T

Lead - Captive Operations

Tata Communications · Hyderabad / Secunderabad, Telangana, Telangana, India, Telangana

8–15 yrs experienceShift, PermanentPosted 4 days ago
Apply now →

Job description

Job Description - -------------- **Job Description L2 Endpoint Security Engineer** **Job Title** : L2 EndpointSecurity Engineer **Location**: Hyderabad **Experience**: Minimum 57 years **Qualification**: B.E/B.Tech/MCA with minimum 5 years of relevant experience OR BCA/BSc-IT with minimum 7 years of relevant experience **Certifications Required:** Must possess CEH, CHFI, GSEC, GMON, ITIL (at least one mandatory) **OEM certification** in at least one endpoint or cloud security platform (Symantec, Palo Alto Cortex XDR, Netskope) preferred **Job Summary**: We are looking for a skilled and experienced **L2 Endpoint Security SOC Engineer** to join our Security Operations Center. This role involves continuous monitoring, administration, and response activities related to endpoint protection and threat detection platforms including **Symantec Endpoint Protection** , **Palo Alto Cortex XDR** , and **Netskope**. The engineer will be responsible for investigating endpoint-related alerts, ensuring endpoint policy compliance, and supporting the overall endpoint and data security posture of the organization. **Key Responsibilities:** * Monitor and manage **Symantec, Cortex XDR, and Netskope** consoles for alerts, incidents, and compliance status. * Investigate and respond to endpoint threats such as malware, ransomware, suspicious behaviors, and data exfiltration attempts. * Perform **policy reviews, tuning, and exception handling** for endpoint security solutions. * Troubleshoot issues related to agent deployment, health, and communication with management servers. * Work on alerts escalated from L1 SOC team and ensure timely resolution or escalation to L3. * Review endpoint-related threat intelligence feeds and correlate with internal alerts for proactive defense. * Support forensic investigation activities on compromised endpoints and assist in evidence gathering. * Track and ensure timely remediation of endpoint vulnerabilities in coordination with IT teams. * Participate in **incident response**, root cause analysis, and recovery actions related to endpoint attacks. * Maintain endpoint compliance across servers, desktops, laptops, and mobile devices as per organizational security policies. * Document standard operating procedures (SOPs), investigation steps, and known issues/resolutions. * Collaborate with network and cloud security teams to investigate multi-vector threats. * Generate regular reports and dashboards on endpoint status, threat trends, and agent health metrics. * Assist in configuration backup/restore and version upgrades of endpoint security solutions. * Participate in internal audits and support external compliance requirements (ISO, PCI, etc.). * Provide feedback on tuning and feature enhancements to improve endpoint protection efficiency. Work closely with SOC teams to correlate Endpoint events with other security incidents. Perform VA/PT remediation from Endpoint configuration perspective. Demonstrate proficiency in Microsoft Excel and PowerPoint to support reporting and presentations. Maintain awareness of latest security threats and Endpoint tools feature enhancements from OEMs. **Desired Skillset:** * Hands-on experience with **Symantec Endpoint Protection** , **Palo Alto Cortex XDR** , and/or **Netskope**. * Experience in endpoint incident handling and threat response. * Good understanding of antivirus, EDR/XDR, DLP, and CASB functionality. * Strong troubleshooting and analytical skills related to endpoint protection. * Knowledge of Windows and Linux systems from a security perspective. * Good understanding of security operations, ticketing workflow, and SLA adherence. * Excellent communication and documentation skills. * Ability to work in 24x7 support environment, including night shifts and weekends.