| Job Description: |
Required Skillset: Microsoft Defender for Endpoint (MDE) Microsoft Defender for Identity (MDI) Microsoft Defender for Cloud Apps (MDCA) CrowdStrike Falcon Proofpoint Email Security Security Incident Investigation and Response Threat Hunting and Threat Intelligence Endpoint Detection & Response (EDR) SIEM/SOAR integration knowledge (Microsoft Sentinel preferred) Windows Server and Active Directory Security Email Security and Anti-Phishing Controls Security Monitoring and Alert Triage
Job Summary We are seeking an experienced and highly motivated Security Tools Team Lead to lead the administration, optimization, and continuous improvement of enterprise cybersecurity platforms. The role requires deep expertise in CrowdStrike EDR, Microsoft Defender for Endpoint (MDE), Microsoft Defender for Identity (MDI), Microsoft Defender for Cloud Apps (MDCA), and Proofpoint Email Security. The successful candidate will lead a team of security specialists, manage daily operations, drive cybersecurity initiatives, support incident response activities, and collaborate closely with SOC, Infrastructure, Cloud, and Business teams. The ideal candidate will possess strong technical expertise, leadership capabilities, stakeholder management skills, and a proactive mindset focused on enhancing the organization's security posture. ________________________________________ Key Responsibilities Administer and support Microsoft Defender Suite (MDE, MDI, MDCA). Manage CrowdStrike Falcon platform including policy tuning, threat detection, and endpoint protection. Monitor and administer Proofpoint email security solutions to protect against phishing, malware, and business email compromise attacks. Investigate security alerts and incidents, perform root cause analysis, and provide remediation recommendations. Conduct proactive threat hunting across endpoints, identities, cloud applications, and email environments. Fine-tune detection rules and security policies to reduce false positives and improve security visibility. Integrate security tools with SIEM platforms such as Microsoft Sentinel. Develop and maintain security monitoring dashboards, reports, and operational documentation. Collaborate with infrastructure, application, and SOC teams during incident response and remediation activities. Support vulnerability management and security compliance initiatives |