Skip to content

Security Engineer - Endpoint Security

eSec Forte TechnologiesThane, MH, IndiaJuly 25, 2026
On-site
Full-time
Endpoint Security
Entry · 1–3 yrs
### About the Role As a Security Engineer specializing in Endpoint Security, you will be instrumental in safeguarding client environments by deploying, configuring, and maintaining advanced EDR and XDR solutions. This role requires a hands-on approach to developing and enforcing robust endpoint security policies, conducting in-depth troubleshooting of complex security issues, and proactively hunting for emergent threats. You will contribute directly to enhancing our clients' defensive posture and incident response capabilities against sophisticated cyber threats. ### Key Responsibilities * Lead the implementation, configuration, and ongoing management of advanced EDR and XDR platforms, specifically CrowdStrike Falcon and Palo Alto Networks Cortex XDR, ensuring optimal performance and coverage across diverse client infrastructures. * Design, develop, and enforce comprehensive endpoint security policies, including host firewall rules, application control, device control, and exploit prevention, tailored to client-specific risk profiles and compliance requirements. * Perform deep-dive analysis and resolution of complex endpoint security incidents, including advanced persistent threats (APTs), ransomware, and zero-day exploits, utilizing forensic techniques and EDR telemetry. * Proactively conduct threat hunting operations leveraging EDR/XDR data to identify stealthy attacker techniques, lateral movement, and anomalous behaviors that evade standard detections, contributing to intelligence-driven defense. * Provide expert technical guidance and support to clients on endpoint security best practices, platform capabilities, and incident remediation strategies, fostering strong client relationships. * Develop and maintain automation scripts (e.g., using PowerShell) for routine security tasks, policy enforcement, and data collection to improve operational efficiency and response times. * Collaborate with broader security operations teams to integrate endpoint security data with SIEM platforms (e.g., Splunk, Microsoft Sentinel) and SOAR playbooks for enhanced correlation and automated response actions. * Continuously monitor the threat landscape for new vulnerabilities and attack techniques relevant to endpoint security, applying proactive measures and recommending strategic improvements to client defenses. ### Requirements * 1-3 years of dedicated experience in an endpoint security engineering, operations, or administration role, with a focus on enterprise-level environments. * B.Tech/M.Tech or BCA/MCA in Computer Science, Information Technology, Cybersecurity, or a closely related technical discipline. * Demonstrated expertise in endpoint security principles, including malware analysis, host intrusion prevention, data loss prevention (DLP), and application whitelisting. * Extensive hands-on experience with the implementation, configuration, and day-to-day operational management of leading EDR and XDR platforms. * Proven proficiency in managing and operating CrowdStrike Falcon and Palo Alto Networks Cortex XDR, including policy creation, alert triage, and advanced query capabilities. * Solid understanding of Windows, Linux, and macOS operating systems, their security models, and common attack surfaces. * Familiarity with network security fundamentals, common attack vectors, and the stages of the cyber kill chain and MITRE ATT&CK framework. * Ability to analyze security logs, network traffic, and system events to detect, investigate, and respond to security incidents. ### Nice-to-Have * Experience with Windows Automation and scripting (e.g., PowerShell, Python) for security tasks and system hardening. * Demonstrated ability to perform advanced threat hunting and develop custom detection rules within EDR/XDR platforms. * Familiarity with other EDR/XDR solutions such as SentinelOne, Microsoft Defender for Endpoint, or Trend Micro Apex One. * Relevant industry certifications such as CompTIA CySA+, GIAC GSEC, or vendor-specific certifications for CrowdStrike or Palo Alto Networks. ### Benefits * Health insurance for the employee and dependents * Professional security-certification reimbursement (e.g., CySA+, GCIH, CrowdStrike Certified Administrator/Analyst) * Annual learning and skill-development allowance * Sponsored conference / training attendance * Flexible work arrangements ### Skills Endpoint Security, EDR, XDR, Windows Automation, Threat Hunting ### Qualification B.Tech/M.Tech or BCA/MCA

Job Details

Experience

Entry · 1–3 yrs

Tools & Tech

CrowdStrike
Linux
macOS
Microsoft Defender
Microsoft Sentinel
Palo Alto
PowerShell
Python
SentinelOne
Splunk
Windows

Preferred Certs

CySA+
GCIH
GSEC