Jobs and Careers
CA
Endpoint Technical Lead
CapgeminiSouthfield, United Statesfull_timeVerifiedPosted 6 Sept 2025
š° $101,320/yr($55,692/yr ā $101,320/yr)
About the role
Endpoint Technical Lead-081551
Description
Ā*** Must be a US Citizen Due to Client Constraints ***
Ā Your Responsibilities:
- Attend client calls and provide updates for the respective tools
- Support L2 for troubleshooting issues
- Manage end-to-end Endpoint Security Solutions including installation, configuration, management, administration, and troubleshooting
- Hands-on experience in the security incident response lifecycle and its phases
- Provide service improvement suggestions to management
- Fine-tune rules and raise cases with vendors for any issues
- Suggest new integrations to clients and their benefits
- Support Endpoint Detection and Response (EDR) applications to ensure cybersecurity service availability for all endpoints (servers, desktops, laptops)
- Monitor encryption, EDR, and AV logs (Bitlocker, Symantec, Sentinel One)
- Monitor dashboard for compliance, threats, and troubleshoot issues
- Check if any incidents are missed by L1 and follow up for the cause
- Maintain SOP for new events
- Whitelisting/blacklisting of IPs
- Review phishing templates sent by L1 and perform 4-Eye Check
- Troubleshoot Proofpoint issues for users and escalate to L3 if unresolved
- Fine-tune policies in Cisco ESA and Fireeye
- Manage the team and attend client calls
- Monitor EDR, email gateway, and AV logs
- Monitor dashboard for compliance, threats, and troubleshoot issues
Your Experience:
- Strong knowledge and understanding of the Microsoft E5 suite
- Hands-on experience with Defender ATP, Azure ATP, O365 Security
- Experience in creating and deploying antimalware policies for Endpoint Protection in System Center Configuration Manager
- Risk/log analysis and understanding of Indicators of Compromise (IOC)
- Basic knowledge of Defender ATP automation and scripting
- Knowledge of grouping/tagging, ATP vulnerability assessment
- Experience with attack simulators, anti-phishing policies, reporting, and threat analytics
- Configuring automation, investigation, and response
- Malware and spyware detection and remediation
- Rootkit detection and remediation
- Critical vulnerability assessment and automatic definition and engine updates
- Working knowledge of client firewall tools, managing auto location, firewall policies, HI checks, and intrusion detection
- Knowledge of DLP, O365, Azure, Intune, encryption
- Experience with Microsoft Defender for Endpoint (MDE) including configuration, management, and troubleshooting
- Experience with Microsoft Defender for Office 365 (MDO) including implementation, policy fine-tuning, and threat management
Email Security:
- Familiarity with email protection from threats including phishing, BEC, imposter, and others
- Handling email security and related incidents
- Knowledge of MX records, DNS, Active Directory, SSO, SAML
- Implementation of email security standards such as SPF, DKIM, and DMARC
- Implementation of security standards such as SIEM
- Enhancing security of email infrastructure by implementing controls to manage and mitigate risks
- Analysis and implementation of perimeter email security and email routing solutions
- Building Standard Operating Processes for operations of the platform
- Managing knowledge transfer of operations to L2 teams
- Ensuring compliance with Group Security policies
- Collaborating with M365, Cyber Security leads, Cyber Defense, Group Security teams
Soft Skills:
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights ā in under 60 seconds.
Apply Now āGenerate Application KitFree account required ā sign up in 30s