Endpoint Security Engineer
About the role
The Endpoint Security Engineer is responsible for implementing and maintaining endpoint security solutions across Windows, macOS, Mobile, and Linux environments. This includes managing application control, next-generation antivirus, privilege management, and vulnerability remediation. The role involves assisting with and enforcing policies for device compliance and secure configurations, monitoring endpoint and client health, investigating incidents, and providing timely resolution. Collaboration with security and infrastructure teams is essential to align endpoint strategy with organizational goals.
Responsibilities
- Implement and maintain endpoint security solutions
- Build automation workflows using APIs
- Manage enterprise management tools like Intune, SCCM, and Jamf Pro
- Apply endpoint security practices including application control, antivirus, EDR, patching, privilege management, Conditional Access, and vulnerability mitigation
- Monitor endpoint and client health, investigate incidents, and resolve issues promptly
- Collaborate with security and infrastructure teams to align endpoint strategy with organizational goals
- Document processes, configurations, and standards to ensure consistency and audit readiness
Requirements
- Experience with Windows, macOS, Mobile, or Linux and scripting languages
- Experience building automation workflows with APIs
- Knowledge of enterprise management tools such as Intune, SCCM, and Jamf Pro
- Knowledge of endpoint security practices, including application control, antivirus, EDR, patching, privilege management, Conditional Access, and vulnerability mitigation
- Knowledge of network security fundamentals and integration with endpoint protection
- Bachelor’s degree in Computer Science, Information Technology, or a related field
- Certifications such as CISSP, CEH, or CompTIA Security+
Qualifications
- Experience with Microsoft Entra and Active Directory
- Experience with Privilege Management tools such as BeyondTrust
- Experience with Application Control tools such as Airlock
- Experience with Next-Gen AV, DLP, and EDR such as CrowdStrike or Trellix
- Knowledge of patching operating systems and applications
- Knowledge of Conditional Access policies and rules
- Knowledge of ServiceNow and Microsoft Teams for project management and tracking
- Excellent troubleshooting, analytical, and communication skills
Skills
Nice if you have:
- Experience with Microsoft Entra and Active Directory
- Experience with Privilege Management tools such as BeyondTrust
- Experience with Application Control tools such as Airlock
- Experience with Next-Gen AV, DLP, and EDR such as CrowdStrike or Trellix
- Knowledge of patching operating systems and applications
- Knowledge of Conditional Access policies and rules
- Knowledge of ServiceNow and Microsoft Teams for project management and tracking
- Excellent troubleshooting, analytical, and communication skills
Benefits
At Booz Allen, we offer a comprehensive benefits package including health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. We also recognize employee contributions through our recognition awards program and provide a competitive salary range of $69,400.00 to $158,000.00 (annualized USD).