MEDR Threat Engineer US work hours

Posted 9 Days Ago
Be an Early Applicant
Hiring Remotely in India
Remote
Mid level
Cloud • Security • Cybersecurity
The Role
Serve as the EDR SME to improve endpoint visibility, detection, and prevention across Windows, macOS, and Linux. Build and enhance SOAR workflows/playbooks, define roadmaps for Carbon Black, CrowdStrike, and SentinelOne, collaborate with SOC and SIEM teams, maintain endpoint security tools, assist customers with threats, and escalate incidents via ITSM.
Summary Generated by Built In

Proficio is an award-winning managed detection and response (MDR) services provider. We provide 24/7 security monitoring, investigation, alerting and response services to organizations in healthcare, financial services, manufacturing, retail and other industries. Take a video tour of our global network of 24/7 Security Operations Centers (SOCs).

Proficio has been highlighted in Gartner’s Market Guide for Managed Detection and Response Services for the last five consecutive years. MSSP Alert ranks Proficio among the top 250 global Managed Security Services Providers (MSSPs).

We have a track record of innovation. Proficio invented the concept of SOC-as-a-Service. We were the first MSSP to provide automated response services and are the only company in our space with a patent for cyber risk scoring and security posture gap analysis.

Our typical client is a medium to large-sized organization that lacks the in-house resources to address the challenges of a rapidly changing threat landscape. The difficulty of hiring and retaining cybersecurity professionals are widely understood. Our prospective clients are also challenged to effectively harness technology and build hardened processes that reduce the risk of security breaches.

While Proficio has developed a unified service delivery platform designed to meet the needs of the most demanding clients, what sets us apart is the quality and passion of our people. We believe the SOC of the Future will meld the creativity of human intelligence with the power of advanced technologies like AI.

Proficio’s commitment to developing and promoting our team members is unparalleled in our industry. Most of our senior managers were promoted from within.

Summary:

The Managed Infrastructure Services team is seeking an experienced MEDR Threat Engineer who is technical, collaborative, and truly excited about working on endpoint products. In this role, you will bring your in-depth knowledge of the endpoint and detection response tasks to help guide the evolution of Proficio's Managed EDR visibility, detection, and prevention technologies. You will work closely with engineering, project managers, Hosted & managed SIEM team, sales, and other departments. You will bring existing knowledge about product EDR best practices and apply them in delivering significant new features and enhancements. The successful candidate will have the ability to interface and influence cross-functional teams throughout the company


Requirements

Responsibilities

  • Act as a subject matter expert for enterprise EDR/XDR technologies and endpoint security solutions across Windows, macOS, and Linux.
  • Design, configure, and maintain EDR/XDR security policies, including prevention controls, detection policies, exclusions, application controls, and other endpoint security configurations.
  • Manage EDR deployments, agent/sensor upgrades, endpoint health, policy assignments, and troubleshooting across customer environments.
  • Create and maintain custom detections, behavioral rules, IOCs, blocklists, and other detection use cases based on emerging threats and customer requirements.
  • Perform threat hunting and advanced investigation of security events involving malware, ransomware, phishing, PowerShell, scripts, lateral movement, persistence, privilege escalation, credential attacks, and other MITRE ATT&CK techniques.
  • Design and maintain integrations between EDR/XDR platforms and SIEM, SOAR, ticketing, identity, email security, threat intelligence, and other security platforms.
  • Work closely with SOC and MDR teams to improve detection coverage, alert quality, investigation processes, and incident response capabilities.
  • Work with customers to understand security requirements, identify use cases, and translate those requirements into EDR/XDR policies, detections, automations, and security controls.
  • Analyze email security events, including phishing attempts, malicious URLs, attachments, suspicious senders, and related endpoint activity.
  • Maintain and administer endpoint security technologies including EDR, antivirus, DLP, web filtering, and email security solutions.
  • Escalate security incidents, detections, and alerts to customers through ITSM and ticketing platforms and provide appropriate investigation details and recommendations.
  • Prepare technical documentation, security assessments, operational reports, and customer-facing security reports.
  • Collaborate with internal security, infrastructure, and engineering teams to troubleshoot complex endpoint security and integration issues.
      

Requirements

  • 3+ years of hands-on experience with enterprise EDR solutions, including deployment, configuration, administration, troubleshooting, and ongoing management.
  • Hands-on experience with at least two enterprise MDR platforms such as CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Carbon Black, Cortex XDR, Cisco XDR, or Trend Micro.
  • Experience with at least one XDR and an understanding of how security telemetry from different sources can be correlated.
  • Strong experience with EDR/XDR policy configuration, deployment, tuning, exclusions, prevention controls, and endpoint management.
  • Experience developing or tuning custom detections, detection rules, indicators, blocklists, and automated response actions.
  • Experience integrating security platforms using APIs, connectors, or other integration methods, including integrations with SIEM, SOAR, ITSM, identity, email security, and threat intelligence platforms.
  • Experience troubleshooting endpoint agents, deployment issues, policy conflicts, connectivity problems, and security tool configuration issues.
  • Knowledge of Windows, macOS, and Linux operating systems and their security configurations and management tools.
  • Knowledge of network security concepts, including network topology, protocols, components, and common security controls.
  • Experience working in a SOC, MDR, MSSP, or customer-facing security environment is highly desirable.
  • Ability to analyze security events and correlate endpoint, network, identity, email, and other security telemetry.

 Additional Qualifications

  • Experience with security automation platforms and workflows such as CrowdStrike Fusion, SentinelOne automation, Cisco XDR workflows, Cortex XDR automation, Microsoft Defender automation, or similar technologies.
  • Experience with threat intelligence platforms such as VirusTotal, AlienVault OTX, AbuseIPDB, Cisco Talos, or similar tools.
  • Experience with scripting and automation using PowerShell, Python, or similar languages.
  • Experience with Microsoft security technologies including Microsoft Entra ID, Intune, Microsoft Defender, and related security services.
  • Experience creating security dashboards, detection coverage metrics, customer assessments, QBRs, or monthly security reports.
  • Knowledge of vulnerability management, compliance, security frameworks, and security operations processes.

Benefits
  • Opportunity to work in a progressive organization with structured training and roadmap for success
  • Meals, Gym, Internet and other reimbursement programs
  • Experience in one of the hottest IT industries today

Proficio is an EOE employer.

Proficio collects certain personal information upon your submission of an application for an open position. More information is available about your consumer rights and our privacy policy at www.proficio.com/privacypolicy

Skills Required

  • 4+ years of experience with IT in a professional work environment
  • 3+ years deployment, configuration, or maintenance to support Enterprise EDR Solutions (including CrowdStrike Falcon, Microsoft Defender, and/or SentinelOne)
  • 3+ years of experience in EDR and/or AV
  • 1+ years of experience performing systems administration (troubleshooting, installation, monitoring, security upgrades)
  • Knowledge of network security architecture concepts (topology, protocols, components, principles)
  • Knowledge of various Enterprise OS configurations and management tools for EDR deployment and management
  • Experience in malware and attack analysis, research, investigation, and response
  • Experience with Cisco Secure Endpoint and Sophos
  • Experience working in a SOC environment (Incident Response, Threat Hunting, Vulnerability Scanning, Log Management)
  • Experience with SIEM, Threat Intelligence Platforms, or Network Monitoring Tools
  • Ability to integrate and analyze cybersecurity data using tools such as Splunk and Elastic
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Carlsbad, CA
190 Employees
Year Founded: 2010

What We Do

Proficio is a world-class Managed Security Service Provider (MSSP) providing managed detection and response solutions, 24×7 security monitoring and advanced data breach prevention services to organizations globally. Our rapid growth is being fueled by the rise in cloud-based services, the acceptance of the Software-as-a-Service (SaaS) model, and the increasing number of cyber security attacks on businesses, hospitals and government. We have developed proprietary security content and threat intelligence tools to identify and proactively defend against advanced attacks and insider threats. Proficio’s founders are veterans of the security and networking industry who have helped guide multiple companies to successful exits. Proficio’s customers benefit from the most advanced security monitoring and 24×7 managed security services that until recently were outside the budget of all but the very largest enterprises. Proficio’s ProSOC service offerings include the following: • 24×7 security event monitoring, alerting, and remediation • Advanced SIEM correlation analysis • Protection against complex attacks and insider threats • Actionable intelligence that enables internal IT teams to effectively and quickly resolve issues • Threat Intelligence • Active Defense that blocks targeted attacks in real time 24×7 • Worry-free compliance audits for: PCI, HIPAA, SOX, GLBA, FFIEC, NERC CIP, and FISMA regulations • Visibility to event logs with easy-to-use web portal, powerful reporting, dashboards, and drill-down analytics • Full management of security devices including patching, health and performance monitoring, and tuning • Free 12 month log retention • Out-of-the-box support for 400+ log sources • Scalable cloud-based deployment – fast implementation and no software or hardware purchases • Advanced scanning eliminating vulnerabilities before they can be exploited

Similar Jobs

Coursera + Udemy  Logo Coursera + Udemy

Senior Software Engineer

Artificial Intelligence • Consumer Web • Edtech • Enterprise Web • HR Tech • Social Impact • Generative AI
Remote or Hybrid
India
1500 Employees

GitLab Logo GitLab

Senior Program Manager

Cloud • Security • Software • Cybersecurity • Automation
Easy Apply
In-Office or Remote
Bangalore, Bengaluru Urban, Karnataka, IND
2500 Employees

Pfizer Logo Pfizer

Assistant Manager - Maintenance

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Remote
Goa, IND
121990 Employees

Dynatrace Logo Dynatrace

Sr Talent Acquisition Advisor

Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Big Data Analytics • Automation
Remote or Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
5600 Employees

Similar Companies Hiring

Credal.ai Thumbnail
Software • Security • Productivity • Machine Learning • Artificial Intelligence
Brooklyn, NY
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account