Apply Edge Start your job search

EDR Expert

VaporVM · Dubai, United Arab Emirates

Apply & track with Apply Edge

EDR ExpertExperience: 3–5+ YearsWe are seeking an experienced EDR Expert with strong hands-on expertise in SentinelOne to monitor, investigate, and analyze endpoint security alerts. The ideal candidate will be responsible for reviewing alerts, distinguishing between false positives and genuine security incidents, and supporting timely incident response.Key ResponsibilitiesReview and analyze SentinelOne EDR alerts to determine whether they represent false positives or genuine security incidents.Investigate endpoint alerts, suspicious activities, malicious processes, files, scripts, and user behavior.Perform detailed analysis of endpoint telemetry, detection data, process trees, and indicators of compromise (IOCs).Validate security incidents and determine the severity and potential impact on the environment.Investigate suspicious or malicious activities using SentinelOne capabilities.Correlate EDR alerts with other available security data to identify potential attack patterns.Escalate confirmed security incidents according to established incident response procedures.Document investigation findings, root causes, and recommended remediation actions.Identify recurring false positives and recommend appropriate alert tuning and policy adjustments.Support containment, remediation, and threat eradication activities where required.Maintain incident records and prepare regular reports on EDR alerts and security incidents.Stay updated on emerging endpoint threats, malware techniques, and MITRE ATT&CK tactics and techniques.Required Skills & Experience3–5+ years of experience in EDR, SOC, Cybersecurity Operations, or Incident Response.Strong hands-on experience with SentinelOne is mandatory.Good understanding of endpoint security, malware analysis, and incident investigation.Experience analyzing process trees, endpoint telemetry, IOCs, and suspicious activities.Strong knowledge of Windows and Linux endpoint security.Understanding of common attack techniques, malware behavior, and MITRE ATT&CK framework.Experience with SIEM platforms such as Splunk, Microsoft Sentinel, or QRadar is an advantage.Strong analytical and incident investigation skills.Relevant cybersecurity certifications such as CompTIA Security+, CySA+, CEH, GCIH, or equivalent are preferred.