EDR & Cloud Security Support (End point detection and response)

Atos

Cyberjaya

On-site

MYR 70,000 - 110,000

Full time

48 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Atos in Malaysia is seeking a cybersecurity specialist to monitor and respond to EDR/XDR alerts across endpoints and cloud platforms. You will investigate incidents, coordinate remediation, and ensure SLAs are met.

The role requires 3–5+ years in EDR/endpoint security or SOC operations, hands-on with Defender platforms, and solid knowledge of Azure/AWS/GCP security and cloud identity.

Qualifications

  • 3–5+ years in EDR, endpoint security, cloud security, or SOC operations.
  • Hands-on with Microsoft Defender for Endpoint or Defender XDR.
  • Knowledge of endpoint telemetry and investigation techniques.
  • Experience investigating malware, ransomware, PowerShell activity, and endpoint compromise.
  • Understanding of Azure security and Microsoft Entra ID.
  • Knowledge of Microsoft Defender for Cloud.
  • Understanding cloud IAM, networking, and security logging.

Responsibilities

  • Monitor and investigate EDR/XDR alerts and incidents.
  • Perform endpoint investigations of processes, files, hashes, and network activity.
  • Investigate malware, ransomware, PowerShell activity, and credential abuse.
  • Perform endpoint isolation, remediation, and response actions.
  • Review sensor status and protection health.
  • Troubleshoot EDR deployment and telemetry issues.
  • Coordinate remediation with SOC, infra, and endpoint teams.
  • Track unresolved EDR issues to closure within SLAs.
  • Monitor and investigate security alerts across Azure, AWS, and GCP.
  • Support Microsoft Defender for Cloud and cloud security monitoring.
  • Investigate cloud authentication, privilege escalation, and anomalous activity.
  • Monitor cloud posture, alerts, identities, and configurations.
  • Support logging and integration with SIEM platforms.

Skills

EDR/XDR monitoring
Endpoint security
Cloud security
SOC operations
Incident response

Tools

Microsoft Defender for Endpoint
Defender XDR
Microsoft Defender for Cloud
Microsoft Sentinel
KQL (Kusto)
Azure

Job description

Responsible for monitoring, administration, troubleshooting, investigation, and operational support of EDR/XDR and cloud security platforms. The role ensures endpoint and cloud threats are detected, investigated, escalated, and remediated within defined service-level agreements.

Key Responsibilities
  • Monitor and investigate EDR/XDR alerts and incidents.
  • Perform endpoint investigations covering processes, command lines, files, hashes, network connections, and user activity.
  • Investigate malware, ransomware, suspicious PowerShell activity, persistence, lateral movement, and credential-related activity.
  • Perform endpoint isolation, remediation, and other approved response actions.
  • Review endpoint health, sensor or agent status, and protection status.
  • Troubleshoot EDR agent deployment, connectivity, policy, and telemetry issues.
  • Support EDR policy configuration, exclusions, and alert tuning.
  • Coordinate with SOC, infrastructure, and endpoint teams to complete remediation.
  • Track unresolved EDR issues and ensure closure within agreed SLAs.
  • Monitor and investigate security alerts across Azure, AWS, and GCP, as applicable.
  • Support Microsoft Defender for Cloud and broader cloud security monitoring.
  • Investigate suspicious cloud authentication, privilege escalation, resource changes, and anomalous activity.
  • Monitor cloud security posture, recommendations, security alerts, identities, network activity, resources, and security configurations.
  • Support investigations involving Microsoft Entra ID identity and authentication events.
  • Coordinate remediation of cloud security findings with cloud and platform teams.
  • Assist with cloud security incident response and root-cause analysis.
  • Support cloud security logging and integration with SIEM platforms.
Required Qualifications and Experience
  • 3–5+ years of experience in EDR, endpoint security, cloud security, or SOC operations.
  • Hands-on experience with Microsoft Defender for Endpoint, Defender XDR, or an equivalent EDR/XDR platform.
  • Good understanding of endpoint telemetry and investigation techniques.
  • Experience investigating malware, ransomware, suspicious PowerShell activity, suspicious processes, and endpoint compromise.
  • Good understanding of Azure security and Microsoft Entra ID.
  • Working knowledge of Microsoft Defender for Cloud.
  • Good understanding of cloud identity and access management, networking, security controls, and logging.
  • Ability to perform technical troubleshooting and security investigations.
  • Good understanding of incident management, escalation, and SLA processes.
Preferred Qualifications
  • Experience with AWS or GCP security.
  • Knowledge of Defender for Identity, Defender Vulnerability Management, and Microsoft Intune.
  • Experience with Microsoft Sentinel and Kusto Query Language.
  • Knowledge of cloud security posture management and cloud workload protection platform concepts.
  • Experience with EDR platforms such as Trellix, CrowdStrike, SentinelOne, or Palo Alto Cortex XDR.
  • Knowledge of MITRE ATT&CK and threat hunting.
  • Understanding of cloud security frameworks and CIS benchmarks.
Preferred Certifications

SC-200, AZ-500, AZ-104, GCIH, or CompTIA Security+.

Key Success Measures
  • Timely investigation and resolution of EDR and cloud security alerts.
  • Improved endpoint and cloud security health and coverage.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

EDR & Cloud Security Operations Specialist
EDR & Cloud Security Operations Specialist

Atos • Cyberjaya

On-site
MYR 70,000 - 110,000
Security Operations Engineer
Security Operations Engineer

QI Group • Petaling Jaya

On-site
MYR 60,000 - 100,000
Security Delivery Consultant
Security Delivery Consultant

ABP Group • Kuala Lumpur

On-site
MYR 120,000 - 170,000
SOC Senior analyst
SOC Senior analyst

Atos • Cyberjaya

On-site
MYR 60,000 - 120,000
EndPoint Security Subject Matter Expert
EndPoint Security Subject Matter Expert

DXC Technology • Petaling Jaya

On-site
MYR 120,000 - 180,000
DXC University
Flexible leave options
Volunteer days
Senior IT Security Consultant
Senior IT Security Consultant

Radii Global • Subang Jaya

On-site
MYR 120,000 - 160,000
SOC Specialist
SOC Specialist

Pride Global • Cyberjaya

On-site
MYR 120,000 - 180,000
Senior Cloud Vulnerability Management & DevSecOps I IT Security
Senior Cloud Vulnerability Management & DevSecOps I IT Security

Maybank • Kuala Lumpur

On-site
MYR 180,000 - 320,000
Senior Manager, Digital Security
Senior Manager, Digital Security

AIA Hong Kong and Macau • Cyberjaya

On-site
MYR 120,000 - 160,000
Competitive salary
Health insurance
Professional development opportunities
SOC Specialist
SOC Specialist

Atos • Cyberjaya

On-site
MYR 120,000 - 180,000