Specialist – Endpoint Security
CPX · Abu Dhabi Emirate, United Arab Emirates
Apply & track with Apply EdgeJob Purpose :-To protect the organization's endpoint estate by operating endpoint security controls, monitoring and investigating EDR/XDR detections, and supporting the containment and remediation of cyber threats. The role maintains secure configurations across Windows, macOS, and Linux endpoints, strengthens endpoint hardening and compliance, supports vulnerability and attack-surface reduction activities, and correlates endpoint, network, web, cloud, and privileged-access telemetry through established SOC, incident response, and ITSM processes.Primary Responsibilities: -Endpoint Threat Monitoring & InvestigationMonitor and investigate alerts across Trend Micro AV, Trend Micro XDR, Deep Discovery Inspector (DDI), TippingPoint IPS, Forcepoint, and Netskope for malware, suspicious behavior, exploit activity, credential threats, malicious network activity, and potential endpoint compromise.Correlate endpoint, network, web, cloud, and identity-security events using telemetry from Trend Micro AV/XDR, DDI, TippingPoint IPS, Forcepoint, Netskope, CyberArk, SIEM, and threat intelligence to determine severity, scope, affected assets, and required escalationPerform initial investigations by reviewing process trees, file and hash details, network connections, user activity, device history, privileged-account activity, and related indicators of compromise.Administer and support endpoint security agents and policies, with primary hands-on experience in Trend Micro AV and Trend Micro XDR, including deployment, health monitoring, policy assignment, signature and engine updates, tamper protection, exclusions, and agent upgrades.Maintain security coverage across Windows, macOS, Linux, VDI, and approved server endpoints; identify unmanaged, disconnected, unhealthy, or non-reporting assets and coordinate remediation.Review endpoint security configurations and exceptions to ensure they are authorized, risk-assessed, time-bound, documented, and aligned with security standards.Tune prevention and detection policies to strengthen security effectiveness while minimizing false positives and operational disruption.Incident Response & Containment : -Execute approved containment actions under SOC/IR guidance, including host isolation, malicious process termination, file quarantine, indicator blocking, privileged-account suspension through CyberArk processes, account disablement, forced sign-outs, and session or token revocation.Support evidence preservation, malware eradication, recovery validation, and post-incident monitoring while maintaining a clear chain of actions and incident timeline.Assess endpoint compliance against approved security baselines, encryption requirements, host firewall policies, application control, device control, and attack-surface reduction rules.Coordinate remediation of endpoint vulnerabilities and security misconfigurations, validate corrective actions, and track exceptions or overdue items to closure.Collaborate with SOC, incident response, PAM/IAM, network security, vulnerability management, infrastructure, workplace technology, and application teams. Support investigations and control validation involving CyberArk, DDI, TippingPoint IPS, Forcepoint, and Netskope.Minimum Work Experience & Education : -Minimum 5 years of experience in endpoint security operations, endpoint protection engineering, SOC operations, or a similar cybersecurity role, including hands-on exposure to EDR/XDR monitoring, incident investigation, and containment.Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related discipline.Skills / Certifications : -Hands-on experience with endpoint and enterprise security technologies, including CyberArk; Trend Micro AV; Trend Micro XDR; Deep Discovery Inspector (DDI); TippingPoint IPS; Forcepoint; and Netskope. Strong knowledge of EDR/XDR alert triage, malware analysis, endpoint containment and remediation, policy administration, endpoint hardening, vulnerability remediation, attack-surface reduction, encryption, host firewall, application and device control, and ITSM/security case-management workflows such as ServiceNow. Relevant certifications include CompTIA Security+, SC-200, MD-102, Trend Micro or CyberArk product certification, or equivalent security-operations credentials; ITIL Foundation is advantageous.