Role Overview : The Endpoint Security Specialist is responsible for delivering comprehensive endpoint protection across all managed devices by deploying, administering, and optimizing an enterprise‑grade Endpoint Detection and Response (EDR) solution. The role ensures real‑time threat detection, response, quarantine, and remediation, supporting the organization's security posture and operational resilience.
Key Responsibilities
1. EDR Platform Management
Deploy, configure, and manage an enterprise‑grade EDR solution such as CrowdStrike or SentinelOne to ensure complete endpoint coverage.
Monitor EDR detections, alerts, and sensor health across all endpoints.
Tune EDR policies to enhance detection accuracy and reduce false positives. Manage real-time threat detection, automated quarantine, containment, and remediation workflows.
2. Endpoint Protection & Hardening
Implement and maintain endpoint security policies including malware protection, exploit prevention, behavioral monitoring, and device control. Enforce secure baselines for all endpoints—including servers, workstations, and remote devices. Collaborate with infrastructure teams to ensure secure configuration of OS, applications, and endpoint services.
3. Threat Detection & Incident Response
Lead or support investigations of endpoint-related security incidents.
Utilize EDR telemetry for root-cause analysis and threat hunting activities. Coordinate rapid containment actions (isolation, kill process, block hash, etc.) during active threats. Provide detailed reports and recommendations post-incident.
4. Compliance & Reporting
Ensure endpoint security controls align with internal policies, regulatory requirements, and audit standards. Generate dashboards and reports for endpoint coverage, risk posture, and EDR performance. Maintain documentation for endpoint security procedures, configurations, and incident-handling steps.
5. Collaboration & Continuous Improvement
Work closely with SOC, IT Infrastructure, Cloud, and Compliance teams to improve detection and response effectiveness. Identify gaps in endpoint defenses and recommend continuous improvements. Support automation initiatives for endpoint onboarding, patching integration, and policy deployment.
Required Skills & Qualifications
Technical Skills
- Hands-on experience with CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, or similar EDR platforms.
- Strong understanding of malware behavior, detection methodologies, and endpoint security architecture.
- Ability to analyze EDR telemetry, perform threat hunting, and execute response actions.
- Knowledge of OS internals (Windows / Linux / macOS), endpoint hardening, and secure configuration standards.