Security Engineer II
About the role
As a Security Engineer II – Endpoint Security, you will serve as an independent assurance layer for the security posture of every corporate endpoint — laptop, server, and workstation across Mac, Windows, Linux, and Windows Server — closing the gaps that make privilege escalation and lateral movement possible. You will validate that local administrative rights, endpoint configuration, and installed software match security intent, while directly owning browser/IDE extension governance and the tuning of endpoint security agents. Reporting into the Cyber Threat Intelligence organization, you will work end-user facing issues end to end and partner closely with Desktop Engineering, Identity & Access Management, and Security Operations.
An ideal candidate combines solid Enterprise Security fundamentals with practical, cross-platform endpoint engineering and system administration experience.
Responsibilities
- Continuous Endpoint Hardening: Maintain a standing, open-ended mandate to identify and drive endpoint security improvements across the fleet — beyond any fixed checklist.
- Endpoint Sensor Engineering: Administer, tune, and troubleshoot endpoint security agents (CrowdStrike Falcon, DTEX, Zscaler ZDP) across all platforms; continuously tighten CrowdStrike prevention/detection policy and investigate agent alerts, escalating true positives with context.
- Application & Extension Governance: Own the browser/IDE extension review process end to end (risk-scoring, approve/deny/remove) and run recurring automated reviews of installed software to surface unauthorized, high-risk, or end-of-life applications.
- Exception Management: Manage approval, tracking, and reporting of endpoint security exceptions.
- Configuration Assurance & Allow-Listing: Validate Group Policy and registry-level settings against security best practices, and partner with Desktop Engineering to move the fleet to an approved application allow list.
- Extended Tooling & Firmware Exposure: Assist with DSPM, inventory/assess out-of-band management tools and applications.
- End-User Support & Documentation: Serve as the primary technical resource for end-user endpoint security issues, and document standards, runbooks, and best-practice guidance for partner teams.
Qualifications
- 2 years of experience in Information Security, Cyber Security, or Endpoint/Systems Engineering.
- 1 year of experience administering cross-platform endpoint environments (Windows, Windows Server, macOS, Linux). Preferred
- Working knowledge of Active Directory, Group Policy Objects, and registry-level security baselining; familiarity with scripting (Python, PowerShell, Bash). Preferred
- Endpoint Security Preferred
- Endpoint Detection And Response Preferred
- Data Loss Prevention (DLP) Preferred
- Group Policy / Active Directory Preferred
- Cross-Platform OS Administration Preferred
- PowerShell Preferred
- Python (Programming Language) Preferred
Pay
The starting base pay range for this position is $98,400 - $154,600 annually. Please keep in mind that this range is the base pay only and does not consider other components that make up the total rewards package for the position. If you are hired at Paychex, your overall compensation will be determined based on factors such as geographic location, skills, education, and/or experience which may result in total compensation outside of this range.
Benefits
- Medical coverage, virtual wellness classes, tuition reimbursement, 401(k) + employer match, adoption assistance, financial assistance, and much more.
- Paid time off, company holidays, culture days, and comprehensive work-life balance programs.
- Award-winning training and development programs.
- Paid time off for volunteerism and company-wide/local initiatives supporting organizations you care about.
Note: The benefits described apply to full-time employees. Benefits for part-time, contract, and intern roles may vary.