Sr. Cyber Security Analyst (MDE)

Societe Generale · Bengaluru

  • Experience5–7 yrs
  • SalaryNot disclosed
  • Work modeonsite
  • Levelsenior
  • Posted3 Sept 2026

About Societe Generale

Societe Generale is hiring in Bengaluru in financial services. This role looks for around 5+ years of experience.

Skills

  • Microsoft Defender for Endpoint
  • Microsoft Endpoint Configuration Manager
  • Group Policy
  • Microsoft Intune
  • Azure Arc
  • Defender Antivirus
  • Linux package management
  • Azure Automation
  • PowerShell
  • Bash
  • Azure DevOps
  • GitHub Actions
  • Microsoft Graph API
  • Attack Surface Reduction
  • Network Protection
  • Controlled Folder Access
  • Indicators of Compromise
  • Endpoint isolation
  • Incident response

The role

A cybersecurity analyst at a financial services company monitors security operations and investigates threats using Microsoft Defender for Endpoint. The role applies endpoint security and incident response to protect enterprise systems.

Full job description

The core responsibilities for the job include the following:

Server Onboarding and Offboarding (Windows and Linux):

Design and operate scalable onboarding processes:

Windows Server: MECM/SCCM, GPO, Intune, Azure Arc, and scripts; ensure the Sense EDR sensor and Defender Antivirus are properly configured (including passive mode transitions if a third-party AV is present).

Linux Server: Package-based installs (mdatp via apt/yum/zypper), onboarding scripts, repo configuration, proxy settings, and service validation.

Maintain golden images / AMIs with pre-onboarding steps, device tagging, and machine groups.

Operate offboarding flows (offboarding package/keys) for decom, M& A carve-outs, and cloud auto-scale lifecycles; reconcile stale/duplicate devices.

Track coverage: % of in-scope servers onboarded, health status, and remediation of inactive/unhealthy devices.

Policy, Exclusions and Hardening:

Define/maintain AV policies, EDR in block mode, Attack Surface Reduction (ASR) rules, network protection, and controlled folder access (where server-appropriate).

Implement file/path/process exclusions with risk-based justification, balancing performance and detection efficacy; perform periodic review, attestation, and removal of stale exceptions.

Manage Indicators of Compromise (IOCs), custom URL/domain/IP indicators, and controlled testing with robust change control.

Operations and Support:

Operate day-to-day MDE tool support: ticket queue, troubleshooting onboarding/health/AV conflicts, performance tuning, and sensor/engine update issues.

Partner with SOC/IR on incidents; drive endpoint containment, isolation support, evidence capture, and post-incident hardening actions.

Automation and Scale:

Build automation with PowerShell, Bash, Azure Automation, Azure DevOps/GitHub Actions, and M365 Defender/Graph APIs.