Endpoint Security Engineer
About the role
Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments. As an Endpoint Security Engineer, you'll design, deploy, and operationalize behavior-based endpoint detection and response (EDR/XDR) capabilities protecting one of the largest private operational fleets in North America — spanning hundreds of thousands of end-user devices, on-premise and virtual servers, and multi-cloud workloads across AWS, Azure, and GCP. You'll partner directly with application owners to tune policies and eliminate friction, while providing tier-3/tier-4 technical escalation support to SOC analysts and IT Operations during active investigations. This is a high-visibility engineering role for someone who thinks in terms of infrastructure-as-code and policy automation rather than device-by-device intervention.
Responsibilities
- Engineer, deploy, and maintain Next-Gen Antivirus (NGAV) and EDR/XDR agents across hundreds of thousands of heterogeneous endpoints
- Implement active behavioral protections against zero-day malware, living-off-the-land binaries, fileless execution, and credential dumping
- Serve as primary technical partner to application owners and business units, establishing baseline behavior profiles to minimize false positives and operational disruption
- Manage allowlisting, exception workflows, and phased ring deployments (canary/pilot/production)
- Act as endpoint security escalation lead for SOC analysts and IT administrators during high-severity events
- Perform advanced host forensics, process-tree reconstruction, memory analysis, and script-based live remediation
- Extend endpoint security standards across private data center virtualization (VMware/Nutanix) and multi-cloud infrastructure
- Continuously validate control efficacy using automated attack simulation (BAS) tools and Purple Team exercises
- Track and report on agent health, tamper-resistance, telemetry integrity, and coverage metrics
Requirements
Must-Have:
- 7+ years of progressive experience in technical cybersecurity engineering or infrastructure security roles
- 3–5 years directly engineering and administering enterprise-grade EDR/XDR platforms across 50,000+ endpoints in a distributed hybrid environment
- Expert-level proficiency administering EDR/XDR platforms across Windows, macOS, Linux, and container runtime environments
- Deep understanding of behavioral IOAs, Sysmon telemetry, and detection authoring (SQL, KQL, Splunk SPL, or YARA)
- Strong scripting ability in PowerShell, Python, or Bash for fleet-wide remediation and automation
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or equivalent practical experience
- U.S. Citizenship or Permanent Residency; ability to work within the continental United States
Preferred / Nice-to-Have:
- GIAC Certified Enterprise Defender (GCED), GIAC Certified Incident Handler (GCIH), or GCFA
- CISSP
- Vendor credentials such as CrowdStrike Certified Falcon Administrator/Hunter or Microsoft SC-200
- Prior experience supporting active SOC investigations in large-scale enterprise environments
- Fluency applying AI/ML tooling (Splunk, Databricks, Elastic) to streamline security operations
Skill(s)
Technical Skills: EDR/XDR engineering (CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne) · Behavioral threat hunting and detection authoring · Windows/Linux kernel internals and API hooking · Multi-cloud workload security (AWS, Azure, GCP) · PowerShell/Python/Bash automation · Host forensics and memory analysis · Attack simulation (BAS) and Purple Team exercises
Soft Skills: Stakeholder empathy and business-impact analysis · Crisis leadership and composure under pressure · Cross-functional collaboration with SOC and IT Operations · Executive-level communication of technical risk
Benefits
- Medical — Multiple POS health plan options including an HSA-compatible plan
- Dental — PPO coverage for preventive, basic, and major services
- Vision — Annual exam, frames, lenses, and contact lens allowance
- 401(k) — Employer match up to 5% of eligible compensation
- Long-Term Disability — 100% employer-paid coverage at 50% of pre-disability earnings
- Life Insurance & AD&D — 100% employer-paid coverage valued at $10,000 each
- PTO — 15–25 days annually based on tenure
- Paid Federal Holidays — All 11 federal holidays observed