L3 EDR SME

Chennai, Noida, Trivandrum · Onsite Full-time 7-9 years B.Tech Direct Client hiring Posted 4 months ago💰 Not disclosed
Apply now

Must Have Skills

SentinelOneEDRCrowdstrikeCybereasonSIEMThreat HuntingMITRE ATT&CKPowerShellPythonWindowsLinuxmacOSAutomationAPI IntegrationsCommunication SkillsNIL

Preferred Skills

SentinelOneEDRCrowdstrikeCybereasonSIEMThreat HuntingMITRE ATT&CKPowerShellPythonWindowsLinuxmacOSAutomationAPI IntegrationsCommunication SkillsNIL


Role: L3 EDR / SIEM Subject Matter Expert (SME)

Role Overview

We are looking for an experienced L3 EDR/ SIEM SME to manage, optimize, and support enterprise-grade EDR/XDR platforms across global client environments. This role requires strong expertise in endpoint security, incident handling, and platform engineering, along with a proactive approach to automation and performance improvement.

Key Responsibilities

  1. Administer, configure, and optimize EDR/XDR platforms (e.g., Microsoft Defender, CrowdStrike, SentinelOne, Cybereason)
  2. Act as L3 escalation point for complex incidents and perform root cause analysis
  3. Monitor, investigate, and resolve SIEM/EDR alerts, tickets, and platform issues
  4. Develop automation scripts/playbooks (PowerShell, Python, APIs) to improve efficiency
  5. Manage policies, exclusions, and platform performance tuning
  6. Collaborate with SOC teams and stakeholders for incident response and service delivery
  7. Maintain documentation, dashboards, and reporting for client environments
  8. Mentor L1/L2 analysts and ensure SLA adherence and operational excellence

Required Skills & Experience

  1. Strong hands-on experience in at least two: SentinelOne, CrowdStrike, Cybereason, Microsoft Defender
  2. Experience in SIEM/EDR platform management and Security Operations
  3. Knowledge of MITRE ATT&CK framework, threat hunting, and incident lifecycle
  4. Scripting experience: PowerShell / Python
  5. Strong understanding of Windows, Linux, macOS environments
  6. Familiarity with SIEM/SOAR integrations and data analysis
  7. Good communication and stakeholder management skills

Nice to Have

  1. Certifications in Cybersecurity / SIEM / EDR / Ethical Hacking
  2. Experience with automation, API integrations, and large-scale environments

Core Skills (Keywords)

EDR | SIEM | SentinelOne | CrowdStrike | Cybereason | Threat Hunting | MITRE ATT&CK | PowerShell | Python

Apply to this job

Required — upload a file or paste the text