l3 edr sme

1 week ago


Chennai, Tamil Nadu, India UST Full time ₹ 12,00,000 - ₹ 36,00,000 per year

7 - 9 Years

1 Opening

Chennai, Noida, Trivandrum

Role description

Role Proficiency:

Provide support to a specific SIEM or EDR technology for global customers; to ensure and maintain the platform is functioning as expected. Independently monitor and proactively take ownership for resolution of issues and work matters.

Outcomes:

  • Monitor investigate and provide meaningful resolution of tickets and issues across multiple customers for the specified SIEM or EDR type. Escalate issues observed accordingly to a team member if appropriate to ensure optimal performance of the supported platform

  • Assist with service requests for platform types such as access requests as well as more targeted requests for specific modules on platform such as dashboard creation and query support. Investigate larger issues to ensure optimal service for internal and external stakeholders.

  • Provide assistance with maintenance activities to help with improving understanding of architecture of supported platforms; as well as self-study to building proficiency for supported toolsets

  • Proactively develop and maintain documentation and knowledge articles for the broader team related to customer support

  • Generate relevant reporting as required for platforms supported on a regular basis; ensuing internal and external reporting requirements are met.

  • Ensure in-life requests are being actioned in a timely manner for self as well as junior roles to ensure effective maintenance and management of the customer platform.

  • With minimal supervision provide support where required to other platform engineers by taking ownership of issues and ensuring requests are rectified focusing on the impact to the customer

  • Provide supervision and guidance to junior members of the team.

Measures of Outcomes:

  • Percent of Adherence to processes and methodologiesa.Percent of adherence to SLAs for in-life ticketing processesb.Percent of adherence to workflows and completeness of audit trails for activities undertaken.

  • Productivity score maintaineda.Number of issues identified early in the event of issues with delivering tasks or workload.b.Number of issues with effective evidence provided for escalations during triage.

  • Number of opportunities to enhance change documentation to ensure processes remain relevant for the broader team.

  • Number: of relevant skill related training and development activities undertaken; evidenced by certification.

  • Number of opportunities to and improve helping to reduce false positives

Outputs Expected:

Technical Expertise:

  • Demonstrate comprehension and experience in the specific SIEM or EDR platform that Engineer is working on.

  • Comfortable with and awareness of the customers being supported; capable of providing support towards high level customer QBR (Quarterly Business Review) preparation.

  • Use technology to identify with the ability to implement technical solutions to issues with queries/rules/dashboards/data feeds

  • Provide input to customer requirements or issues i.e.

    Ability to have understanding to translate a customer requirement into a technical solution of how that could be achieved in the respective platform.

  • Provide support to Junior members.

Platform Management – Incidents and Requests:

  • Provide accurate updates to appropriate Service and Change Requests; ensuring audit trails are preserved and SLAs are achieved.

  • Take the lead to identify issues with the specified platform type or its supporting infrastructure.

  • Proactive identification of issues

    with behavioural analysis/patterns identified

    with suggestions for resolutions.

  • Provide support to Junior members.

Stakeholder Focus:

  • Ensure relevant reporting metrics of customer information provided in a timely manner; and engaging customer/TAM/Project team where required.

  • Ensure customer specific processes are being followed.

  • Undertake mandatory and proactive learning and development opportunities.

Skill Examples:

  • Good communication skills

  • Skill in being prepared to undertake background check/validation to ensure integrity.

  • Ability to work unsupervised with the assigned SIEM or EDR technologies and their supporting infrastructure

  • Ability to work from CLI.

  • Ability to work with multiple querying languages

  • Aptitude in working with querying data and the role of a SIEM/EDR

  • Ability to show analytical skills working across multiple technologies and customers.

Knowledge Examples:

Knowledge Examples

  • Experience working with Security Operations and/or EDR/SIEM Platform Management role.

  • A deep understanding of the workings of supported toolsets and technologies.

  • Knowledge of IT Infrastructure and basic networking concepts

  • Knowledge of MITRE ATT&CK framework and how it can be applied to use cases.

  • Knowledge of creation of detection rules as well as improving and enhancing SIEM/EDR

  • Knowledge of Big Data and Data manipulation.

  • Desirable: Certifications in IT infrastructure / SIEM / EDR / Ethical Hacking

  • Desirable: Academic qualifications and/or relevant work experience in lieu of qualification.

Additional Comments:

Role Overview: We are looking for a highly skilled and motivated L3 EDR Subject Matter Expert (SME) to join our Managed EDR (MEDR) team. The SME will play a key role in managing, optimizing, and evolving enterprise-grade EDR/XDR platforms across multiple client environments. This role demands strong technical expertise, analytical thinking, and a proactive approach to improving platform performance, automation, and service delivery.

Key Responsibilities:

Platform Administration & Optimization

  • Own the administration, configuration, and tuning of EDR/XDR platforms (e.g., Microsoft Defender, Cybereason, SentinelOne, CrowdStrike,).
  • Maintain and optimize policies, exclusions, and performance baselines.
  • Conduct regular platform health checks, upgrades, and patch validations.
  • Manage multi-tenant or multi-client environments within SaaS/Hybrid EDR deployments. Incident Support & Advanced Troubleshooting
  • Serve as the highest escalation point (L3) for complex platform or endpoint issues.
  • Collaborate with SOC teams during critical incidents for technical deep-dive analysis.
  • Perform root cause analysis and provide platform-level remediations. Automation & Operational Excellence
  • Develop scripts or playbooks (PowerShell, Python, API integrations) to automate repetitive administrative tasks.
  • Identify areas for process improvement to enhance speed, efficiency, and reliability of the MEDR service. Service Delivery & Client Support
  • Work closely with client security teams and product owners for change management, onboarding, and continuous improvement.
  • Create and maintain detailed operational documentation, SOPs, and configuration baselines.
  • Provide technical inputs during service reviews and roadmap discussions. Security Engineering & Continuous Improvement
  • Contribute to EDR policy enhancements, integration with SIEM/SOAR tools, and telemetry enrichment.
  • Research and test new EDR features, threat detection techniques, and best practices.
  • Mentor L1/L2 analysts and guide them on advanced EDR operations.

Required Skills & Qualifications:

  • Strong hands-on experience with Cybereason, Microsoft Defender for Endpoint, SentinelOne, CrowdStrike, or Cortex XDR (at least two mandatory).
  • Deep understanding of endpoint security architecture, EDR telemetry, and threat hunting workflows.
  • Experience in policy fine-tuning, device group management, automation (PowerShell, Python), and API-based integrations.
  • Knowledge of Windows, macOS, and Linux endpoint internals and troubleshooting.
  • Familiarity with MITRE ATT&CK, incident lifecycle, and EDR-SIEM integrations.
  • Excellent documentation, communication, and cross-functional collaboration skills.
  • Strong analytical and problem-solving skills.
  • Ownership mindset with ability to operate independently.
  • Mentorship and knowledge-sharing orientation.
  • Continuous learner attitude towards emerging EDR and XDR technologies.
Skills

SentinelOne, EDR, Crowdstrike, Cybereason

About UST

UST is a global digital transformation solutions provider. For more than 20 years, UST has worked side by side with the world's best companies to make a real impact through transformation. Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation. With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients' organizations. With over 30,000 employees in 30 countries, UST builds for boundless impact—touching billions of lives in the process.



  • Chennai, Tamil Nadu, India Indium software Full time ₹ 6,00,000 - ₹ 12,00,000 per year

    Job InformationDate Opened10/08/2025Job TypePermanentRSD NO12029IndustryIT ServicesMin Experience8Max Experience12CityChennaiState/ProvinceTamil NaduCountryIndiaZip/Postal Code600018Job DescriptionJob Title: Java/J2EE SME – L3 Production Support Engineer Job Summary: We are looking for an experienced Java/J2EE Technical SME to join our Level 3 (L3)...

  • Vmware SME

    2 weeks ago


    Chennai, Tamil Nadu, India Tata Consultancy Services Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    TCS has been a great pioneer in feeding the fire of young techies like you. We are a global leader in the technology arena and there's nothing that can stop us from growing together.What we are looking forRole: Vmware SME (must havehandson VR Automation exp)Experience Range: yearsLocation: Pune, Chennai/HyderabadInterview Mode: Telephonic InterviewMust...

  • Mobile SME

    6 days ago


    Chennai, Tamil Nadu, India Virtusa Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    L3 Analyst JDWe are seeking a highly skilled System Analyst proficient on Mobile apps development technologies and frameworks. This role is responsible for troubleshooting user-reported incidents resolving system issues performing proactive and preventive maintenance to resolve issues faster and maintain higher uptime. In addition the analyst will contribute...

  • Associate III

    2 weeks ago


    Chennai, Tamil Nadu, India UST Full time ₹ 6,00,000 - ₹ 18,00,000 per year

    Role DescriptionRole Proficiency:Independently support customer applications by monitoring and resolving the system issues. Guides other associates and assists Lead 1 – Production SupportOutcomesUnderstand the application/feature/component and issues related to the same from Business users to resolve issues and create required SOPs/RunbooksMonitor triage...

  • Senior SOC Analyst

    1 week ago


    Chennai, Tamil Nadu, India Freshworks Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Company Description Organizations everywhere struggle under the crushing costs and complexities of "solutions" that promise to simplify their lives. To create a better experience for their customers and employees. To help them grow. Software is a choice that can make or break a business. Create better or worse experiences. Propel or throttle growth. Business...

  • Senior SOC Analyst

    1 day ago


    Chennai, Tamil Nadu, India Freshworks Full time ₹ 4,50,000 - ₹ 6,00,000 per year

    Organizations everywhere struggle under the crushing costs and complexities of "solutions" that promise to simplify their lives. To create a better experience for their customers and employees. To help them grow. Software is a choice that can make or break a business. Create better or worse experiences. Propel or throttle growth. Business software has become...


  • Chennai, Tamil Nadu, India Tata Communications Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Responsible for all aspects of engineering activities and personnel within the Global IP & MPLS Engineering Centre related to WIFI, LAN & NAC service development activities with the objective of providing efficient, cost effective and differentiated network services and solution offered to customers and ensuring all engineering projects, initiatives, and...


  • Chennai, Tamil Nadu, India Bank of America Full time ₹ 5,00,000 - ₹ 15,00,000 per year

    Job Description:At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work is core to how we drive Responsible Growth. This includes our...


  • Chennai, Tamil Nadu, India Citi Full time ₹ 8,00,000 - ₹ 24,00,000 per year

    OverviewCiti's technology team is growing at lightning speed, and we're looking for talented technologists to help build the future of global banking. Ourteams are creating innovations used across the globe – we're changing the way people bank and how the world does business. Citi'stechnology team supports business operations in 100+ countries, across...


  • Chennai, Tamil Nadu, India BNP Paribas Full time ₹ 1,00,00,000 - ₹ 2,00,00,000 per year

    About BNP Paribas GroupEstablished in 2005, BNP Paribas India Solutions is a wholly owned subsidiary of BNP Paribas SA, European Union's leading bank with an international reach. With delivery centers located in Bengaluru, Chennai and Mumbai, we are a 24x7 global delivery center. India Solutions services three business lines: Corporate and Institutional...