Endpoint Security Engineer
We are seeking a cybersecurity professional who can perform security operations, endpoint security, and incident response within large-scale enterprise environments. The ideal candidate will be deploying and maturing EDR platforms, enhancing detection coverage, and strengthening security workflows. This role requires a practitioner who has supported complex and distributed environments, contributed to operational reliability, and improved detection and response processes through refined logic, increased visibility, and optimized tooling.
Responsibilities
- Build strong relationships across teams and communicate complex security concepts to a wide range of audiences, including senior leadership.
- Implement infrastructure and cybersecurity controls that enhance detection, improve vulnerability insights, and strengthen event correlation across large enterprises.
- Conduct risk and vulnerability assessments across network, system, and application layers, leveraging big-data analytics and traditional security event types to identify advanced threats and indicators of compromise.
- Investigate and remediate security incidents, conduct proactive threat hunting, and perform detailed root cause analysis.
- Tune detection rules, engineer advanced logging configurations, and contribute to incident response playbooks.
Requirements
- Experience with incident response, threat detection, root cause analysis, and security operations within large-scale enterprise environments.
- Experience applying CIS Benchmarks, NIST standards, CMMC requirements, CDM EDR criteria, and the CISA EDR Maturity Model to strengthen enterprise security posture.
- Experience developing and refining detection logic, tuning SIEM rules, and leveraging industry frameworks such as MITRE ATT&CK to strengthen detection accuracy.
- Knowledge of endpoint detection and response (EDR) concepts, including deployment, tuning, and optimization across extensive endpoint fleets.
- Knowledge of leading security tools, including Palo Alto, SentinelOne, CrowdStrike Falcon, Symantec, and Splunk.
- Ability to support and enhance operational workflows, documentation, and clear reporting for technical and non-technical stakeholders.
- Ability to obtain a Secret clearance.
- Bachelor's degree in Computer Science.
Benefits
- Health, life, disability, financial, and retirement benefits.
- Paid leave, professional development, tuition assistance, work-life programs, and dependent care.
- Recognition awards program for exceptional performance and superior demonstration of company values.
Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits.
Pay
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $99,000.00 to $225,000.00 (annualized USD).
Schedule
This role may be remote, hybrid, or onsite:
- Remote: Occasional in-person work at a Booz Allen or customer facility may be required.
- Hybrid: Frequent work from a Booz Allen facility, with possible visits to customer facilities as needed.
- Onsite: Work primarily performed at a Booz Allen office or customer facility.
Employees working virtually are generally expected to have their cameras on during meetings to support engagement and effective communication.