Blue Origin

Endpoint Security Engineer III

Blue Origin$130K — $182K *
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Systems, Computer Science, or equivalent experience.
  • 5+ years managing endpoint security tooling.
  • Hands-on experience with Microsoft Defender for Endpoint, including configuration and health management.
  • Experience with Tanium or similar endpoint management platforms.
  • Multi-platform proficiency on Windows, macOS, and Linux in endpoint security.
  • Strong scripting skills in PowerShell, Python, or Bash for automation.
  • Familiarity with NIST and ISO 27000-series standards.

Responsibilities

  • Lead endpoint detection and response across Windows, macOS, and Linux systems.
  • Monitor sensor health and rectify unmonitored endpoints proactively.
  • Manage endpoint antivirus policies while balancing security and engineering workload.
  • Write and maintain advanced hunting queries for security posture validation.
  • Configure and manage the enterprise endpoint management platform Tanium for security needs.
  • Identify and report security posture based on recognized benchmarks for compliance.
  • Document endpoint security processes to establish standard procedures.

Benefits

  • Medical, dental, and vision coverage.
  • Life insurance options, including supplemental coverage.
  • Paid parental leave and short/long-term disability benefits.
  • 401(k) plan with company match up to 5%.
  • Education Support Program to enhance professional development.
  • Eligible employees receive stock options.
  • Generous paid time off and company-paid holidays.
Full Job Description
Application close date:
Applications will be accepted on an ongoing basis until the requisition is closed.

As part of a small, accomplished team of experts, you will protect and secure the endpoints that Blue Origin's engineers, technicians, and business teams depend on every day. You will share in the team's impact on all aspects of endpoint security, and you will lead and assist with many aspects of operations and engineering on the Endpoint Experience team.

Security engineers evaluate, select, procure, implement, and operate security technology supporting enterprise and space systems. This role is the technical lead for our AV and EDR stack - Microsoft Defender for Endpoint and Tanium - and it is deliberately operating-system agnostic. You will be expected to reason about detection coverage, agent health, and security posture with equal fluency across all systems.

We are looking for someone to apply their technical expertise, leadership skills, and commitment to quality to positively impact safe human spaceflight. Passion for our mission and vision is required.

Responsibilities

Microsoft Defender for Endpoint
- Own endpoint detection and response coverage across the fleet: onboarding and offboarding, agent lifecycle, platform build currency, and tamper protection, on Windows, macOS, and Linux.
- Monitor and remediate sensor health, and continuously reconcile Defender coverage against authoritative inventory so that unmonitored endpoints are found and fixed rather than discovered during an incident.
- Manage antivirus and protection policy - scan behavior, definition currency, at tack surface reduction rules, exclusions, and platform-specific configuration - balancing security outcome against engineering workload impact.
- Write and maintain advanced hunting queries to answer posture and exposure questions, and understand the limits of what endpoint telemetry can and cannot show.
- Operate diagnostic tooling (client analyzers and equivalent) and drive vendor cases to resolution when platform defects affect the fleet.
- Act on security recommendations and vulnerability findings surfaced by the platform, prioritizing by real exposure rather than raw score.

Tanium
- Own the architecture, configuration, and operation of the enterprise endpoint management and security platform, including content, permissions, and shared services.
- Author and maintain platform content - sensors, packages, and saved questions - that returns correct answers across every supported operating system, including multi-distribution Linux.
- Design and maintain the role-based access model: roles, personas, user groups, computer groups, and filter groups, scoped to least privilege across multiple consuming organizations.
- Configure action groups and targeting tiers so that change lands predictably and progressively across the fleet.
- Use the platform as the fleet's measurement and remediation instrument: build the content that reports security posture and closes the gap between "we have a policy" and "we can prove it is applied."

Posture reporting, requirements, and documentation
- Instrument the fleet to report security posture against recognized benchmarks (CIS, DISA STIG) and to evidence control implementation for compliance obligations, including NIST 800-series and ISO 27000-series requirements.
- Report on the state of adjacent security controls owned by partner engineers - including disk encryption and device control - using Defender and Tanium telemetry, so that coverage gaps are visible without duplicating ownership of those platforms.
- Build platform content and collectors that triage endpoint and application performance problems - crashes, driver faults, and degradation - and attribute them to a responsible component, so that fleet-wide issues are diagnosed from evidence rather than anecdote.
- Work with engineering and development groups to provide endpoint security requirements for new applications and systems.
- Document processes and procedures relating to endpoint security technologies, at a standard others can execute from.
- Contribute to the endpoint security roadmap and to best practices at the department level.

Technical leadership
- Contribute to the strategy of endpoint security within the team; independently determine and develop technical plans for complex problems and use technical judgement to select methods and techniques best suited to the problem.
- As a senior member of the team, mentor other team members on security technologies and standards.
- Review the work of other team members and be accountable for technical analysis within your discipline.
- Interface effectively with all levels of the organization, up to and including executive staff, as well as external customers and vendors.
- Work closely with the Cyber Security Threat Operations team and partner IT teams to build and maintain endpoint security technologies.
- Regular participation in on-call rotation.
- Available to support flexible work hours to support various organizational objectives.

Qualifications

- Minimum of a bachelor's degree in Information Systems, Computer Science, or equivalent practical experience.
- 5+ years performing deployments and managing endpoint security tooling.
- Hands-on engineering experience operating an enterprise antivirus and endpoint detection and response stack at fleet scale. Microsoft Defender for Endpoint strongly preferred, including onboarding, antivirus and ASR policy configuration, sensor health management, and advanced hunting.
- Hands-on administration and engineering experience with an enterprise endpoint management platform. Tanium strongly preferred.
- Familiarity with endpoint encryption, and with application performance monitoring and troubleshooting.
- Genuine multi-platform depth. Demonstrated ability to administer, instrument, and troubleshoot security tooling on Windows, macOS, and Linux - not deep expertise in one with passing familiarity with the others. Candidates should be able to speak to endpoint security work they have personally done on all three.
- Demonstrated experience executing a platform migration or major version cutover: planning, phased execution, validation, and operational handoff.
- Strong scripting and automation skills across platforms - PowerShell, Python, and/or Bash - to optimize for consistency and efficiency.
- Familiarity with host, network, and cloud-based security technologies.
- Experience with NIST 800-series standards, including 800-30, 800-53, 800-82, and 800-171.
- Experience with ISO 27000-series standards.
- Active Directory and Entra ID concepts as they apply to endpoint identity, scoping, and access.
- Ability to interface with all levels of an organization up to the executive staff and external customers.
- Ability to earn trust, maintain positive and professional relationships, and contribute to a culture of inclusion.
- Ability to convey technical information to technical and non-technical users, and to document epics, stories, and tasks in the enterprise ticketing system.

Desired
- Applicable security certifications - CISSP, GIAC certifications, CISM, CISA, or Security+.
- Experience operating security platforms in a FedRAMP, GCC High, or otherwise accredited cloud environment.
- Experience with Microsoft Intune for endpoint security policy delivery.
- Experience authoring Tanium sensors for Linux across multiple distributions, and an understanding of why cross-platform content is harder than it looks.
- Experience with CMMC-driven control implementation and CUI handling requirements.
- Experience with security automation and orchestration, and with platform APIs for programmatic administration.
- Understanding of incident response processes and the role endpoint telemetry plays in them.
- Experience supporting engineering or manufacturing workstation fleets with specialized hardware and software requirements.
- Exposure to infrastructure-as-code and configuration management (Ansible or equivalent).
- Experience mentoring engineers and raising the operational maturity of a platform beyond single-owner dependency.

Export Control Regulations

Applicants for employment at Blue Origin must be a U.S. citizen or national, U.S. permanent resident (i.e. current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.

Base Pay Range for:
WA applicants is $130,706.00 - $182,987.70

Other site ranges may differ

Culture Statement

Don't meet all desired requirements? Studies have shown that some people are less likely to apply to jobs unless they meet every single desired qualification. At Blue Origin, we are dedicated to building an authentic workplace, so if you're excited about this role but your past experience doesn't align perfectly with every desired qualification in the job description, we encourage you to apply anyway. You may be just the right candidate for this or other roles.

Export Control Regulations

Applicants for employment at Blue Origin must be a U.S. citizen or national, U.S. permanent resident (i.e. current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.

Benefits
  • Benefits include: Medical, dental, vision, basic and supplemental life insurance, paid parental leave, short and long-term disability, 401(k) with a company match of up to 5%, and an Education Support Program.
  • Stock Options for all regular employees (working at least 20 hours/week)
  • Paid Time Off: Up to four (4) weeks per year based on weekly scheduled hours, and up to 14 company-paid holidays.
  • Dependent on role type and job level, employees may be eligible for benefits and bonuses based on the company's intent to reward individual contributions and enable them to share in the company's results, or other factors at the company's sole discretion. Bonus amounts and eligibility are not guaranteed and subject to change and cancellation. Please check with your recruiter for more details.


About Blue Origin

Blue Origin is an aerospace company that develops rockets and spacecraft for commercial and government customers. The company's products include the New Shepard suborbital vehicle and the New Glenn orbital rocket. Blue Origin was founded in 2000 by Jeff Bezos and is headquartered in Kent, Washington.
Learn more about Blue Origin
Size
3,000 employees
Industry
Founded
2000

Similar Jobs

More Jobs at Blue Origin

More Aerospace & Defense Jobs

Find similar Endpoint Security Engineer III jobs: