Help AG is looking for a Senior Security Engineer – EDR & NDR who will be responsible for the design, implementation, administration, optimization, and support of Endpoint Detection & Response (EDR) and Network Detection & Response (NDR) platforms across customer environments. The role requires strong technical expertise in deploying, integrating, tuning, and maintaining enterprise security platforms while ensuring optimal performance, visibility, and security coverage. The engineer will work closely with SOC Analysts, Incident Response, Threat Intelligence, SIEM Engineering, Solution Architects, and customers to deliver high-quality Managed Security Services and support strategic cybersecurity initiatives.
Responsibilities
EDR Platform Administration
Deploy, configure, administer, and maintain enterprise EDR platforms including:
Microsoft Defender for Endpoint
CrowdStrike Falcon
Carbon Black
Trend Micro Vision One / Apex One
Perform health checks, upgrades, troubleshooting, and lifecycle management.
Configure sensors, packet capture, metadata collection, and monitoring infrastructure.
Tune AI-based detections and behavioural analytics.
Investigate suspicious network activities including lateral movement, command-and-control communications, ransomware, insider threats, and credential abuse.
Integrate NDR platforms with SIEM, SOAR, EDR, and Threat Intelligence platforms.
Perform platform health monitoring, upgrades, and capacity management.
Engineering & Integration
Design and implement integrations between EDR, NDR, SIEM, SOAR, Threat Intelligence Platforms, Active Directory, Microsoft Entra ID, and ITSM platforms.
Develop automation workflows using APIs and scripting to improve operational efficiency.
Create and maintain architecture diagrams, technical documentation, SOPs, and operational runbooks.
Support customer onboarding, migration, and platform integration projects.
Validate telemetry collection, data quality, and event visibility across integrated security platforms.
Threat Detection & Security Operations
Work closely with SOC and Incident Response teams to investigate and respond to security incidents.
Conduct threat hunting using endpoint, network, and SIEM telemetry.
Develop and improve detection use cases aligned with the MITRE ATT&CK framework.
Participate in purple team exercises, adversary emulation, and continuous improvement initiatives.
Recommend security improvements based on emerging threats and incident findings.
Operational Responsibilities
Perform platform upgrades, patching, backup validation, and preventive maintenance.
Monitor platform health, licensing, storage, and overall performance.
Maintain technical documentation, SOPs, and knowledge base articles.
Provide technical mentoring and guidance to junior engineers and SOC analysts.
Participate in after-hours maintenance and critical incident support when required.
Qualifications & Skills
Minimum 5–7 years of experience in cybersecurity engineering or security operations.
Minimum 4 years of hands-on experience administering enterprise EDR platforms.
Minimum 3 years of experience administering NDR platforms.
Preferred Certifications
CrowdStrike Falcon Administrator / Responder
Microsoft Defender for Endpoint Administrator
VMware Carbon Black Administrator
Trend Micro Vision One Professional
Vectra AI Certified Administrator
ExtraHop Reveal(x) Certified Engineer
Microsoft Certified: Security Operations Analyst (SC-200)
Microsoft Certified: Azure Security Engineer (AZ-500)
Splunk Core Certified Power User, Enterprise Security Admin, or Microsoft Sentinel certification (preferred)
CISSP, GCIH, GCED, CySA+, Security+, or equivalent
Working knowledge of SIEM platforms, preferably Splunk Enterprise Security and/or Microsoft Sentinel, including data onboarding, alert tuning, dashboards, and investigations.
Experience supporting enterprise security platforms within a SOC or Managed Security Services (MSS) environment.
EDR
Microsoft Defender for Endpoint
CrowdStrike Falcon
VMware Carbon Black Cloud
Trend Micro Vision One / Apex One
NDR
Vectra AI
ExtraHop Reveal(x)
SIEM
Splunk Enterprise / Splunk Enterprise Security
Microsoft Sentinel
Basic knowledge of KQL and SPL
Log onboarding and normalization
Correlation rule development
Dashboard creation
Alert tuning
Data connector troubleshooting
Strong understanding of:
Endpoint Security
Network Security
Incident Response
Threat Hunting
Detection Engineering
MITRE ATT&CK Framework
IOC/IOA Management
Malware Analysis
Windows and Linux Security
Active Directory & Microsoft Entra ID
Networking (TCP/IP, DNS, VPN, Firewalls)
REST APIs
PowerShell and/or Python scripting
Benefits
Health insurance with one of the leading global providers for medical insurance.
Career progression and growth through challenging projects and work.
Employee engagement and wellness campaigns activities throughout the year.
Excellent learning and development opportunities.
Inclusive and diverse working environment.
Flexible/Hybrid working environment.
Open door policy.
About Us
Help AG, the cybersecurity arm of e&, is the Middle East's trusted cybersecurity partner, enabling governments, enterprises and critical industries to innovate with confidence. Combining strategic consulting, advanced managed security services and deep technology expertise, Help AG helps organisations strengthen cyber resilience, secure AI adoption and build trusted sovereign digital environments. With regional expertise and a customer-first approach, Help AG delivers end-to-end cybersecurity capabilities designed to protect critical operations, manage evolving risks and support secure digital transformation. Through continuous innovation, trusted partnerships and measurable outcomes, Help AG enables organisations to remain resilient, prepared and confident in a complex digital world.