Job Summary
The Track Lead for Support & Operations will play a pivotal role in managing operational processes with a focus on continuous improvement, problem-solving, and meeting client SLAs. This position requires strong leadership to empower teams and ensure effective execution of support functions, driving enhancements that align with organizational goals.
As an L3 Security Engineer, you will be responsible for ensuring the smooth operation of EDR solutions by monitoring platform health, enforcing security policies, and troubleshooting endpoint issues across multiple EDR platforms including CrowdStrike, Palo Alto XDR, Microsoft Defender for Endpoint, and SentinelOne. Your role includes onboarding devices, validating security rules, handling basic policy enforcement issues, and ensuring that all endpoints remain compliant with security baselines. You will assist in resolving connectivity issues, missing telemetry cases, and agent health checks while escalating complex platform-related problems to L3.
Key Responsibilities
1. Optimize Symantec Endpoint Protection Systems By Analyzing Operational Data And Implementing Enhancements To Improve Management Reporting And Streamline Information Flow.
2. Collaborate With Clients To Understand Their Requirements And Ensure The Support Team Consistently Meets Or Exceeds Client Expectations Through Effective Problem Resolution.
3. Lead And Mentor The Project Team, Fostering Transparent Communication Of Project Goals And Facilitating A Culture Of Accountability And High Performance Within Symantec Edr Frameworks.
4. Drive Innovation By Proposing And Implementing New Ideas For Process Development, Utilizing Symantec Tools To Enhance Overall Organizational Efficiency And Effectiveness.
5. Develop Tailored Solutions Based On Customer Needs Using Symantec Endpoint Protection, Ensuring Alignment With The Operational Environment To Achieve Desired Business Outcomes.
Ensure endpoints are successfully onboarded to EDR solutions across all platforms (Windows, macOS, Linux, iOS, Android).Monitor endpoint connectivity and health status within the EDR portals.Validate that security rules, EDR, and antivirus policies are applied correctly.Assist in troubleshooting policy conflicts and enforcement issues.Investigate and validate EDR alerts, classify threats, and escalate incidents if required.Apply basic remediation steps like isolating devices, initiating scans, or triggering automated investigations.Identify endpoints not reporting telemetry or experiencing EDR agent failures.Perform basic troubleshooting (e.g., restarting services, re-onboarding devices, checking connectivity).Escalate complex security incidents and persistent issues to L3.Assist in preparing incident summaries and compliance reports for management.Ensure endpoints are running the latest security patches and EDR updates.Validate compliance with security baselines and recommend corrective actions.Collaborate with global SOC, Threat Hunting, and Incident Response teams for critical security incidents.
Skill Requirements
1. Strong Understanding Of Symantec Endpoint Protection And Edr Technologies.
2. Proficiency In Operational Management And Continuous Improvement Methodologies.
3. Excellent Problem-Solving And Analytical Skills.
4. Strong Leadership And Team Management Capabilities.
5. Effective Communication And Interpersonal Skills.
Hands-on expertise in CrowdStrike, Palo Alto XDR, Microsoft Defender for Endpoint, and SentinelOne.Ability to analyze malware behaviors, execute incident containment strategies, and escalate threats appropriately.Scripting knowledge in PowerShell or Python (preferred).Strong analytical, documentation, and communication skills.
Other Requirements
1. Certification In Symantec Endpoint Protection Is Optional But Valuable
CrowdStrike Certified Falcon Administrator (CCFA)Palo Alto Networks Certified Cybersecurity Associate (PCCSA)Microsoft Certified: Security Operations Analyst Associate (SC-200)SentinelOne Certified Administrator