MetroStar Systems

Sr. Endpoint Security Engineer I (Trellix) (6837)

MetroStar Systems • $138K — $166K *
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Active TS/SCI security clearance required.
  • Seven years of engineering experience in cybersecurity needed.
  • Five years administering or engineering Trellix or similar solutions in a large environment.
  • Hands-on experience with Trellix/McAfee products like ePO, ENS, EDR, and DLP necessary.
  • Experience integrating security technologies with SIEM and SOAR platforms required.
  • Strong analytical and troubleshooting skills emphasized.

Responsibilities

  • Monitor and manage Trellix security platforms.
  • Support SOC analysts by enhancing detection capabilities and investigating events.
  • Configure application whitelisting and implement security controls.
  • Design and deploy endpoint hardening solutions using Trellix.
  • Develop and maintain data protection policies and encryption controls.
  • Integrate security telemetry with SIEM for improved visibility and response.
  • Conduct root-cause analysis of security incidents and management issues.

Benefits

  • Health, dental, and vision insurance offered.
  • 401(k) plan with company match available.
  • Generous paid time off and holiday policy.
  • Parental leave and dependent care included.
  • Flexible working arrangements provided.
  • Opportunities for professional development and training offered.
  • Employee assistance and wellness programs available.
Full Job Description
As a Sr. Endpoint Security Engineer I (Trellix SME), you'll serve as the technical lead for the organization's endpoint security and data protection ecosystem, balancing day-to-day operational support with strategic cybersecurity engineering initiatives. This person will own, build, and run the Trellix platform, including its design and architecture. You will work closely with security operations, infrastructure, application teams, and leadership to strengthen the organization's overall security posture.

What you'll do:
  • Monitor and manage enterprise Trellix security platforms, including ePO, ENS, EDR, DLP, and encryption technologies.
  • Support SOC analysts by tuning alerts, improving detection capabilities, and investigating endpoint security events.
  • Configure application whitelisting, File Integrity Monitoring, DLP enhancements, and security control implementation.
  • Design and deploy endpoint hardening and application control solutions using Trellix Application and Change Control.
  • Develop and maintain DLP policies, encryption controls, removable media protections, and data classification safeguards.
  • Integrate endpoint security telemetry with SIEM and SOAR platforms to improve visibility, detection, and automated response capabilities.
  • Perform root-cause analysis of security incidents, policy conflicts, and endpoint management issues.
  • Develop automation workflows and improve operational efficiency using scripts, APIs, and orchestration tools.
  • Create and maintain dashboards, reports, and metrics that support cybersecurity operations and executive reporting.
  • Collaborate with security assessors and compliance teams to implement and validate technical controls.
  • Document security architectures, SOPs, playbooks, and engineering standards.
  • Research emerging threats, evaluate new security capabilities, and recommend improvements to strengthen enterprise cyber defenses.

What you'll need to succeed:
  • Active TS/SCI security clearance.
  • Seven or more years of relevant engineering experience.
  • At least five years of hands-on experience administering or engineering Trellix, McAfee, HBSS, or ESS solutions in a large enterprise environment.
  • Broad hands-on experience administering and engineering multiple Trellix/McAfee enterprise security products, such as ePO, ENS, EDR, DLP, Drive Encryption (FRP/FRMP), Policy Auditor, Rogue System Detection, Trellix Security for Microsoft Exchange, Application and Change Control, and File Integrity Monitoring. Experience with TIE and DXL is a plus.
  • Hands-on background implementing and managing application whitelisting, endpoint hardening, encryption, and data protection technologies.
  • Ability to integrate endpoint security platforms with SIEM, SOAR, threat intelligence, and identity management solutions.
  • Strong understanding of endpoint security architecture, cyber threat detection, incident response, and risk management principles.
  • A background in developing and maintaining DLP policies, device-control mechanisms, and data-exfiltration prevention controls.
  • Ability to develop security engineering standards, SOPs, playbooks, and operational procedures.
  • Experience supporting compliance initiatives and implementing security controls aligned with federal cybersecurity frameworks and regulations.
  • Strong analytical, troubleshooting and root-cause analysis skills.

SALARY RANGE: $138,000 - $166,000

The salary range for this position is determined based on qualifications, skills, and relevant experience. The final salary offered will be determined based on several factors including:
  • The candidate's professional background and relevant work experience
  • The specific responsibilities of the role and organizational needs
  • Internal equity and alignment with current team compensation
  • This role is also eligible for additional compensation, subject to the terms and policies of MetroStar, which may include:
    • Performance-based bonuses
    • Company-paid training and/or certifications
    • Referral bonuses


Application Deadline: Applications will be accepted on a rolling basis until the position is filled; candidates are encouraged to apply as early as possible for full consideration.

Additional Compensation: This role may also be eligible for bonuses and/or additional incentives based on individual and company performance.

Benefits: All full-time employees are eligible to participate in our benefits programs:
  • Health, dental, and vision insurance
  • 401(k) retirement plan with company match
  • Paid time off (PTO) and holidays
  • Parental Leave and dependent care
  • Flexible work arrangements
  • Professional development opportunities
  • Employee assistance and wellness programs

About MetroStar Systems

MetroStar Systems is a technology services provider specializing in digital transformation, cybersecurity, and customer experience. The company was founded in 1999 and is headquartered in Washington, DC. MetroStar Systems has worked with clients in the public and private sectors, including the Department of Defense, the Department of Homeland Security, and the Federal Aviation Administration. The company has received numerous awards for its work, including being named a Top Workplace by The Washington Post.
Learn more about MetroStar Systems
Size
400 employees
Industry
Net Income
$2 million
Founded
1999
5 Year Trend
+20%
Revenue
$50 million

Similar Jobs

More Jobs at MetroStar Systems

More Aerospace & Defense Jobs

Find similar Sr. Endpoint Security Engineer I (Trellix) (6837) jobs: