🎁 Before you apply, rehearse this interview. Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card. I want my training →
JD for MSS Analyst (EDR/DLP) Location - Gurgaon Job Summary We are looking for a proactive and technically skilled Cyber Security Analyst (L1/L1.5) with hands-on exposure to Data Loss Prevention (DLP), Endpoint Detection & Response (EDR)/Antivirus (AV), and Network Access Control (NAC) technologies. The candidate will be responsible for monitoring security alerts, performing initial investigations, handling endpoint and policy-related incidents, and supporting day-to-day security operations. The role requires good analytical skills, understanding of cybersecurity fundamentals, and the ability to troubleshoot security incidents with minimal supervision. Key Responsibilities EDR / Antivirus Operations Monitor EDR/AV console for malware, suspicious activities, IOC detections, and endpoint threats. Perform basic threat investigation and endpoint analysis. Isolate/quarantine endpoints when required based on standard procedures. Validate malware alerts, suspicious files, and endpoint behavior. Assist in IOC blocking, endpoint remediation, and policy management. Ensure endpoint agent health and AV signature updates across systems. DLP Operations Monitor and analyze DLP alerts/incidents related to email, endpoint, web, USB, and cloud channels. Perform initial triage and validation of DLP incidents. Investigate policy violations and escalate genuine incidents as per SOP. Assist in DLP policy tuning, whitelisting, and false-positive reduction. Coordinate with users/business teams for incident validation and closure. Maintain incident documentation and reporting. Required Skills Technical Skills Basic understanding of: o DLP concepts and incident handling o EDR/XDR and Antivirus technologies o Windows OS, Active Directory, networking fundamentals o TCP/IP, DNS, DHCP, VPN, proxy basics Hands-on experience with any security tools such as: o DLP: Forcepoint, Trellix DLP etc. o EDR/AV: Trellix, CrowdStrike, Defender, SentinelOne, Cortex XDR, etc. Understanding of security incidents, malware behavior, and phishing analysis. Basic knowledge of SIEM tools and log analysis is preferred. Compensation: 600,000.00 - 750,000.00 per year Benefits: Provident Fund Application Question(s): How many years of experience you have in Cyber Security Do you have any experience in EDR-DLP What is your Notice Period What is your Current CTC What is your Expected CTC Work Location: In person .