Responsibilities Design, deploy, and operate EPP/EDR/XDR for workstations, laptops, VDI, and supported servers Own endpoint detection logic, tuning, and response actions in coordination with SOC Define and enforce endpoint hardening standards and gold images Operate application allow‑listing, tamper