Listing Description
The successful candidate will have a team-oriented, client-facing mindset with proven experience conducting EDR infrastructure deployments. You will help clients identify high impact threat scenarios and execute proof of concepts for prevention, detection, and response using customized endpoint security architectures. You’ll use your deep insights to identify, recommend and execute resolution for malware and other EDR-detected incidents while helping to develop and execute methodologies for EDR deployment, feature enablement and technical integration in a SOC.
Must Haves
- 2+ years EDR administration (CrowdStrike Falcon, VMware Carbon Black, Palo Alto Network Cortex XDR, Microsoft Windows Defender, Cylance, Tanium etc.)
- 2+ years of working with EDR tools performing requirements gathering, deployment, configuration, and conducting threat hunting
- 2+ years working with operational information security disciplines (e.g. incident response, security infrastructure management, or monitoring services)
- Proven success contributing to a team-oriented environment
- Proven ability to work with clients in a problem-solving environment
- Cybersecurity experience in complex global enterprises and Fortune 500 companies
Nice to Haves
- 1+ years security tool engineering and administration (e.g. NGAV, EPP, EDR, SIEM, SOAR, UEBA, Deception, Attack Surface Management, etc.)
- Some of the following EDR experience- Agent deployment, health check and coverage sustainability
- Threat Hunting
- Systems integration
- Comparing vendor functionality
- Mapping EDR capabilities to threat scenarios
- Deploying EDR in a multi-agent (i.e. AV, NG AV) environments
- Deep understanding and proven experience in Cybersecurity Operations (Monitoring, Detection, Incident Response, Forensics)
- Project and delivery management experience
- RFP/RFI Response knowledge (ability to work and support proposal efforts)
Listing Details
- Citizenship: Us Citizen
- Incentives: Both
- Education: Bachelors Degree
- Travel: No Travel
- Telework: Full Telecommute