rapid detection and response.
- Lead proactive threat hunting initiatives using XDR data and threat intelligence to detect adversarial behaviors.
- Maintain and optimize the XDR platform, including rule development, system integrations, and telemetry accuracy.
- Investigate security incidents, unusual activity, and escalated alerts from the SOC, delivering clear findings and remediation guidance.
- Create and update incident response runbooks for critical threat scenarios and operational procedures.
- Lead ransomware preparedness efforts and resilience testing, including validation of backup systems and maintenance of response playbooks.
- Develop and manage security automation workflows and SOAR playbooks to enhance detection speed and response effectiveness.
- Serve as the operational liaison to the SOC, supporting service level agreement adherence and technical escalations.
- Generate accurate and timely reports on endpoint health, network security controls, DLP alert trends, IAM system status, and incident response metrics