L2 - Security Engineer (EDR Solutions)

Há 2 dias


Brasilia, Brasil HCLTech Tempo inteiro

www.hcltech.com
We are HCLTech, one of the world’s largest and fastest growing technology and DSA companies with over 227,000 professionals across 60 countries, driving progress through industry-leading capabilities focused on Digital, Engineering and Cloud.

The driving force behind this work, our people, is a diverse, creative and passionate audience that enables us to continually raise the bar for excellence in our services. We strive to empower each of our professionals to achieve their best, while also striving to help them find their daily inspiration and become the best version of themselves.

Job Title: L2 Security Engineer - EDR Solutions (CrowdStrike, Palo Alto XDR, Microsoft Defender for Endpoint, SentinelOne)
Location: Hybrid, 24x7 Shifts
Job Type: Full-Time (Rotational Shift Model, including weekends and holidays)

Job Summary:
As an L2 Security Engineer, you will be responsible for ensuring the smooth operation of EDR solutions by monitoring platform health, enforcing security policies, and troubleshooting endpoint issues across multiple EDR platforms including CrowdStrike, Palo Alto XDR, Microsoft Defender for Endpoint, and SentinelOne. Your role includes onboarding devices, validating security rules, handling basic policy enforcement issues, and ensuring that all endpoints remain compliant with security baselines. You will assist in resolving connectivity issues, missing telemetry cases, and agent health checks while escalating complex platform-related problems to L3.

Key Responsibilities:
· Ensure endpoints are successfully onboarded to EDR solutions across all platforms (Windows, macOS, Linux, iOS, Android).
· Monitor endpoint connectivity and health status within the EDR portals.
· Validate that security rules, EDR, and antivirus policies are applied correctly.
· Assist in troubleshooting policy conflicts and enforcement issues.
· Investigate and validate EDR alerts, classify threats, and escalate incidents if required.
· Apply basic remediation steps like isolating devices, initiating scans, or triggering automated investigations.
· Identify endpoints not reporting telemetry or experiencing EDR agent failures.
· Perform basic troubleshooting (e.g., restarting services, re-onboarding devices, checking connectivity).
· Escalate complex security incidents and persistent issues to L3.
· Assist in preparing incident summaries and compliance reports for management.
· Ensure endpoints are running the latest security patches and EDR updates.
· Validate compliance with security baselines and recommend corrective actions.
· Collaborate with global SOC, Threat Hunting, and Incident Response teams for critical security incidents.

Required Skills & Knowledge:
· Hands-on expertise in CrowdStrike, Palo Alto XDR, Microsoft Defender for Endpoint, and SentinelOne.
· Ability to analyze malware behaviors, execute incident containment strategies, and escalate threats appropriately.
· Scripting knowledge in PowerShell or Python (preferred).
· Strong analytical, documentation, and communication skills.

Work Environment & Shift Requirements:
· 24x7 support model with rotational shifts (including nights, weekends, and holidays).
· Ability to work in a fast-paced, high-pressure SOC environment.
· Excellent collaboration and coordination with global cybersecurity teams.

Preferred Certifications:
· CrowdStrike Certified Falcon Administrator (CCFA)
· Palo Alto Networks Certified Cybersecurity Associate (PCCSA)
· Microsoft Certified: Security Operations Analyst Associate (SC-200)
· SentinelOne Certified Administrator

At HCLTech, we don’t just offer jobs — we offer journeys. Join a global team where your work drives innovation, your ideas matter, and your growth is supported every step of the way.

Why Choose HCLTech?
Be part of a purpose-led organization with a global footprint
Collaborate with diverse teams across borders
Work on cutting-edge technologies in enterprise integration
Enjoy career mobility, continuous learning, and a culture of inclusion

Ready to #FindYourSpark and be part of a team that’s #SuperchargingProgress ?
Apply now or reach out to learn more about this exciting opportunity


  • Security Operations Analyst

    1 semana atrás


    Brasilia, Brasil Kyndryl Tempo inteiro

    Who We Are Kyndryl is a market leader that thinks and acts like a start-up. We design, build, manage, and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward - always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our...


  • Brasilia, Brasil Teletex IT Solutions Tempo inteiro

    Você é uma pessoa que gosta de realizar os seus **SONHOS** e busca por desafios para alcançar **VOOS CADA VEZ MAIS ALTOS**? Gosta de ser **PROTAGONISTA** e construir relações que sejam **SUSTENTÁVEIS**? É fanático por **INOVAR** e deseja** MULTIPLICAR O SEU CONHECIMENTO **com uma equipe que não para de crescer? **_#VamosPraCima_**! Se você quer...

  • Analista de Infra Sênior

    2 semanas atrás


    Brasilia, Brasil BuscarVagas Tempo inteiro

    Administrar/Implementar soluções de segurança como SIEM, WAF, EDR e outros. Propor melhorias no ambiente de segurança Criação de regras, playbooks, runbooks para automatizar e melhorar o monitoramento interno baseado nos frameworks de segurança. Identificar e analisar logs das ferramentas de segurança Resposta a incidentes de segurança. A Combinar...


  • Brasilia, Brasil Fortinet Tempo inteiro

    Professional Services Architect  As customers security infrastructure become more complex, Fortinet Professional Services experts are positioned to help them every step of the way. We’ve accumulated many years of experience to help our customers with their security design, deployment, operation, and optimization needs. The Professional Services Architect...

  • Analista de Segurança

    2 semanas atrás


    Brasilia, Brasil Véli RH Tempo inteiro

    Publicado hoje **Cargo**:Analista de Segurança (Pré-Venda Técnico) **Tipo de Contrato**:Prestador de serviço (PJ) **Área profissional**:Informática/T.I. **Carga-horária**:40 **Número de vagas**:1 **Benefícios**:Férias remuneradas. **Requisitos**: Escolaridade mínima: Graduação - Concluído - Obrigatório Pós-Graduação - Concluído -...


  • Greater Brasilia, Brasil G4F Tempo inteiro

    Especialista em Gestão de Segurança da Informação (Presencial - Brasília) Atribuições: Apoiar gerencialmente nas ações de segurança cibernética; Apoiar na elaboração, implantação, monitoramento, avaliação e manutenção de normativos de segurança da informação; Apoiar gerencialmente os processos de auditoria interna de segurança...


  • Brasilia, Brasil Hepta Tempo inteiro

    **Brasília/DF**: - 08:00-18:00 ESCOLARIDADE **Superior - Completo** - Na área de TI CONHECIMENTOS - Administração de servidores: Linux - Administração de servidores: Windows server INFORMAÇÕES ADICIONAIS - Necessidade de estrutura para Homeoffice CERTIFICAÇÕES - Google Professional Cloud Architects **Opcional** - AWS Certified Solutions...

  • Major Acct Manager

    Há 3 dias


    Brasilia, Brasil Fortinet Tempo inteiro

    **Responsibilities**: - Develop account plans to achieve goals and exceed quota responsibility - Maximize Fortinet opportunity while providing value added solutions to public sector institutions - Serves as lead contact responsible for the flow of information to/from executive management - Works closely together with the Team Lead MAM - Major Account...


  • Greater Brasilia, Brasil G4F Tempo inteiro

    Especialista em Gestão de Segurança da Informação (Presencial - Brasília) Atribuições:Apoiar gerencialmente nas ações de segurança cibernética;Apoiar na elaboração, implantação, monitoramento, avaliação e manutenção de normativos de segurança da informação;Apoiar gerencialmente os processos de auditoria interna de segurança...


  • Greater Brasilia, Brasil G4F Tempo inteiro

    Especialista em Gestão de Segurança da Informação (Presencial - Brasília) Atribuições: Apoiar gerencialmente nas ações de segurança cibernética; Apoiar na elaboração, implantação, monitoramento, avaliação e manutenção de normativos de segurança da informação; Apoiar gerencialmente os processos de auditoria interna de segurança...