Endpoint Security Engineer

Posted 4 Days Ago
Be an Early Applicant
Hiring Remotely in GBR
Remote
Senior level
Artificial Intelligence • Machine Learning • Analytics
The Role
Designs, deploys, and operates enterprise EDR/XDR and NGAV capabilities across hundreds of thousands of heterogeneous endpoints, servers, containers, virtual environments, and multi-cloud workloads. Responsibilities include behavioral protection, detection authoring, allowlisting, phased deployments, endpoint health monitoring, advanced host forensics, live remediation, SOC escalation support, attack simulation, and Purple Team validation. The engineer partners with application owners and IT teams to reduce false positives, improve coverage, and communicate technical risk.
Summary Generated by Built In
Description

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.

As an Endpoint Security Engineer, you'll design, deploy, and operationalize behavior-based endpoint detection and response (EDR/XDR) capabilities protecting one of the largest private operational fleets in North America — spanning hundreds of thousands of end-user devices, on-premise and virtual servers, and multi-cloud workloads across AWS, Azure, and GCP. You'll partner directly with application owners to tune policies and eliminate friction, while providing tier-3/tier-4 technical escalation support to SOC analysts and IT Operations during active investigations. This is a high-visibility engineering role for someone who thinks in terms of infrastructure-as-code and policy automation rather than device-by-device intervention.

This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.

Responsibilities:

  • Engineer, deploy, and maintain Next-Gen Antivirus (NGAV) and EDR/XDR agents across hundreds of thousands of heterogeneous endpoints
  • Implement active behavioral protections against zero-day malware, living-off-the-land binaries, fileless execution, and credential dumping
  • Serve as primary technical partner to application owners and business units, establishing baseline behavior profiles to minimize false positives and operational disruption
  • Manage allowlisting, exception workflows, and phased ring deployments (canary/pilot/production)
  • Act as endpoint security escalation lead for SOC analysts and IT administrators during high-severity events
  • Perform advanced host forensics, process-tree reconstruction, memory analysis, and script-based live remediation
  • Extend endpoint security standards across private data center virtualization (VMware/Nutanix) and multi-cloud infrastructure
  • Continuously validate control efficacy using automated attack simulation (BAS) tools and Purple Team exercises
  • Track and report on agent health, tamper-resistance, telemetry integrity, and coverage metrics
Requirements

Must-Have:

  • 7+ years of progressive experience in technical cybersecurity engineering or infrastructure security roles
  • 3–5 years directly engineering and administering enterprise-grade EDR/XDR platforms across 50,000+ endpoints in a distributed hybrid environment
  • Expert-level proficiency administering EDR/XDR platforms across Windows, macOS, Linux, and container runtime environments
  • Deep understanding of behavioral IOAs, Sysmon telemetry, and detection authoring (SQL, KQL, Splunk SPL, or YARA)
  • Strong scripting ability in PowerShell, Python, or Bash for fleet-wide remediation and automation
  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or equivalent practical experience
  • U.S. Citizenship or Permanent Residency; ability to work within the continental United States

Preferred / Nice-to-Have:

  • GIAC Certified Enterprise Defender (GCED), GIAC Certified Incident Handler (GCIH), or GCFA
  • CISSP
  • Vendor credentials such as CrowdStrike Certified Falcon Administrator/Hunter or Microsoft SC-200
  • Prior experience supporting active SOC investigations in large-scale enterprise environments
  • Fluency applying AI/ML tooling (Splunk, Databricks, Elastic) to streamline security operations
Skill(s)

Technical Skills:

EDR/XDR engineering (CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne) · Behavioral threat hunting and detection authoring · Windows/Linux kernel internals and API hooking · Multi-cloud workload security (AWS, Azure, GCP) · PowerShell/Python/Bash automation · Host forensics and memory analysis · Attack simulation (BAS) and Purple Team exercises

Soft Skills:

Stakeholder empathy and business-impact analysis · Crisis leadership and composure under pressure · Cross-functional collaboration with SOC and IT Operations · Executive-level communication of technical risk

Benefits

Medical — Multiple POS health plan options including an HSA-compatible plan

Dental — PPO coverage for preventive, basic, and major services

Vision — Annual exam, frames, lenses, and contact lens allowance

401(k) — Employer match up to 5% of eligible compensation

Long-Term Disability — 100% employer-paid coverage at 50% of pre-disability earnings

Life Insurance & AD&D — 100% employer-paid coverage valued at $10,000 each

PTO — 15–25 days annually based on tenure

Paid Federal Holidays — All 11 federal holidays observed

Skills Required

  • 7+ years of progressive experience in technical cybersecurity engineering or infrastructure security roles
  • 3-5 years engineering and administering enterprise-grade EDR/XDR platforms across 50,000+ endpoints in distributed hybrid environments
  • Expert-level proficiency administering EDR/XDR platforms across Windows, macOS, Linux, and container runtime environments
  • Deep understanding of behavioral IOAs, Sysmon telemetry, and detection authoring using SQL, KQL, Splunk SPL, or YARA
  • Strong scripting ability in PowerShell, Python, or Bash for fleet-wide remediation and automation
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or equivalent practical experience
  • U.S. Citizenship or Permanent Residency
  • Ability to perform all work within the continental United States
  • GIAC GCED, GCIH, or GCFA certification
  • CISSP certification
  • CrowdStrike Certified Falcon Administrator or Hunter, or Microsoft SC-200 certification
  • Prior experience supporting active SOC investigations in large-scale enterprise environments
  • Fluency applying AI/ML tooling such as Splunk, Databricks, or Elastic to streamline security operations
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
35 Employees
Year Founded: 2018

What We Do

Dragonfly AI uses a biologically driven AI to predict attention on visual assets. Across all channels and environments, the platform can be integrated with workflows to validate decision-making with data for creative that has a higher impact and performs better. Particularly relevant for CPG and FMCG brands but can be integrated with any creative process for a new layer of data insights to support teams in optimizing creative specifically for attention

Similar Jobs

Atlassian Logo Atlassian

Head of Customer Success, EMEA

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
London, Greater London, England, GBR
11000 Employees

Atlassian Logo Atlassian

Manager, Customer Success Architects (AI)

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
London, Greater London, England, GBR
11000 Employees

Coinbase Logo Coinbase

Operations Senior Associate

Artificial Intelligence • Blockchain • Fintech • Financial Services • Cryptocurrency • NFT • Web3
Easy Apply
Remote
UK
4700 Employees
82K-91K Annually

Dropbox Logo Dropbox

Sales Operations Manager

Artificial Intelligence • Cloud • Consumer Web • Productivity • Software • App development • Data Privacy
Remote
2 Locations
2500 Employees
91K-124K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account