Journeyman Endpoint Engineer

SpecPro Sustainment and Environmental, LLC

$90K — $110K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-5 years in endpoint administration or related enterprise engineering activities.
  • Active DoD Secret security clearance required.
  • DoD IAT Level II-compliant certification needed.
  • Hands-on experience with endpoint-management and software-deployment technologies.
  • Knowledge of Microsoft Defender for Endpoint or similar EDR technologies.
  • Experience troubleshooting endpoint connectivity and configuration issues.
  • Familiarity with endpoint encryption technologies like BitLocker and FileVault.

Responsibilities

  • Deploy and configure Microsoft Defender for Endpoint on various operating systems.
  • Maintain endpoint onboarding packages, scripts, and configurations.
  • Monitor endpoint health and remediate issues during onboarding.
  • Remove legacy Trellix agents after successful Defender deployment.
  • Manage disk encryption configuration and validation processes.
  • Troubleshoot deployment and endpoint-security issues effectively.
  • Coordinate with various teams to address migration and operational challenges.

Benefits

  • Paid holidays and paid time off, including sick and vacation leave.
  • Medical, dental, and vision insurance.
  • Flexible spending accounts.
  • Short and long-term disability insurance.
  • Company paid life insurance.
  • 401(k) plan with company match and discretionary profit sharing.
  • Tuition reimbursement program.
Full Job Description
Eagle Integrated Services (EIS) is seeking a Journeyman Endpoint Engineer to support the enterprise migration and implementation of Microsoft Defender for Endpoint across approximately 3,000 Windows, macOS, and Linux endpoints at the Uniformed Services University of the Health Sciences (USUHS).

The Journeyman Endpoint Engineer will serve as a hands-on technical resource responsible for endpoint onboarding, security-agent migration, configuration, troubleshooting, and the controlled removal of legacy Trellix technologies. This position will leverage enterprise endpoint-management and automation technologies to execute the migration efficiently while minimizing disruption to users and mission operations.

What You'll Do:
  • Deploy and configure Microsoft Defender for Endpoint across Windows, macOS, and Linux devices using automated deployment methods and enterprise endpoint-management tools.
  • Develop, execute, and maintain deployment packages, scripts, policies, and configurations supporting enterprise endpoint onboarding.
  • Monitor endpoint enrollment, agent health, connectivity, and security telemetry and remediate devices that fail to onboard or report correctly.
  • Execute the controlled removal of legacy Trellix security agents following successful Defender implementation and validation and support decommissioning of the legacy Trellix/ePO environment.
  • Configure and validate native disk encryption, including BitLocker for Windows and FileVault for macOS, and verify encryption status and recovery-key escrow before removing applicable legacy technologies.
  • Troubleshoot endpoint-security and deployment issues, including agent conflicts, installation failures, connectivity problems, policy conflicts, and operating-system-specific configuration issues.
  • Support macOS security requirements, including applicable system and security extensions, and Linux Defender deployment using shell scripting and Linux system-management tools.
  • Maintain compliance with applicable DISA STIGs and DoD cybersecurity requirements across managed endpoints.
  • Test and validate endpoint configurations and support phased deployment activities, including pilot groups, production migration, exception handling, and remediation.
  • Track endpoint onboarding, migration, and remediation progress and provide status information supporting the master project schedule.
  • Develop and maintain SOPs, deployment procedures, troubleshooting guides, configuration documentation, and operational playbooks.
  • Coordinate with cybersecurity, infrastructure, service desk, and engineering personnel to resolve endpoint migration and operational issues.

What You Bring:

Required:
  • 3-5 years of experience supporting endpoint administration, software distribution, endpoint security, or related enterprise engineering activities.
  • Active DoD Secret security clearance.
  • Current DoD IAT Level II-compliant certification, as applicable to current DoD requirements.
  • Hands-on experience with enterprise endpoint-management and software-deployment technologies.
  • Experience supporting Windows endpoint configuration and administration.
  • Experience deploying, configuring, and troubleshooting endpoint-security agents or similar enterprise software.
  • Working knowledge of Microsoft Defender for Endpoint or comparable endpoint detection and response (EDR) technologies.
  • Experience troubleshooting endpoint connectivity, software installation, policy, and configuration issues.
  • Familiarity with endpoint encryption technologies, including BitLocker and/or FileVault.
  • Working knowledge of cybersecurity configuration and compliance requirements in Federal or DoD environments.
  • Ability to develop technical documentation and effectively communicate technical issues with engineering and operational teams.

Preferred:
  • Experience with Microsoft Configuration Manager (SCCM/MECM) and/or Microsoft Intune.
  • Experience administering Microsoft Defender for Endpoint in an enterprise environment.
  • Experience supporting macOS through JAMF or another enterprise MDM platform.
  • Experience with Linux administration and Bash/shell scripting.
  • Experience with Trellix ePO, Trellix endpoint agents, or migrations from legacy Trellix technologies.
  • Experience supporting multi-OS enterprise environments.
  • Familiarity with DISA STIGs and DoD endpoint-security requirements.
  • Experience supporting large-scale endpoint migrations, software deployments, or security-tool transitions.
  • Current Microsoft Certified: Endpoint Administrator Associate (MD-102), Microsoft security/security-operations certification applicable to Defender technologies, or another relevant Microsoft endpoint, security, or cloud certification.

What We Offer:

EIS offers a competitive benefits package to include: paid holidays, paid time off including sick and vacation leave, medical, dental and vision insurance, flexible spending accounts, short and long term disability, company paid life insurance, 401(k) with a company match and discretionary profit sharing and tuition reimbursement.

Similar Jobs

More Jobs at SpecPro Sustainment and Environmental, LLC

More Information Technology Jobs

Find similar Journeyman Endpoint Engineer jobs: