l3 edr sme

1 week ago


Chennai, Tamil Nadu, India UST Full time ₹ 12,00,000 - ₹ 36,00,000 per year

7 - 9 Years

1 Opening

Chennai, Noida, Trivandrum

Role description

Role Proficiency:

Provide support to a specific SIEM or EDR technology for global customers; to ensure and maintain the platform is functioning as expected. Independently monitor and proactively take ownership for resolution of issues and work matters.

Outcomes:

  • Monitor investigate and provide meaningful resolution of tickets and issues across multiple customers for the specified SIEM or EDR type. Escalate issues observed accordingly to a team member if appropriate to ensure optimal performance of the supported platform

  • Assist with service requests for platform types such as access requests as well as more targeted requests for specific modules on platform such as dashboard creation and query support. Investigate larger issues to ensure optimal service for internal and external stakeholders.

  • Provide assistance with maintenance activities to help with improving understanding of architecture of supported platforms; as well as self-study to building proficiency for supported toolsets

  • Proactively develop and maintain documentation and knowledge articles for the broader team related to customer support

  • Generate relevant reporting as required for platforms supported on a regular basis; ensuing internal and external reporting requirements are met.

  • Ensure in-life requests are being actioned in a timely manner for self as well as junior roles to ensure effective maintenance and management of the customer platform.

  • With minimal supervision provide support where required to other platform engineers by taking ownership of issues and ensuring requests are rectified focusing on the impact to the customer

  • Provide supervision and guidance to junior members of the team.

Measures of Outcomes:

  • Percent of Adherence to processes and methodologiesa.Percent of adherence to SLAs for in-life ticketing processesb.Percent of adherence to workflows and completeness of audit trails for activities undertaken.

  • Productivity score maintaineda.Number of issues identified early in the event of issues with delivering tasks or workload.b.Number of issues with effective evidence provided for escalations during triage.

  • Number of opportunities to enhance change documentation to ensure processes remain relevant for the broader team.

  • Number: of relevant skill related training and development activities undertaken; evidenced by certification.

  • Number of opportunities to and improve helping to reduce false positives

Outputs Expected:

Technical Expertise:

  • Demonstrate comprehension and experience in the specific SIEM or EDR platform that Engineer is working on.

  • Comfortable with and awareness of the customers being supported; capable of providing support towards high level customer QBR (Quarterly Business Review) preparation.

  • Use technology to identify with the ability to implement technical solutions to issues with queries/rules/dashboards/data feeds

  • Provide input to customer requirements or issues i.e.

    Ability to have understanding to translate a customer requirement into a technical solution of how that could be achieved in the respective platform.

  • Provide support to Junior members.

Platform Management – Incidents and Requests:

  • Provide accurate updates to appropriate Service and Change Requests; ensuring audit trails are preserved and SLAs are achieved.

  • Take the lead to identify issues with the specified platform type or its supporting infrastructure.

  • Proactive identification of issues

    with behavioural analysis/patterns identified

    with suggestions for resolutions.

  • Provide support to Junior members.

Stakeholder Focus:

  • Ensure relevant reporting metrics of customer information provided in a timely manner; and engaging customer/TAM/Project team where required.

  • Ensure customer specific processes are being followed.

  • Undertake mandatory and proactive learning and development opportunities.

Skill Examples:

  • Good communication skills

  • Skill in being prepared to undertake background check/validation to ensure integrity.

  • Ability to work unsupervised with the assigned SIEM or EDR technologies and their supporting infrastructure

  • Ability to work from CLI.

  • Ability to work with multiple querying languages

  • Aptitude in working with querying data and the role of a SIEM/EDR

  • Ability to show analytical skills working across multiple technologies and customers.

Knowledge Examples:

Knowledge Examples

  • Experience working with Security Operations and/or EDR/SIEM Platform Management role.

  • A deep understanding of the workings of supported toolsets and technologies.

  • Knowledge of IT Infrastructure and basic networking concepts

  • Knowledge of MITRE ATT&CK framework and how it can be applied to use cases.

  • Knowledge of creation of detection rules as well as improving and enhancing SIEM/EDR

  • Knowledge of Big Data and Data manipulation.

  • Desirable: Certifications in IT infrastructure / SIEM / EDR / Ethical Hacking

  • Desirable: Academic qualifications and/or relevant work experience in lieu of qualification.

Additional Comments:

Role Overview: We are looking for a highly skilled and motivated L3 EDR Subject Matter Expert (SME) to join our Managed EDR (MEDR) team. The SME will play a key role in managing, optimizing, and evolving enterprise-grade EDR/XDR platforms across multiple client environments. This role demands strong technical expertise, analytical thinking, and a proactive approach to improving platform performance, automation, and service delivery.

Key Responsibilities:

Platform Administration & Optimization

  • Own the administration, configuration, and tuning of EDR/XDR platforms (e.g., Microsoft Defender, Cybereason, SentinelOne, CrowdStrike,).
  • Maintain and optimize policies, exclusions, and performance baselines.
  • Conduct regular platform health checks, upgrades, and patch validations.
  • Manage multi-tenant or multi-client environments within SaaS/Hybrid EDR deployments. Incident Support & Advanced Troubleshooting
  • Serve as the highest escalation point (L3) for complex platform or endpoint issues.
  • Collaborate with SOC teams during critical incidents for technical deep-dive analysis.
  • Perform root cause analysis and provide platform-level remediations. Automation & Operational Excellence
  • Develop scripts or playbooks (PowerShell, Python, API integrations) to automate repetitive administrative tasks.
  • Identify areas for process improvement to enhance speed, efficiency, and reliability of the MEDR service. Service Delivery & Client Support
  • Work closely with client security teams and product owners for change management, onboarding, and continuous improvement.
  • Create and maintain detailed operational documentation, SOPs, and configuration baselines.
  • Provide technical inputs during service reviews and roadmap discussions. Security Engineering & Continuous Improvement
  • Contribute to EDR policy enhancements, integration with SIEM/SOAR tools, and telemetry enrichment.
  • Research and test new EDR features, threat detection techniques, and best practices.
  • Mentor L1/L2 analysts and guide them on advanced EDR operations.

Required Skills & Qualifications:

  • Strong hands-on experience with Cybereason, Microsoft Defender for Endpoint, SentinelOne, CrowdStrike, or Cortex XDR (at least two mandatory).
  • Deep understanding of endpoint security architecture, EDR telemetry, and threat hunting workflows.
  • Experience in policy fine-tuning, device group management, automation (PowerShell, Python), and API-based integrations.
  • Knowledge of Windows, macOS, and Linux endpoint internals and troubleshooting.
  • Familiarity with MITRE ATT&CK, incident lifecycle, and EDR-SIEM integrations.
  • Excellent documentation, communication, and cross-functional collaboration skills.
  • Strong analytical and problem-solving skills.
  • Ownership mindset with ability to operate independently.
  • Mentorship and knowledge-sharing orientation.
  • Continuous learner attitude towards emerging EDR and XDR technologies.
Skills

SentinelOne, EDR, Crowdstrike, Cybereason

About UST

UST is a global digital transformation solutions provider. For more than 20 years, UST has worked side by side with the world's best companies to make a real impact through transformation. Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation. With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients' organizations. With over 30,000 employees in 30 countries, UST builds for boundless impact—touching billions of lives in the process.



  • Chennai, Tamil Nadu, India Indium software Full time ₹ 6,00,000 - ₹ 12,00,000 per year

    Job InformationDate Opened10/08/2025Job TypePermanentRSD NO12029IndustryIT ServicesMin Experience8Max Experience12CityChennaiState/ProvinceTamil NaduCountryIndiaZip/Postal Code600018Job DescriptionJob Title: Java/J2EE SME – L3 Production Support Engineer Job Summary: We are looking for an experienced Java/J2EE Technical SME to join our Level 3 (L3)...


  • Chennai, Tamil Nadu, India OA Compserve Pvt. Ltd Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    DescriptionJob Opening - DetailsPosition :Device management L3 Support EngineersLocation :ChennaiExperience :At least 10 to 12 years of experience out of which minimum 7 Years of experience in security incident monitoring, security architecture, security solution implementation, administration and management of security devices as mentioned in RFP.Detailed...

  • Mobile SME

    6 days ago


    Chennai, Tamil Nadu, India Virtusa Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    L3 Analyst JDWe are seeking a highly skilled System Analyst proficient on Mobile apps development technologies and frameworks. This role is responsible for troubleshooting user-reported incidents resolving system issues performing proactive and preventive maintenance to resolve issues faster and maintain higher uptime. In addition the analyst will contribute...


  • Chennai, Tamil Nadu, India Cozzera Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Position:IT Infrastructure & Security Operations EngineerExperience:8+ YearsLocation:Onsite – ChennaiEngagement:Full-timeAbout the RoleWe are seeking a highly skilledIT Infrastructure & Security Operations Engineerto lead operations across on-premises, cloud, and hybrid environments. The ideal candidate will bring strong hands-on expertise inNutanix HCI,...


  • Chennai, Tamil Nadu, India Tata Communications Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    About The CompanyTSC Redefines Connectivity with Innovation and IntelligenceDriving the next level of intelligence powered by Cloud, Mobility, Internet of Things, Collaboration, Security, Media services and Network services, we at Tata Communications are envisaging a New World of CommunicationsJob Title: Cloud and Virtualization SME (DriveNets Experience...

  • Senior SOC Analyst

    6 days ago


    Chennai, Tamil Nadu, India freshworks technologies ltd Full time ₹ 12,00,000 - ₹ 24,00,000 per year

    Job Description Company Description Organizations everywhere struggle under the crushing costs and complexities of solutions that promise to simplify their lives. To create a better experience for their customers and employees. To help them grow. Software is a choice that can make or break a business. Create better or worse experiences. Propel or throttle...

  • Associate III

    2 weeks ago


    Chennai, Tamil Nadu, India UST Full time ₹ 6,00,000 - ₹ 18,00,000 per year

    Role DescriptionRole Proficiency:Independently support customer applications by monitoring and resolving the system issues. Guides other associates and assists Lead 1 – Production SupportOutcomesUnderstand the application/feature/component and issues related to the same from Business users to resolve issues and create required SOPs/RunbooksMonitor triage...

  • Senior SOC Analyst

    1 week ago


    Chennai, Tamil Nadu, India Freshworks Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Company Description Organizations everywhere struggle under the crushing costs and complexities of "solutions" that promise to simplify their lives. To create a better experience for their customers and employees. To help them grow. Software is a choice that can make or break a business. Create better or worse experiences. Propel or throttle growth. Business...

  • Senior SOC Analyst

    2 weeks ago


    Chennai, Tamil Nadu, India Freshworks Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Senior SOC Analyst (AI Analyst & Automation Engineer) Company Description Organizations everywhere struggle under the crushing costs and complexities of "solutions" that promise to simplify their lives. To create a better experience for their customers and employees. To help them grow. Software is a choice that can make or break a business. Create better...

  • Associate III

    2 days ago


    Chennai, Tamil Nadu, India UST Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    3 - 5 Years1 OpeningChennai, Kochi, TrivandrumRole descriptionRole Proficiency:Independently support customer applications by monitoring and resolving the system issues. Guides other associates and assists Lead 1 – Production SupportOutcomes:Understand the application/feature/component and issues related to the same from Business users to resolve issues...