Jobs · Information Technology

Endpoint Security Engineer

Dragonfli Group · United States · 2 days ago
RemoteRemoteInformation TechnologyFull-time

About the role

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments. As an Endpoint Security Engineer, you'll design, deploy, and operationalize behavior-based endpoint detection and response (EDR/XDR) capabilities protecting one of the largest private operational fleets in North America — spanning hundreds of thousands of end-user devices, on-premise and virtual servers, and multi-cloud workloads across AWS, Azure, and GCP. You'll partner directly with application owners to tune policies and eliminate friction, while providing tier-3/tier-4 technical escalation support to SOC analysts and IT Operations during active investigations. This is a high-visibility engineering role for someone who thinks in terms of infrastructure-as-code and policy automation rather than device-by-device intervention.

Responsibilities

  • Engineer, deploy, and maintain Next-Gen Antivirus (NGAV) and EDR/XDR agents across hundreds of thousands of heterogeneous endpoints
  • Implement active behavioral protections against zero-day malware, living-off-the-land binaries, fileless execution, and credential dumping
  • Serve as primary technical partner to application owners and business units, establishing baseline behavior profiles to minimize false positives and operational disruption
  • Manage allowlisting, exception workflows, and phased ring deployments (canary/pilot/production)
  • Act as endpoint security escalation lead for SOC analysts and IT administrators during high-severity events
  • Perform advanced host forensics, process-tree reconstruction, memory analysis, and script-based live remediation
  • Extend endpoint security standards across private data center virtualization (VMware/Nutanix) and multi-cloud infrastructure
  • Continuously validate control efficacy using automated attack simulation (BAS) tools and Purple Team exercises
  • Track and report on agent health, tamper-resistance, telemetry integrity, and coverage metrics

Requirements

Must-Have:

  • 7+ years of progressive experience in technical cybersecurity engineering or infrastructure security roles
  • 3–5 years directly engineering and administering enterprise-grade EDR/XDR platforms across 50,000+ endpoints in a distributed hybrid environment
  • Expert-level proficiency administering EDR/XDR platforms across Windows, macOS, Linux, and container runtime environments
  • Deep understanding of behavioral IOAs, Sysmon telemetry, and detection authoring (SQL, KQL, Splunk SPL, or YARA)
  • Strong scripting ability in PowerShell, Python, or Bash for fleet-wide remediation and automation
  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or equivalent practical experience
  • U.S. Citizenship or Permanent Residency; ability to work within the continental United States

Preferred / Nice-to-Have:

  • GIAC Certified Enterprise Defender (GCED), GIAC Certified Incident Handler (GCIH), or GCFA
  • CISSP
  • Vendor credentials such as CrowdStrike Certified Falcon Administrator/Hunter or Microsoft SC-200
  • Prior experience supporting active SOC investigations in large-scale enterprise environments
  • Fluency applying AI/ML tooling (Splunk, Databricks, Elastic) to streamline security operations

Skill(s)

Technical Skills: EDR/XDR engineering (CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne) · Behavioral threat hunting and detection authoring · Windows/Linux kernel internals and API hooking · Multi-cloud workload security (AWS, Azure, GCP) · PowerShell/Python/Bash automation · Host forensics and memory analysis · Attack simulation (BAS) and Purple Team exercises

Soft Skills: Stakeholder empathy and business-impact analysis · Crisis leadership and composure under pressure · Cross-functional collaboration with SOC and IT Operations · Executive-level communication of technical risk

Benefits

  • Medical — Multiple POS health plan options including an HSA-compatible plan
  • Dental — PPO coverage for preventive, basic, and major services
  • Vision — Annual exam, frames, lenses, and contact lens allowance
  • 401(k) — Employer match up to 5% of eligible compensation
  • Long-Term Disability — 100% employer-paid coverage at 50% of pre-disability earnings
  • Life Insurance & AD&D — 100% employer-paid coverage valued at $10,000 each
  • PTO — 15–25 days annually based on tenure
  • Paid Federal Holidays — All 11 federal holidays observed

Similar jobs