Job Summary
We are seeking a highly analytical and technical WAF / EDR / SSE Security
Specialist to join our Security Operations team. In this role, you will be
the primary line of defense responsible for monitoring, triaging, and
investigating security alerts generated across our critical edge, endpoint,
and cloud service boundaries.
You will manage the alert lifecycles of three primary pillars: Web
Application Firewalls (WAF) for application edge defense, Endpoint Detection
& Response (EDR) for host-level security, and Security Service Edge
(SSE) for secure cloud/web access (including CASB and ZTNA). The ideal
candidate is an alert-triage expert who can rapidly distinguish between
complex false positives and malicious behavior, ensuring critical incidents
are escalated and mitigated before damage occurs.
Key Roles & Responsibilities
-
Continuous Alert Monitoring & Triage: Monitor high-volume alerts from
WAF (application layer attacks), EDR (endpoint/host anomalies), and SSE
(data loss, malicious web traffic, unauthorized cloud application usage)
via our SIEM/SOAR platform.
-
Deep-Dive Investigation: Analyze security events to determine root cause.
Validate if anomalous endpoint behavior, suspicious web requests, or
strange cloud data access represents a true positive threat or a benign
business action.
-
WAF Tuning & Management: Review WAF blocks and alerts (e.g., SQLi,
XSS, automated bot traffic). Coordinate with application teams to tune
false positives and optimize WAF rule sets without disrupting legitimate
traffic.
-
Endpoint Incident Containment: Leverage EDR tools to isolate compromised
endpoints, kill malicious processes, harvest forensic artifacts, and
investigate execution chains (e.g., malicious PowerShell, process
injection).
-
SSE & Data Security Enforcement: Track anomalies in data movement and
web gateways. Identify shadow IT, potential data exfiltration vectors, and
violations of our Zero Trust Network Access (ZTNA) policies.
-
Reporting & Documentation: Document comprehensive investigation
timelines and findings in our ticketing system. Create weekly/monthly
metrics reporting on alert volumes, true vs. false-positive ratios, threat
trends, and time-to-remediate.
-
Playbook Optimization: Work closely with senior security engineers to
automate repetitive triage tasks by developing and refining SOAR (Security
Orchestration, Automation, and Response) playbooks.
Key Requirements – Education & Certificates
Bachelor’s degree – BTech or equivalent.
Key Requirements - Experience & Skills
Technical
-
Experience: 2–4+ years of dedicated SOC, MDR, or specialized security
monitoring experience focusing on endpoint and web application defenses.
-
EDR Tool Proficiency: Deep, practical experience using major EDR/XDR
platforms (e.g., CrowdStrike Falcon, SentinelOne, Microsoft Defender for
Endpoint, Carbon Black).
-
WAF Experience: Solid understanding of HTTP/HTTPS protocols, the OWASP Top
10, and experience triaging alerts or adjusting rules in enterprise WAFs
(e.g., Cloudflare, Akamai, AWS WAF, Imperva).
-
SSE/SASE Literacy: Familiarity with Security Service Edge architectures,
including Secure Web Gateways (SWG), Cloud Access Security Brokers (CASB),
and Zero Trust Network Access (ZTNA) solutions (e.g., Zscaler, Netskope,
Palo Alto Prisma).
-
Log & Packet Analysis: Strong capability in reading and interpreting
security event logs, syslogs, application logs, and analyzing network
traffic patterns.
-
Analytical Mindset: Excellent investigative skills with the ability to
correlate seemingly unrelated alerts (e.g., a WAF alert followed by a
specific EDR process launch) to map out an adversary's footprint.
Nice to have
-
Relevant security certifications such as:
-
Foundational: CompTIA Security+, CySA+, or GIAC Security Essentials
(GSEC).
-
Vendor-Specific: CrowdStrike Certified CCFA/CCFR,
Cloudflare/Netskope/Zscaler certifications.
-
Experience writing basic queries to hunt for threats (e.g., KQL for
Microsoft Defender/Sentinel or SPL for Splunk).
-
Basic scripting skills (Python, Bash, or PowerShell) to aid in alert log
parsing.