Basic Purpose
We are looking for an experienced L2-L3 Security Operations
& Support Engineer with strong hands-on expertise in Endpoint Security,
EDR/XDR, and Privileged Access Management (PAM) technologies to manage advanced
administration, escalations, troubleshooting, optimization, and operational
support activities for enterprise security environments.
The engineer will work closely with SOC, Infrastructure,
Cloud, Audit, OEM TAC, and Security teams to strengthen endpoint security
posture, improve operational efficiency, and support critical incident response
activities.
The role includes advanced troubleshooting, policy
governance, threat investigation, product upgrades, integrations, and security
operations support across enterprise environments.
Endpoint Security / EDR
Hands-on experience with:
- Trend Micro Deep Security
- Trellix Endpoint Security / EDR
- SentinelOne Singularity Platform / EDR
Experience in:
- Endpoint Protection (EPP) and Endpoint Detection & Response (EDR/XDR)
- Antivirus / Anti-malware operations
- Alert monitoring, analysis, and incident triaging
- Agent deployment, upgrade, and troubleshooting
- Policy management, tuning, and configuration
- Endpoint health monitoring and compliance management
- Server and endpoint security administration
- File Integrity Monitoring (FIM)
L3 Advanced Skills:
- Threat hunting and malware investigation
- Root Cause Analysis (RCA)
- Advanced incident investigation and response handling
- Security architecture optimization
Hands-on experience with:
- ARCON PAM
Experience in:
- Privileged access lifecycle management
- Password vaulting and rotation
- Privileged session monitoring and auditing
- Access governance and workflows
- MFA integration
- Privileged account onboarding and management
- NAC exposure (preferably Aruba ClearPass)
- SIEM / SOC operational knowledge
- Cloud security exposure (AWS / Azure)
- Vulnerability management and patching concepts
- Threat intelligence and security automation
- Basic scripting (PowerShell / Python)
- ServiceNow and ITIL process knowledge
L2 Responsibilities
- Handle security alerts, incidents, and escalations from L1 teams
- Perform routine troubleshooting for agent, policy, and communication issues
- Support endpoint agent deployment, upgrades, and maintenance
- Assist in policy tuning and configuration updates
- Monitor endpoint health and compliance status
- Follow SOPs and maintain operational documentation
- Lead resolution of critical and high-severity security incidents.
- Perform advanced threat investigation and malware analysis
- Conduct Root Cause Analysis (RCA) for complex issues
- Design, optimize, and govern endpoint security and PAM policies
- Lead upgrades, migrations, onboarding, and platform enhancements
- Provide technical mentorship to L1/L2 engineers
- Drive automation, optimization, and security improvements
- Own SOPs, run books, and architecture-level documentation
- Coordinate with OEM/vendor TAC for critical escalations
- Support audit, compliance, and governance activities
- Strong analytical and troubleshooting skills
- Excellent communication and stakeholder management abilities
- Experience in enterprise production security environments
- Strong understanding of cybersecurity architecture and operations
- Ability to handle complex incidents independently (L3 expectation)
Requirements
Note: Joining Immediate or within 1 month.
Skills Required
- 3-8+ years of experience in enterprise production security environments
- Hands-on experience with Trend Micro Deep Security
- Hands-on experience with Trellix Endpoint Security or EDR
- Hands-on experience with SentinelOne Singularity Platform or EDR
- Experience with endpoint protection, EDR/XDR, antivirus, and anti-malware operations
- Experience with alert monitoring, analysis, and incident triage
- Experience with agent deployment, upgrades, and troubleshooting
- Experience with endpoint security policy management, tuning, and configuration
- Experience with endpoint health monitoring and compliance management
- Experience with server and endpoint security administration
- Experience with File Integrity Monitoring
- Threat hunting and malware investigation experience
- Advanced incident investigation and response experience
- Root Cause Analysis experience
- Hands-on experience with ARCON PAM
- Experience with privileged access lifecycle management, password vaulting, rotation, session monitoring, auditing, access governance, MFA integration, and privileged account onboarding
- Strong analytical and troubleshooting skills
- Excellent communication and stakeholder management abilities
- Ability to handle complex incidents independently at L3 level
- NAC exposure, preferably Aruba ClearPass
- SIEM and SOC operational knowledge
- Cloud security exposure with AWS or Azure
- Vulnerability management and patching knowledge
- Threat intelligence and security automation experience
- Basic scripting with PowerShell or Python
- ServiceNow and ITIL process knowledge
- Availability for 24/7 rotational or on-call support
- Immediate or within-one-month joining availability
What We Do
Techsec Digital Global Pvt. Ltd. provides technology, cybersecurity, cloud, networking, infrastructure, and digital transformation solutions. The company helps organizations safeguard critical information, maintain regulatory compliance, and ensure uninterrupted business operations through customized security tools, secure infrastructure design and management, professional services, automation, and expert consulting. It is ISO/IEC 27001:2022 certified and serves businesses navigating complex digital security and transformation needs.








