Apply now »

EY-Cybersecurity-Endpoint Security And Endpoint Management-Manager

Location:  Kochi
Other locations:  Anywhere in Country
Salary: Competitive
Date:  Sep 28, 2026

Job description

Requisition ID:  1746190

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. 

 

 

 

 

EY –Cybersecurity Manager, Endpoint Security & Endpoint Management

Overview

As a Manager in EY’s Cybersecurity practice, you will play a key role in delivering Endpoint Security, Endpoint Protection Platform (EPP), Endpoint Detection & Response (EDR/XDR), Mobile Device Management (MDM), Endpoint Privilege Management, Vulnerability and Patch Management, and Email Security services across multiple client environments. We are seeking cybersecurity professionals with experience across such as Microsoft Defender for Endpoint, Symantec Endpoint Security, CrowdStrike Falcon, SentinelOne Singularity, Palo Alto Cortex XDR, Trend Micro Vision One, Trellix Endpoint Security, Broadcom Carbon Black, Microsoft Intune, Ivanti Endpoint Manager/MobileIron,, Microsoft Defender for Office 365.

The role involves implementing, administering, monitoring, and optimizing endpoint protection technologies to safeguard enterprise devices, mobile endpoints, and email communication channels. The successful candidate will work closely with cybersecurity, infrastructure, workplace, cloud, and security operations teams to improve endpoint security posture and cyber resilience.

 

The Opportunity

We are seeking cybersecurity professionals with 12+ years of experience in Endpoint Security, Endpoint Management, EDR Operations, Device Management, Email Security, or Cybersecurity Consulting.

The ideal candidate will possess strong technical expertise in endpoint protection, threat detection and response, attack surface reduction, device compliance management, email security controls, and security operations.

 

Key Responsibilities

Endpoint Security Operations

  • Deploy, administer, and manage endpoint security solutions such as Microsoft Defender, Symantec Endpoint Security, CrowdStrike Falcon, SentinelOn and Symantec Endpoint Security.
  • Configure malware protection, antivirus, anti-ransomware, endpoint hardening, and attack surface reduction controls.
  • Monitor endpoint security alerts and investigate suspicious activities.
  • Manage endpoint security policies and protection baselines.
  • Support patching validation, endpoint compliance monitoring, and security posture improvement initiatives.
  • Conduct endpoint threat analysis and support remediation activities.
  • Collaborate with security operations teams during cybersecurity investigations.

 

Endpoint Detection & Response (EDR)

  • Administer and manage Broadcom Carbon Black EDR solutions.
  • Investigate endpoint threats, suspicious processes, malware activity, and indicators of compromise.
  • Perform threat hunting and endpoint forensic analysis.
  • Develop and tune detection rules, watchlists, and response workflows.
  • Support incident containment, eradication, and recovery activities.
  • Analyze attack techniques and map findings to MITRE ATT&CK tactics and techniques.
  • Support major cybersecurity incidents and security investigations.

 

Mobile Device Management (Microsoft Intune)

  • Administer Microsoft Intune for enterprise device management.
  • Configure device enrollment, compliance policies, and conditional access integrations.
  • Implement and manage mobile application management (MAM) policies.
  • Support management of Windows, macOS, iOS, and Android devices.
  • Configure endpoint compliance controls and device security baselines.
  • Implement device hardening and endpoint protection controls.
  • Support secure remote workforce and Bring Your Own Device (BYOD) initiatives.
  • Troubleshoot device configuration and policy deployment issues.

 

Email Security Operations

  • Administer Trend Micro Email Gateway security solutions.
  • Configure anti-malware, anti-spam, anti-phishing, and email content filtering policies.
  • Investigate phishing campaigns, business email compromise attempts, and malicious email activity.
  • Monitor email security alerts and policy violations.
  • Perform threat analysis on email-based attacks and suspicious attachments.
  • Tune email security controls to improve detection effectiveness and reduce false positives.
  • Support email security incident response activities.

 

Security Monitoring, Integration & Automation Tools

  • Integrate endpoint and email security telemetry with Microsoft Sentinel, Splunk Enterprise Security, IBM QRadar, Google Security Operations, or other SIEM platforms.
  • Develop automated investigation and response workflows using Microsoft Sentinel playbooks, Splunk SOAR, Palo Alto Cortex XSOAR, IBM Security SOAR, or ServiceNow Security Operations.
  • Use KQL, PowerShell, Python, Live Response, Sysinternals, Wireshark, and osquery for threat hunting, endpoint investigation, administration, and automation.

 

Endpoint Security Governance & Operations

  • Develop and maintain endpoint security standards, procedures, and operational runbooks.
  • Support endpoint security assessments and compliance reviews.
  • Generate endpoint security metrics, dashboards, and operational reports.
  • Collaborate with SOC, infrastructure, cloud, IAM, and workplace technology teams.
  • Participate in vulnerability remediation and security improvement initiatives.
  • Support endpoint lifecycle management and technology onboarding activities.
  • Contribute to process automation and operational efficiency improvements.

 

Skills and Attributes for Success

  • Strong understanding of Endpoint Protection Platforms (EPP) and Endpoint Detection & Response (EDR) technologies.
  • Experience with endpoint hardening malware protection, threat hunting, and incident response.
  • Knowledge of Microsoft Defender, Symantec Endpoint Security, and Carbon Black capabilities.
  • Understanding of Mobile Device Management (MDM) and Mobile Application Management (MAM).
  • Familiarity with Zero Trust, device compliance, conditional access, and endpoint governance.
  • Strong knowledge of Windows, macOS, iOS, and Android security controls.
  • Understanding of email security threats including phishing, malware, ransomware, and business email compromise.
  • Knowledge of cybersecurity frameworks such as NIST CSF, CIS Controls, MITRE ATT&CK, and ISO 27001.
  • Strong analytical, troubleshooting, and stakeholder management skills.

 

To Qualify for the Role, You Must Have

  • B. Tech, M. Tech, or equivalent degree in Cybersecurity, Computer Science, Information Security, or related disciplines.
  • 12+ years of relevant cybersecurity experience.
  • Hands-on experience with one or more of the following:
    • EPP/EDR/XDR: Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne Singularity, Palo Alto Cortex XDR, Trend Micro Vision One, Trellix Endpoint Security, Symantec Endpoint Security, or Broadcom Carbon Black
    • UEM/MDM: Microsoft Intune, VMware Workspace ONE, Ivanti Endpoint Manager/MobileIron, Jamf Pro, or Microsoft Configuration Manager
    • Email Security: Microsoft Defender for Office 365, Proofpoint, Mimecas, Cisco Secure Email, or Barracuda Email Protection
    • SIEM/SOAR and ITSM integrations: Microsoft Sentinel, Splunk, IBM QRadar, Google Security Operations, Cortex XSOAR.
  • Experience supporting endpoint security operations and incident response activities.
  • Understanding of endpoint hardening, threat detection, malware analysis, and device compliance management.
  • Familiarity with MITRE ATT&CK, endpoint attack techniques, and security monitoring concepts.
  • Strong verbal and written communication skills.
  • Experience with PowerShell, Python, KQL, automation, or scripting is an advantage.

 

What We Look For

Professionals who are passionate about endpoint security, threat detection, and cyber defense. Successful candidates will possess strong technical expertise, analytical thinking, and a proactive approach to identifying and responding to threats. A strong sense of ownership, customer focus, and commitment to delivering high-quality cybersecurity services will be key to success in this role.

 

 

EY | Building a better working world 


 
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.  


 
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.  


 
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.  

Apply now »