- Act as the primary administrator and subject matter expert for the endpoint protection platform
- Proactively configure, maintain, and optimize endpoint prevention and detection policies
- Manage sensor lifecycle, coverage, versioning, and health across enterprise endpoints
- Administer role-based access controls and identity integrations (e.g., SSO, RBAC)
- Execute response actions such as host containment, process termination, and IOC management in support of Security Operations and Incident Response teams activities
- Ensure alerts integrate effectively with SIEM and ITSM platforms
- Support triaging and investigating detections and alerts in coordination with Security Operations and Incident Response teams
- Partner with Security Operations and Incident Response teams on investigations and post incident reviews
- Maintain documentation, runbooks, and standard operating procedures
- Participate in change management and risk review processes for policy updates
- Support audits, assessments, and compliance reviews related to endpoint security
- Identify opportunities to improve platform efficiency, reliability, and automation
Requirements
- 8+ years of experience in systems or security platform administration
- Hands-on experience administering CrowdStrike Falcon or a comparable EDR platform
- Strong understanding of endpoint security concepts and incident response workflows
- Experience supporting Windows, Linux, and macOS environments
- Ability to operate independently in a production enterprise environment
- Experience integrating endpoint security platforms with SIEM or ITSM tools
- Scripting or automation experience (PowerShell, Python, Bash)
- Experience in regulated or highly controlled environments
- Relevant security or platform certifications
Core Competencies
Demonstrates expertise in endpoint protection platform administration, including configuration, maintenance, and optimization of security policies. Proficient in incident response workflows and integration with SIEM and ITSM tools, ensuring compliance and operational efficiency.
Highest-signal resume keywords
- CrowdStrike Falcon Administration
- Endpoint Security Concepts
- Incident Response Workflows
- Scripting Automation (PowerShell, Python, Bash)
- Integration with SIEM or ITSM Tools
ATS Optimization Keywords
Hard Skills
- Endpoint Protection Platform Administration
- Policy Configuration and Maintenance
- Sensor Lifecycle Management
- Role-Based Access Control (RBAC)
- Host Containment and Process Termination
- Documentation and Runbook Maintenance
- Change Management Participation
- Windows Environment Support
- Linux Environment Support
- MacOS Environment Support
Soft Skills
- Independent Operation
- Collaboration with Security Teams
- Problem-Solving
Certifications & Qualifications
- Relevant Security Certifications
Industry Keywords
- Regulated Environments
- Compliance Reviews
- Risk Review Processes
- Incident Response
- Security Operations
Tools & Technologies
- SIEM Platforms
- ITSM Tools
- Endpoint Detection and Response (EDR) Platforms