As a
Sr. Endpoint Security Engineer I (Trellix SME), you'll serve as the technical lead for the organization's endpoint security and data protection ecosystem, balancing day-to-day operational support with strategic cybersecurity engineering initiatives. This person will own, build, and run the Trellix platform, including its design and architecture. You will work closely with security operations, infrastructure, application teams, and leadership to strengthen the organization's overall security posture.
What you'll do:- Monitor and manage enterprise Trellix security platforms, including ePO, ENS, EDR, DLP, and encryption technologies.
- Support SOC analysts by tuning alerts, improving detection capabilities, and investigating endpoint security events.
- Configure application whitelisting, File Integrity Monitoring, DLP enhancements, and security control implementation.
- Design and deploy endpoint hardening and application control solutions using Trellix Application and Change Control.
- Develop and maintain DLP policies, encryption controls, removable media protections, and data classification safeguards.
- Integrate endpoint security telemetry with SIEM and SOAR platforms to improve visibility, detection, and automated response capabilities.
- Perform root-cause analysis of security incidents, policy conflicts, and endpoint management issues.
- Develop automation workflows and improve operational efficiency using scripts, APIs, and orchestration tools.
- Create and maintain dashboards, reports, and metrics that support cybersecurity operations and executive reporting.
- Collaborate with security assessors and compliance teams to implement and validate technical controls.
- Document security architectures, SOPs, playbooks, and engineering standards.
- Research emerging threats, evaluate new security capabilities, and recommend improvements to strengthen enterprise cyber defenses.
What you'll need to succeed:- Active TS/SCI security clearance.
- Seven or more years of relevant engineering experience.
- At least five years of hands-on experience administering or engineering Trellix, McAfee, HBSS, or ESS solutions in a large enterprise environment.
- Broad hands-on experience administering and engineering multiple Trellix/McAfee enterprise security products, such as ePO, ENS, EDR, DLP, Drive Encryption (FRP/FRMP), Policy Auditor, Rogue System Detection, Trellix Security for Microsoft Exchange, Application and Change Control, and File Integrity Monitoring. Experience with TIE and DXL is a plus.
- Hands-on background implementing and managing application whitelisting, endpoint hardening, encryption, and data protection technologies.
- Ability to integrate endpoint security platforms with SIEM, SOAR, threat intelligence, and identity management solutions.
- Strong understanding of endpoint security architecture, cyber threat detection, incident response, and risk management principles.
- A background in developing and maintaining DLP policies, device-control mechanisms, and data-exfiltration prevention controls.
- Ability to develop security engineering standards, SOPs, playbooks, and operational procedures.
- Experience supporting compliance initiatives and implementing security controls aligned with federal cybersecurity frameworks and regulations.
- Strong analytical, troubleshooting and root-cause analysis skills.
SALARY RANGE: $138,000 - $166,000
The salary range for this position is determined based on qualifications, skills, and relevant experience. The final salary offered will be determined based on several factors including:
- The candidate's professional background and relevant work experience
- The specific responsibilities of the role and organizational needs
- Internal equity and alignment with current team compensation
- This role is also eligible for additional compensation, subject to the terms and policies of MetroStar, which may include:
- Performance-based bonuses
- Company-paid training and/or certifications
- Referral bonuses
Application Deadline: Applications will be accepted on a rolling basis until the position is filled; candidates are encouraged to apply as early as possible for full consideration.
Additional Compensation: This role may also be eligible for bonuses and/or additional incentives based on individual and company performance.
Benefits: All full-time employees are eligible to participate in our benefits programs:
- Health, dental, and vision insurance
- 401(k) retirement plan with company match
- Paid time off (PTO) and holidays
- Parental Leave and dependent care
- Flexible work arrangements
- Professional development opportunities
- Employee assistance and wellness programs