Estuate - IT Security Analyst I - Endpoint & Identity Threat Protection

Estuate, Inc.

Hyderabad

On-site

INR 1,200,000 - 1,800,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Mattel is seeking a Sr Security Engineer for Endpoint & Identity Threat Protection to design, deploy, and optimize advanced detection and response across global environments.

You will own proactive detection, automation, and threat protection strategies, collaborating with Security Operations, IT, and Architecture teams to strengthen cyber defense and ensure policy compliance.

Qualifications

  • 5+ years in cybersecurity engineering focused on endpoint and identity protection.
  • Experience with enterprise EDR/ITP platforms (CrowdStrike, SentinelOne, Defender for Endpoint).
  • Strong knowledge of Windows, macOS, Linux and attacker TTPs.
  • Experience integrating endpoint/identity protection with SIEM/SOAR.
  • Familiarity with IAM frameworks (Azure AD, Okta, SSO, MFA).

Responsibilities

  • Engineer, deploy, and optimize EDR and ITP platforms across enterprise environments.
  • Tune detection logic and behavioral rules to reduce false positives.
  • Collaborate with SOC and IR teams to investigate and remediate incidents.
  • Integrate EDR/ITP with SIEM, SOAR, and threat intel platforms.
  • Develop automation and playbooks for security operations.
  • Support secure configuration management and policy enforcement across endpoints.
  • Document workflows and participate in post-incident reviews.
  • Evaluate new endpoint/identity technologies and support PoCs.

Skills

EDR
Identity Threat Protection
Cloud/Hybrid security
Windows/Linux/macOS
Scripting (PowerShell/Python)
IAM (Azure AD/Okta/SSO/MFA)
SIEM/SOAR integration
Threat Intelligence

Education

Bachelor's degree in CS or Information Security

Tools

CrowdStrike
SentinelOne
Defender for Endpoint
Azure AD
Okta
Python
PowerShell

Job description

Job Description

The Sr Security Engineer Endpoint & Identity Threat Protection (EDR / ITP) is responsible for engineering, deploying, and optimizing advanced detection and response technologies that safeguard Mattel's global enterprise. This senior technical role focuses on proactive endpoint detection, response automation, and identity threat protection, helping to strengthen the organization's cyber defense posture. The position requires deep technical expertise across endpoint and identity protection technologies, strong collaboration skills, and a commitment to continuous improvement through automation, analytics, and security modernization initiatives.

Roles and Responsibilities
  • Engineer, deploy, and maintain enterprise Endpoint Detection and Response (EDR) and Identity Threat Protection (ITP) platforms across Mattel's environments.
  • Develop, tune, and optimize behavioral analytics and detection logic to identify, prevent, and respond to malicious activity targeting endpoints and identities.
  • Collaborate with Security Operations and Incident Response teams to investigate, contain, and remediate security incidents effectively and efficiently.
  • Integrate EDR and ITP technologies with SIEM, SOAR, and threat intelligence platforms to improve visibility, automation, and response capabilities.
  • Contribute to the architecture, implementation, and continuous enhancement of endpoint and identity threat protection strategies in alignment with Mattel's cybersecurity goals.
  • Partner with IT, Infrastructure, and Security Architecture teams to support secure configuration management, policy enforcement, and system hardening across all endpoints.
  • Ensure endpoint and identity protection controls align with corporate security policies, compliance mandates, and global regulatory standards.
  • Perform advanced telemetry analysis, detection validation, and post-incident investigations to improve detection fidelity and reduce false positives.
  • Collaborate with Engineering, Cloud, and Infrastructure teams to ensure endpoint tools operate effectively across hybrid and cloud environments.
  • Develop and maintain documentation, operational standards, and playbooks for endpoint and identity threat protection workflows.
  • Participate in post-incident reviews to identify gaps, lessons learned, and opportunities to enhance security processes.
  • Evaluate emerging endpoint and identity threat protection technologies and contribute to technical proof-of-concept initiatives to support security.
Required
  • 5 - 7+ years of experience in cybersecurity engineering, with a focus on endpoint and identity threat protection in enterprise environments.
  • Demonstrated expertise managing enterprise-grade EDR and ITP platforms such as CrowdStrike, SentinelOne, Defender for Endpoint, or similar solutions.
  • Strong technical knowledge of endpoint operating systems (Windows, macOS, Linux) and adversary tactics, techniques, and procedures (TTPs).
  • Experience designing and optimizing detection logic, behavioral rules, and custom correlation within EDR and identity systems.
  • Proficiency in integrating endpoint and identity threat protection solutions with SIEM, SOAR, and automation platforms.
  • In-depth understanding of identity and access management (IAM) frameworks such as Azure AD, Okta, SSO, and MFA.
  • Experience in IOC and IOA analysis, enrichment, and use of threat intelligence for proactive defense and detection tuning.
  • Hands‑on experience in scripting or automation using PowerShell, Python, or equivalent languages for workflow orchestration and data enrichment.
  • Strong understanding of endpoint configuration, policy management, application allowlisting, and device control.
  • Excellent communication and collaboration skills with the ability to work effectively across global and cross‑functional teams.
Preferred
  • Bachelor's degree in computer science, Information Security, or a related field (or equivalent experience).
  • Certifications such as GSEC, SSCP, GCED, GCIA, or CompTIA CySA+.
  • Experience supporting hybrid endpoint environments across on‑premises, cloud (AWS, Azure, GCP), and virtualized systems.
  • Familiarity with the MITRE ATT&CK framework for mapping detections, validating coverage, and improving response maturity.
  • Hands‑on experience with SOAR or orchestration platforms to enhance threat detection and response workflows.
  • Knowledge of modern endpoint protection trends, AI/ML‑based detection models, and zero‑trust security principles.

(ref:hirist.tech)

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Security DAP
Sr Security DAP

Mattel, Inc. • Hyderabad

On-site
INR 1,800,000 - 3,200,000
Endpoint Security Engineer
Endpoint Security Engineer

India Fan Corporation • Hyderabad

On-site
INR 1,800,000 - 2,800,000
Endpoint Engineer
Endpoint Engineer

VAYUZ Technologies • India

On-site
INR 900,000 - 1,500,000
Security Engineer / Cybersecurity Specialist
Security Engineer / Cybersecurity Specialist

Codvo.ai • India

On-site
INR 1,200,000 - 2,000,000
Security Assesments - Architect
Security Assesments - Architect

Mattel • Hyderabad

On-site
INR 4,200,000 - 6,000,000
Security Engineer
Security Engineer

Etched • Bengaluru

On-site
INR 2,000,000 - 4,000,000
Security Engineer / Analyst
Security Engineer / Analyst

Lodha • Mumbai City

On-site
INR 1,200,000 - 1,800,000
MEDR Threat Engineer US work hours
MEDR Threat Engineer US work hours

PROFICIO • India

On-site
INR 1,500,000 - 2,100,000
Meals reimbursement
Gym reimbursement
Internet reimbursement
+1
Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000
Senior Cybersecurity Endpoint Security and Infrastructure Security (EDR and
Senior Cybersecurity Endpoint Security and Infrastructure Security (EDR and

AT&T • India

On-site
INR 1,800,000 - 3,000,000