
Endpoint Security Engineer
- Southlake, TX Phoenix, AZ
- $120,000-140,000 per year
- Permanent
- Full-time
- Preferred experience managing endpoint security tools such as EDR, DLP, device control, drive encryption, and file integrity monitoring.
- Understand General networking concepts such as firewalls and IP networking.
- Understand fundamental operating system functionality and how applications communicate and interact with the operating system.
- Fundamental understanding of public cloud and SaaS concepts.
- Customization, implementation of best practices, determine specific value-driven use cases, and fully integrate the solution into the environment.
- Develop and report enterprise level metrics for endpoint security controls.
- Work closely with Stakeholders Teams (Compliance, Mainframe, Windows, Linux, Network, SIEM, Remedy, Asset Management) to develop high value enterprise capabilities/results while reducing noise and false alarms.
- Experience with PowerShell, CQL, Python, REST API, and GIT
- Help architect solutions (initial state, transition, final state architectures).
- Create content filters, rules, dashboards, and reports.
- Provide compliance and audit evidence for monitored systems.
- Identify and implement automation of repetitive tasks.
- Document, publish and maintain a knowledge base of information pertaining to the functionality, processes and procedures related to the supported tools.
- Create, modifying, test, deploy procedure and rules specific to asset type (i.e. mainframe, web servers, database servers, batch servers, application servers)
- EPP/EDR
- SIEM/SOAR
- Microsoft InTune
- DLP
- FIM
- More than 7 years of progressive experience in cybersecurity engineering with multiple security controls within multiple security domains.
- At least 3 years focused on Endpoint Security Engineering
- At least 2 years’ experience with handling workloads in an Agile environment utilizing SCRUM with Lean/MVP methodologies.
- Bachelor's Degree in Computer Science, Engineering or related field
- CISSP, CISM, or other relevant information security industry recognized certification preferred.
- Experience with CrowdStrike or a comparable EDR.