Job Summary:
Seeking a Senior Endpoint Cybersecurity Engineer with strong hands-on experience designing, deploying, configuring, and maintaining enterprise endpoint security solutions across workstations and servers. The role will focus on endpoint detection and response, endpoint protection, threat detection, incident response, endpoint hardening, security automation, and integration with broader security platforms. The engineer will collaborate with SOC and Incident Response teams, support threat hunting and Zero Trust initiatives, troubleshoot complex endpoint security issues, and provide technical guidance to stakeholders.
Key Responsibilities:
• Design, deploy, configure, and maintain enterprise endpoint security solutions across workstations and servers.
• Administer and optimize EDR, EPP, endpoint protection, and deception technologies.
• Configure and tune endpoint security policies, detection rules, prevention controls, exclusions, and automated response actions.
• Monitor endpoint telemetry and investigate suspicious activity, malware, security alerts, and indicators of compromise.
• Partner with SOC and Incident Response teams to investigate, contain, remediate, and close endpoint security incidents.
• Develop and tune detection logic based on threat intelligence, emerging attack techniques, and MITRE ATT&CK.
• Identify and reduce false positives while maintaining effective endpoint detection and prevention coverage.
• Troubleshoot endpoint agents, policies, connectivity, telemetry, and deployment issues.
• Integrate endpoint security platforms with SIEM, SOAR, threat intelligence, IAM, and vulnerability management tools.
• Support threat hunting, endpoint hardening, vulnerability remediation, and Zero Trust security initiatives.
• Evaluate new endpoint security technologies, participate in vendor assessments, and support proof-of-concept activities.
• Maintain endpoint security standards, architecture documentation, procedures, and operational runbooks.
• Mentor junior engineers and communicate security risks, incidents, and remediation recommendations to technical and business stakeholders.
Required Qualifications:
• 8+ years of experience in Cybersecurity, Information Security, Security Engineering, or Endpoint Security.
• 5+ years of hands-on experience with enterprise endpoint security technologies.
• 3+ years of experience with EDR/EPP platforms, endpoint detection, threat hunting, or incident response.
• Hands-on experience with CrowdStrike, Microsoft Defender, SentinelOne, Trellix, Carbon Black, or similar endpoint security platforms.
• Strong knowledge of endpoint security, malware, ransomware, threat detection, incident response, and endpoint hardening.
• 3+ years of experience with MITRE ATT&CK, SIEM/SOAR, threat intelligence, and security monitoring.
• Working knowledge of Windows and Linux security and endpoint architecture.
• 3+ years of experience with PowerShell, Python, Bash, or similar scripting and automation tools.
• Understanding of Zero Trust, vulnerability management, security controls, and enterprise risk management.
• Strong analytical, troubleshooting, documentation, communication, and stakeholder-management skills.
• Ability to explain previous projects, including security requirements, technical contributions, challenges, and delivered outcomes.
• Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field, or equivalent experience.