Posted on: 06/04/2026
Role : L3 EDR / SIEM Subject Matter Expert (SME)
Role Overview :
We are looking for an experienced L3 EDR/ SIEM SME to manage, optimize, and support enterprise-grade EDR/XDR platforms across global client environments. This role requires strong expertise in endpoint security, incident handling, and platform engineering, along with a proactive approach to automation and performance improvement.
Key Responsibilities :
- Administer, configure, and optimize EDR/XDR platforms (e.g., Microsoft Defender, CrowdStrike, SentinelOne, Cybereason)
- Act as L3 escalation point for complex incidents and perform root cause analysis
- Monitor, investigate, and resolve SIEM/EDR alerts, tickets, and platform issues
- Develop automation scripts/playbooks (PowerShell, Python, APIs) to improve efficiency
- Manage policies, exclusions, and platform performance tuning
- Collaborate with SOC teams and stakeholders for incident response and service delivery
- Maintain documentation, dashboards, and reporting for client environments
- Mentor L1/L2 analysts and ensure SLA adherence and operational excellence
Required Skills & Experience :
- Strong hands-on experience in at least two : SentinelOne, CrowdStrike, Cybereason, Microsoft Defender
- Experience in SIEM/EDR platform management and Security Operations
- Knowledge of MITRE ATT&CK framework, threat hunting, and incident lifecycle
- Scripting experience : PowerShell / Python
- Strong understanding of Windows, Linux, macOS environments
- Familiarity with SIEM/SOAR integrations and data analysis
- Good communication and stakeholder management skills
Nice to Have :
- Certifications in Cybersecurity / SIEM / EDR / Ethical Hacking
- Experience with automation, API integrations, and large-scale environments
Core Skills (Keywords) :
- EDR | SIEM | SentinelOne | CrowdStrike | Cybereason | Threat Hunting | MITRE ATT&CK | PowerShell | Python
Required Skills :
- SentinelOne
- EDR
- Crowdstrike
- Cybereason
- SIEM
- Threat Hunting
- MITRE ATT&CK
- PowerShell
- Python
- Windows
- Linux
- macOS
- Automation
- API Integrations
- Communication Skills
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1626128