Summary: Triangle Cyber is seeking an Endpoint Security Engineer for a federal client to design, deploy, and operationalize active, behavior-based endpoint detection and response capabilities across a large enterprise network. Leveraging platforms like CrowdStrike Falcon, Microsoft Defender, SentinelOne, and Splunk, you will play a pivotal role in safeguarding this expansive network.
Responsibilities:- Engineer, deploy, and maintain Next-Gen Antivirus (NGAV) and Endpoint Detection & Response (EDR/XDR) agents across a diverse range of endpoints.
- Implement behavioral protections against zero-day malware and advanced persistent threats.
- Collaborate with application owners and business units to establish baseline behavior profiles.
- Manage allowlisting, exception workflows, and phased ring deployments to ensure seamless protection.
- Support SOC investigations and collaborate with system owners for enterprise security.
Requirements:- U.S. Citizenship required.
- 8+ years of relevant experience in cybersecurity engineering or infrastructure security roles.
- Experience with enterprise-grade EDR/XDR platforms (CrowdStrike Falcon, Microsoft Defender, and/or SentinelOne SIEM) across extensive endpoint environments
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or equivalent experience (17 years total).
- Proficiency in administering endpoint platforms across various operating systems.
- Expertise in behavioral analysis, threat hunting, and using query languages like SQL, KQL, and YARA.
- Strong programming skills in PowerShell, Python, or Bash for automation.
- Fluency in using AI/ML technologies to automate security activities.
- Ability to balance security controls with business operations, ensuring minimal disruption.
- Experience in crisis leadership, operational scale management, and policy automation.
Preferred:- GIAC Certified Enterprise Defender (GCED), GCIH, or GCFA certification.
- CISSP certification.
- Vendor-specific credentials, such as CrowdStrike Certified Falcon Administrator or Microsoft Certified: Security Operations Analyst Associate.