We are seeking a highly motivated and detail-oriented Senior Security Administrator to join our Cybersecurity team. The candidate will be responsible for the end-to-end administration, monitoring, and optimization of the organization’s endpoint security, vulnerability management, patch management, and web security infrastructure.
This role will oversee the day-to-day operations, configuration, tuning, and lifecycle management of Antivirus, EDR/XDR, vulnerability assessment, patch management, and Secure Web Gateway/SASE platforms. The successful candidate will play a critical role in ensuring that endpoints, servers, and internet-facing traffic remain secure, compliant, and protected against evolving cyber threats.
- Administer, configure, and maintain Endpoint Detection and Response (EDR), Extended Detection and Response (XDR), and Antivirus platforms, including CrowdStrike Falcon and Trend Micro Apex One/Vision One, across desktops, servers, and cloud workloads.
- Monitor EDR/XDR and Antivirus consoles for malware detections, policy violations, and suspicious endpoint activities.
- Investigate, contain, and remediate security incidents involving compromised or infected endpoints.
- Manage agent deployment, health monitoring, tamper protection, policy enforcement, exclusions, and platform tuning to reduce false positives while maintaining optimal protection.
- Own and manage the complete vulnerability management lifecycle using Qualys VMDR, including asset discovery, authenticated scanning, risk assessment, vulnerability prioritization, exception handling, and remediation tracking.
- Analyze vulnerabilities using CVSS, TruRisk, and other risk-based methodologies to prioritize remediation efforts.
- Coordinate with infrastructure and system administration teams to plan, schedule, and monitor operating system and third-party application patch deployments.
- Track patch compliance and ensure timely closure of critical and high-severity vulnerabilities within defined SLAs.
- Administer and maintain Secure Web Gateway and SASE platforms such as Forcepoint Web Security and Fortinet FortiSASE.
- Configure and manage URL filtering, web content controls, SSL inspection policies, internet access governance, and application access policies.
- Implement and maintain Zero Trust Secure Access (ZTSA/ZTNA) policies to enforce identity-based, least-privilege access for remote and hybrid users.
- Investigate web security incidents, including malicious URL access, command-and-control (C2) communications, and policy circumvention attempts, and coordinate remediation activities.
- Generate dashboards, executive reports, and operational metrics related to endpoint security health, vulnerability posture, patch compliance, and web security.
- Perform regular platform health checks, upgrades, configuration reviews, and license management activities.
- Support internal and external audits, regulatory assessments, and compliance reviews related to endpoint, vulnerability, and web security controls.
- Develop, maintain, and continuously improve security SOPs, operational runbooks, and incident response playbooks.
- Coordinate with vendors and OEM support teams for issue resolution, product upgrades, and escalations.
- Participate in on-call and rotational shift support to ensure continuous 24×7 security operations coverage.
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- 3-6 years of hands-on experience in endpoint security, vulnerability management, patch management, and web security administration.
- CrowdStrike Falcon
-
Trend Micro Apex One, Vision One, and Deep Security
- Qualys VMDR, TruRisk, and CyberSecurity Asset Management (CSAM)
-
WSUS or equivalent patch management solutions
- Forcepoint Web Security
-
Fortinet FortiSASE
-
Zero Trust Secure Access (ZTSA/ZTNA)
- Strong understanding of Windows and Linux/Unix security administration
-
Working knowledge of networking concepts and protocols
-
Familiarity with cloud security controls in Azure and AWS environments
-
Knowledge of malware analysis fundamentals, Indicators of Compromise (IOCs), and endpoint forensics
-
Strong understanding of CVEs, CVSS scoring, vulnerability prioritization, and risk-based remediation strategies
- Strong analytical and problem-solving abilities.
-
Excellent troubleshooting and incident resolution skills.
-
Effective verbal and written communication skills.
-
Ability to collaborate across technical and business teams.
-
Strong organizational skills with the ability to manage multiple priorities.
-
High level of ownership, accountability, and attention to detail.
-
Flexibility to work in rotational shifts supporting a 24×7 operational environment.
- CrowdStrike Certified Falcon Administrator (CCFA)
-
Trend Micro Certified Professional
-
Qualys Certified Specialist (VM/VMDR)
-
CompTIA Security+
-
EC-Council Certified Incident Handler (ECIH)
-
EC-Council Certified SOC Analyst (CSA)