ATP Server Security Operations Analyst
Deloitte Technology Information Technology Posted: 19-Sep-2025
Hermitage, Tennessee, United States
Nashville, Tennessee, United States
Tampa, Florida, United States
Work you'll do
We are looking for an Advance Threat Protection Server Security Operations Analyst to join our Deloitte Global Team.
Key Responsibilities:
- Operational Support: Provide 4th level support for incidents and requests related to endpoint health, including on-call work when required.
- Ticket Management: Monitor and handle tickets assigned to your support queues and be available to support any related major incidents.
- Product Expertise: Develop a deep understanding of the endpoint protection products you will be managing.
- Documentation: Create and maintain knowledge base documents and playbooks outlining end-to-end support procedures and inter-team workflows.
- Change Management: Support change management activities for product upgrades within the production environment, collaborating with in-house teams and third parties to ensure successful implementation.
- Escalation Response: Respond to escalations from Security Policy Management, GNOC, SOC, and Member Firms, assisting them with understanding endpoint protection products and support processes.
- Testing and Ad-Hoc Duties: Assist the technical lead/architect and security analyst in testing product upgrades and perform other job-related duties as assigned.
The team
Qualifications
Required Qualifications:
- Experience with configuration and deployment of endpoint protection platforms (e.g., CrowdStrike, McAfee, Microsoft).
- Strong working knowledge of server operating systems (Windows Server 2016, 2019, 2022, Linux – REHL, SUSE, Ubuntu) or Microsoft Defender for EndPoint
- Working knowledge of computer networking (firewalls, routing, etc.)
- Knowledge of configuration, policy, and event workflows and playbooks.
- Experience with Python and PowerShell scripting.
- Experience in supporting security tools (e.g., anti-virus, host intrusion detection).
- Experience working within a service management framework (e.g., ITIL).
- Knowledge of Security Information and Event Management (SIEM) tools.
- Understanding of SCCM and BigFix