Track Lead - JAMF
Teknik, data och digitalt · IT-infrastruktur och säkerhet · Cybersäkerhet · Mjukvaruutveckling
I korthet
The L3 Endpoint Security Engineer is a technical Subject Matter Expert (SME) for Antivirus, NGAV, and EDR platforms, responsible for solution architecture, threat investigations, and platform optimization. This role provides technical leadership to L1/L2 teams and focuses on continuous improvement of endpoint security services.
Ansvarsområden
- Serve as the technical Subject Matter Expert (SME) for Antivirus (AV), Next-Generation Antivirus (NGAV), and Endpoint Detection & Response (EDR) platforms.
- Design, implement, administer, and optimize endpoint security solutions.
- Lead deployment, migration, upgrade, and integration projects for endpoint security technologies.
- Define and maintain endpoint security baselines, standards, policies, and governance controls.
- Lead investigation and resolution of critical security incidents, malware outbreaks, ransomware attacks, and advanced threats.
- Perform advanced threat hunting, malware analysis, forensic investigations, and root cause analysis.
- Develop and implement containment, remediation, recovery, and detection enhancement strategies.
- Optimize security policies, exclusions, detections, alerts, and response workflows.
- Act as the highest technical escalation point for complex endpoint security issues.
- Design and support integrations with Microsoft Intune, Active Directory, Entra ID, SIEM platforms, Microsoft Sentinel, Splunk, and SOC monitoring solutions.
- Drive continuous service improvement initiatives through platform tuning, automation, orchestration, and operational process optimization.
- Conduct Proof of Concepts (POCs) and evaluate emerging endpoint security technologies.
- Collaborate with SOC, Infrastructure, Cloud, and Endpoint Management teams.
- Develop and maintain technical documentation, architecture diagrams, SOPs, runbooks, and knowledge base articles.
- Provide technical leadership, mentoring, training, and knowledge transfer to L1 and L2 engineers.
- Prepare executive reports, security posture assessments, compliance reports, risk analyses, and strategic recommendations.
- Support audit, compliance, and governance activities.
Krav
- Must have 8+ years of experience in Endpoint Security and Implementation (MS Defender, SentinelOne, CrowdStrike, JAMF Protect, Zimperium)
- Proficiency with MS Defender, SentinelOne, CrowdStrike, JAMF Protect, Zimperium
- Experience with Defender
Önskade kvalifikationer
- Design and support integrations with Microsoft Intune, Active Directory, Entra ID, SIEM platforms, Microsoft Sentinel, Splunk, and SOC monitoring solutions
- Collaborate with SOC, Infrastructure, Cloud, and Endpoint Management teams to strengthen detection, response, and security operations capabilities.
- Develop and maintain technical documentation, architecture diagrams, SOPs, runbooks, standards, and knowledge base articles.
- Prepare executive reports, security posture assessments, compliance reports, risk analyses, and strategic recommendations for stakeholders and management.
- Support audit, compliance, and governance activities while ensuring adherence to organizational security requirements and best practices.
Förmåner
- Supercharge your potential.
- Find your career.
- Find your spark.
- A place that knows that helping its customers stay on top starts by putting its people first.
#Endpoint Security#Antivirus#NGAV#EDR#JAMF