Endpoint Security Engineer (8+years, CrowdStrike Falcon, Microsoft Defender, Sen

Summary

The Endpoint Security Engineer will design, deploy, and manage behavior-based endpoint detection and response capabilities for a federal client. The role involves using tools like CrowdStrike Falcon, Microsoft Defender, SentinelOne, and Splunk to secure large-scale enterprise networks.

Summary: Triangle Cyber is seeking an Endpoint Security Engineer for a federal client to design, deploy, and operationalize active, behavior-based endpoint detection and response capabilities across a large enterprise network. Leveraging platforms like CrowdStrike Falcon, Microsoft Defender, SentinelOne, and Splunk, you will play a pivotal role in safeguarding this expansive network.

Responsibilities:

  • Engineer, deploy, and maintain Next-Gen Antivirus (NGAV) and Endpoint Detection & Response (EDR/XDR) agents across a diverse range of endpoints.
  • Implement behavioral protections against zero-day malware and advanced persistent threats.
  • Collaborate with application owners and business units to establish baseline behavior profiles.
  • Manage allowlisting, exception workflows, and phased ring deployments to ensure seamless protection.
  • Support SOC investigations and collaborate with system owners for enterprise security.

Requirements:

  • U.S. Citizenship required.
  • 8+ years of relevant experience in cybersecurity engineering or infrastructure security roles.
  • Experience with enterprise-grade EDR/XDR platforms (CrowdStrike Falcon, Microsoft Defender, and/or SentinelOne SIEM) across extensive endpoint environments
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or equivalent experience (17 years total).
  • Proficiency in administering endpoint platforms across various operating systems.
  • Expertise in behavioral analysis, threat hunting, and using query languages like SQL, KQL, and YARA.
  • Strong programming skills in PowerShell, Python, or Bash for automation.
  • Fluency in using AI/ML technologies to automate security activities.
  • Ability to balance security controls with business operations, ensuring minimal disruption.
  • Experience in crisis leadership, operational scale management, and policy automation.

Preferred:

  • GIAC Certified Enterprise Defender (GCED), GCIH, or GCFA certification.
  • CISSP certification.
  • Vendor-specific credentials, such as CrowdStrike Certified Falcon Administrator or Microsoft Certified: Security Operations Analyst Associate.

Triangle Cyber, LLC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to any legally protected status.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available