Technical :
- Advanced knowledge of EDR / XDR platforms, including Microsoft Defender for Endpoint, Trellix HX, SEP, and other leading endpoint security platforms.
- Strong understanding on Windows Event Logging, PowerShell, and endpoint telemetry.
- Scripting experience with PowerShell or Python for automation and data enrichment.
- Advanced knowledge of Microsoft Sentinel, the Azure security stack (Microsoft Defender, Azure Security Center, Azure AD), and integration with cloud and on-premises environments.
- Experience with log optimization tools for log routing, transformation, and enrichment.
- Proficiency with Kusto Query Language (KQL) for advanced threat-hunting, log analysis, and analytic rule creation.
- Strong understanding of security incident response processes, including root cause analysis and remediation techniques.
- Experience managing vendors and / or contractors on projects and problem resolution.
Experience :
Overall experience we are looking for 14+ YearsA minimum of 5 years of experience in security engineering roles, with a focus on threat detection, endpoint security, or SIEM solutions, and the proven ability to operate cross functionally to execute business wide initiatives is preferredPreferred 3-5 years of experience in general cybersecurity roles, with a focus on threat detection, EDR / XDR, and SIEM solutions.Hands-on experience managing Microsoft Defender for Endpoint, Trellix HX, and Symantec Endpoint Security (or equivalent).Experience with EDR tuning, behavioral detections, IOC management, and response workflows.Familiarity with EDR / XDR API integrations.Experience integrating EDR / XDR platforms with Microsoft Sentinel or similar SIEMs.Working knowledge of MITRE ATT&CK, NIST CSF, CMMC, and ISO frameworks.Non-technical or soft skills :
Excellent verbal and written communications skills, project management and the ability to articulate complex security issues to both technical and non-technical stakeholders.High motivation, with dynamic and customer-centric skills and the ability to thrive in a challenging and changing high-pressure environment.Strong leadership, effective meeting management, group facilitation and mentoring skills with a proven ability to work across teams.Strong documentation discipline and the ability to translate technical findings into actionable recommendations.Able to work autonomously while maintaining a high level of accuracy and attention to detail.Highly analytical mindset with a proactive approach to problem-solving and continuous improvement.Ability to manage multiple tasks and prioritize effectively in a fast-paced, dynamic environment.Proven ability to mentor and guide junior engineers and analysts.Proficient understanding and applicability of :NIST Cybersecurity frameworkFDA cybersecurity guidanceMITRE ATT&CK frameworkLockheed Martin Cyber Kill ChainSkills Required
Powershell, Azure Ad, Sep