Koniag Government Services

Senior Endpoint Protection Analyst

Koniag Government Services • $110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, IT, or related field
  • 5+ years of experience in cybersecurity with focus on endpoint security
  • Experience administering enterprise endpoint protection and EDR platforms like CrowdStrike
  • Background in conducting incident investigations and forensic analysis.
  • Ability to obtain Public Trust Clearance

Responsibilities

  • Serve as a senior technical authority for endpoint protection solutions.
  • Monitor and respond to endpoint security alerts, analyzing incidents thoroughly.
  • Lead incident response efforts for malware and unauthorized access.
  • Perform forensic analysis to identify indicators of compromise.
  • Develop and tune endpoint detection rules and policies for improved accuracy.
  • Conduct vulnerability assessments and compliance reviews.
  • Collaborate with SOC and network teams to integrate endpoint security intelligence.

Benefits

  • Medical, dental, and vision insurance
  • 401(k) retirement plan
  • Paid time off and parental leave
  • Life and disability insurance
  • Flexible spending accounts and commuter benefits
  • Tuition reimbursement
Full Job Description
This position may be filled prior to the posted deadline. Interested candidates are encouraged to apply as soon as possible.

Koniag Operation Services, a Koniag Government Services company, is seeking an experienced Senior Endpoint Protection Analyst to join a cybersecurity team dedicated to protecting critical IT infrastructure and ensuring the security and integrity of enterprise endpoint environments. This position requires the ability to obtain a Public Trust Clearance to support our government customer.

Benefits include medical, dental, and vision insurance, 401(k) retirement plan, paid time off, paid parental leave, life and disability insurance, flexible spending accounts, commuter benefits, and tuition reimbursement.

The ideal candidate is a highly skilled, proactive cybersecurity professional who is passionate about endpoint security, threat detection, and incident response, and possesses the technical depth and analytical expertise to identify, investigate, and mitigate complex endpoint threats in a fast-paced, mission-driven environment.

The Senior Endpoint Protection Analyst will serve as a senior-level subject matter expert responsible for the administration, monitoring, analysis, and continuous improvement of enterprise endpoint protection solutions. This individual will play a critical role in defending the organization's endpoint infrastructure against cyber threats, leading incident response activities, and ensuring endpoint security tools and configurations remain current, effective, and compliant with applicable federal security standards and policies.

Principal responsibilities will include but are not limited to:
  • Serve as a senior technical authority for enterprise endpoint protection platforms, including endpoint detection and response (EDR), antivirus, anti-malware, host-based intrusion detection, and data loss prevention (DLP) solutions.
  • Monitor, analyze, and respond to endpoint security alerts, events, and incidents, conducting thorough investigations to determine scope, impact, and root cause.
  • Lead and support incident response activities related to endpoint threats, including malware infections, ransomware, unauthorized access, lateral movement, and data exfiltration attempts.
  • Perform in-depth forensic analysis of compromised endpoints to identify indicators of compromise (IOCs), threat actor techniques, tactics, and procedures (TTPs), and recommend remediation actions.
  • Develop, tune, and maintain endpoint detection rules, policies, and configurations to reduce false positives, improve detection fidelity, and ensure comprehensive coverage across the enterprise endpoint environment.
  • Conduct regular vulnerability assessments and endpoint compliance reviews, identifying gaps in endpoint security posture and recommending corrective actions.
  • Collaborate with the Security Operations Center (SOC), network security, and IT operations teams to correlate endpoint telemetry with broader threat intelligence and network security data.
  • Manage and administer endpoint protection platforms, ensuring agents are deployed, updated, and functioning correctly across all managed endpoints.
  • Develop and maintain endpoint security policies, standards, baselines, and hardening guidelines in alignment with federal security frameworks such as NIST, FISMA, and agency-specific requirements.
  • Research and analyze emerging cyber threats, vulnerabilities, and attack techniques relevant to endpoint environments, providing actionable intelligence and recommendations to leadership and stakeholders.
  • Support the development and continuous improvement of endpoint security playbooks, standard operating procedures (SOPs), and incident response runbooks.
  • Prepare and deliver clear, accurate, and timely security reports, briefings, and documentation for technical teams and non-technical stakeholders including government leadership.
  • Mentor and provide technical guidance to junior analysts, sharing knowledge and best practices to strengthen the overall capabilities of the cybersecurity team.
  • Participate in security audits, assessments, and Authorization to Operate (ATO) activities by providing endpoint security documentation, evidence, and subject matter expertise.
  • Evaluate and recommend new endpoint security technologies, tools, and capabilities to enhance the organization's overall security posture.
  • Support patch management and vulnerability remediation efforts by validating endpoint compliance and coordinating with IT operations teams.
  • Actively contribute to threat hunting activities, proactively searching for hidden threats and anomalous behaviors within the endpoint environment.


Education and Experience:

Required:
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related field from an accredited college or university.
  • 5+ years of experience in cybersecurity, with a focus on endpoint security, endpoint protection, or incident response.
  • Demonstrated experience administering and operating enterprise endpoint protection and EDR platforms such as CrowdStrike Falcon, Microsoft Defender for Endpoint, Carbon Black, SentinelOne, or similar solutions.
  • Experience conducting endpoint security incident investigations, forensic analysis, and malware analysis.


Preferred:
  • 7+ years of experience in cybersecurity with a specialization in endpoint protection or security operations.
  • Experience supporting endpoint security operations in a federal government IT environment.

Required Skills and Competencies:
  • Deep technical expertise in endpoint protection technologies including EDR, antivirus, anti-malware, host-based intrusion detection systems (HIDS), and data loss prevention (DLP) solutions.
  • Proficiency in administering and operating at least one enterprise EDR platform such as CrowdStrike Falcon, Microsoft Defender for Endpoint, Carbon Black, SentinelOne, or equivalent.
  • Strong experience conducting security incident investigations, root cause analysis, and digital forensic analysis of compromised endpoints.
  • Solid understanding of malware analysis techniques, including static and dynamic analysis, and the ability to identify and document indicators of compromise (IOCs).
  • Familiarity with threat intelligence frameworks such as MITRE ATT&CK and the ability to map observed adversary behaviors to known TTPs.
  • Experience developing and tuning endpoint detection rules, alerts, and security policies to improve detection accuracy and reduce alert fatigue.
  • Knowledge of federal cybersecurity frameworks, standards, and regulations including NIST SP 800-53, FISMA, and FIPS, and the ability to align endpoint security practices with these requirements.
  • Experience supporting vulnerability management and patch compliance activities within enterprise endpoint environments.
  • Proficiency with security information and event management (SIEM) platforms for correlating endpoint telemetry with broader security event data.
  • Strong analytical, critical thinking, and problem-solving skills with the ability to assess complex security situations and make timely, informed decisions.
  • Excellent written and verbal communication skills in English, with the ability to produce clear and accurate security reports, documentation, and briefings for both technical and executive audiences.
  • Ability to mentor junior team members and contribute to the professional development of the broader cybersecurity team.
  • Ability to work effectively both independently and collaboratively within a cross-functional cybersecurity team environment.
  • Ability to obtain and maintain a Public Trust Clearance.


Desired Skills and Competencies:
  • Experience working in a federal government cybersecurity environment, preferably supporting a civilian or defense agency.
  • One or more industry-recognized cybersecurity certifications such as:
    • CompTIA Security+, CySA+, or CASP+
    • Certified Ethical Hacker (CEH)
    • GIAC Certified Enterprise Defender (GCED)
    • GIAC Certified Incident Handler (GCIH)
    • GIAC Certified Forensic Analyst (GCFA)
    • Certified Information Systems Security Professional (CISSP)
    • CrowdStrike Certified Falcon Responder (CCFR) or equivalent vendor certification
  • Experience with threat hunting methodologies and tools, including proactive identification of advanced persistent threats (APTs) within endpoint environments.
  • Familiarity with cloud endpoint security concepts and experience securing endpoints within Microsoft Azure, AWS, or hybrid cloud environments.
  • Experience with scripting languages such as Python, PowerShell, or Bash for automating security tasks and enhancing endpoint monitoring capabilities.
  • Knowledge of network security concepts including firewalls, proxies, and intrusion detection/prevention systems and how they correlate with endpoint security telemetry.
  • Experience participating in or supporting Authorization to Operate (ATO) processes and security control assessments.
  • Familiarity with zero trust architecture principles and their application to endpoint security strategies.
  • Experience supporting or contributing to Security Operations Center (SOC) operations, including shift-based monitoring and escalation procedures.


About Koniag Government Services

Koniag Government Services Careers

Join the dynamic team at Koniag Government Services, a leader in providing innovative solutions to government clients. This esteemed company offers a plethora of job opportunities that pave the way for professional growth and career advancement in a diverse and inclusive environment.

Explore Career Opportunities

Koniag Government Services is actively hiring and offers a range of positions that cater to various skills and experiences. Whether you're a seasoned professional or a recent graduate, Koniag Government Services provides a platform to enhance your career through meaningful work in a supportive culture.

Innovation and Leadership

At the forefront of innovation, Koniag Government Services encourages its team to lead with creativity and strategic thinking. The company is committed to leadership development and diversity training, ensuring that all team members have the opportunity to excel and contribute to industry-leading projects.

Professional Growth and Development

Koniag Government Services is dedicated to the professional development of its employees. With comprehensive benefits, competitive employment packages, and opportunities for advancement, the company supports its team in achieving their career goals. Networking within the company and industry is encouraged, fostering a community of learning and mutual growth.

Internship Programs

For those starting their career journey, Koniag Government Services offers internship programs that provide real-world experience and a pathway to full-time employment. Interns gain valuable industry knowledge and develop essential skills under the guidance of experienced mentors.

Commitment to Diversity and Inclusion

Diversity is at the core of Koniag Government Services' values. The company is committed to creating an inclusive environment where diverse voices are heard and valued. Diversity training is integral, equipping the team with the tools to thrive in a multicultural setting.

Applying for a Position

To apply for a position at Koniag Government Services, candidates should prepare a resume that highlights relevant experience and skills. The interview process is designed to assess fit both for the role and the company culture, ensuring alignment with the team’s values and objectives.

Stay Connected with Koniag Government Services Careers

Explore the various job opportunities and embark on a path of professional growth and innovation. Koniag Government Services is not just a workplace but a community where careers flourish in an environment of respect, integrity, and continuous learning.

Search Koniag Government Services Jobs

Discover the exciting career opportunities available at Koniag Government Services. Search for open positions that match your skills and interests, and join a team that values curiosity, creativity, and collaboration.

Keep Up to Date

Stay informed with the latest career tips, industry insights, and company updates directly from Koniag Government Services. Engage with content that can transform your professional journey and lead to rewarding opportunities.

Job Alert Emails

Personalize your subscription to receive job alerts and insider tips tailored to your preferences from Koniag Government Services. See what exciting and rewarding opportunities await in the field of government services.
Learn more about Koniag Government Services
Size
501 employees
Industry

Similar Jobs

More Jobs at Koniag Government Services

More Information Technology Jobs

Find similar Senior Endpoint Protection Analyst jobs: