Cybersecurity Engineer – Endpoint & User Security
Job Overview
Prometric is seeking a Cybersecurity Engineer with a primary focus on endpoint security, device management, and data protection technologies. This role is responsible for securing and managing enterprise endpoints using Microsoft Defender, Intune, Purview, and related Microsoft security technologies. The engineer will design, implement, and maintain security controls for corporate and BYOD environments while supporting compliance, threat detection, incident response, and endpoint hardening initiatives.
The ideal candidate combines strong technical expertise with a proactive security mindset and the ability to work across IT, Infrastructure, Identity Management, Compliance, and Security Operations teams.
Primary Responsibilities
Endpoint Security Administration
- Design, deploy, and manage Microsoft Defender for XDR across Windows, macOS, and mobile devices using Intune and Conditional Access policies.
- Monitor endpoint security alerts, investigate threats, and coordinate remediation activities.
- Develop and maintain endpoint protection policies, attack surface reduction rules, and endpoint hardening standards.
- Optimize Defender configurations to improve threat detection while minimizing operational impact.
Device Management & Intune
- Administer Microsoft Intune for endpoint configuration, compliance, application deployment, and lifecycle management.
- Develop and maintain device compliance policies, security baselines, and configuration profiles.
- Support Autopilot provisioning and device enrollment processes.
- Manage patching and update policies for corporate endpoints.
BYOD & Mobile Security
- Design and maintain secure BYOD and mobile device management solutions.
- Implement Conditional Access, device compliance, and application protection policies.
- Support secure access controls for personally owned devices accessing corporate resources.
- Evaluate emerging mobile security capabilities and recommend improvements.
Data Protection & Purview
- Administer and support Microsoft Purview capabilities including Information Protection, Data Lifecycle Management, Data Loss Prevention, Records Management, Insider Risk Management, and eDiscovery.
- Design and maintain data classification frameworks, sensitivity labels, retention policies, and information governance controls across Microsoft 365.
- Partner with Legal, Privacy, Compliance, and Security teams to implement data protection and regulatory compliance requirements.
- Support investigations, legal holds, eDiscovery requests, and data governance initiatives.
Identity & User Security
- Investigate and respond to user identity security events including risky sign-ins, impossible travel, unfamiliar sign-ins, compromised accounts, and suspicious authentication activity.
- Support secure user lifecycle processes including privileged access, MFA, Conditional Access, password resets, and account recovery.
- Investigate identity-related alerts generated through Microsoft Defender for Identity and Microsoft Entra ID.
- Partner with the Service Desk to improve identity security processes.
Email Security
- Administer Microsoft Defender for Office 365, Proofpoint, and Abnormal Security.
- Manage email authentication technologies including SPF, DKIM, and DMARC.
- Investigate phishing campaigns, malicious emails, spoofing attempts, and business email compromise incidents.
- Tune email security policies to improve detection while reducing false positives.
Continuous Improvement
- Research emerging endpoint threats and security technologies.
- Identify opportunities for automation and process improvement.
- Participate in incident response investigations involving endpoint, device, or data security events.
- Provide technical guidance and mentorship to junior team members and IT staff.
Required Qualifications
- Bachelor's degree in Information Security, Computer Science, Information Technology, or related field (or equivalent experience).
- 3–5+ years of cybersecurity or endpoint engineering experience.
- Hands‑on experience managing Microsoft Defender for XDR and Endpoint.
- Hands‑on experience administering Microsoft Intune in an enterprise environment.
- Experience in implementing and managing Microsoft Purview DLP and Information Protection.
- Strong understanding of Windows endpoint security, device management, and modern authentication.
- Experience with Conditional Access, MFA, endpoint compliance, and Zero Trust principles.
- Knowledge of endpoint hardening methodologies and security frameworks.
- Strong troubleshooting, documentation, and communication skills.
Preferred Qualifications
- Microsoft Security certifications (SC-200, SC-300, SC-400, AZ-500, MD-102, or equivalent).
- Experience with Defender XDR and Microsoft Security Copilot.
- Experience supporting BYOD and mobile security programs.
- Experience with identity security technologies including Entra ID, PIM, and Conditional Access.
- Familiarity with ISO 27001, NIST Cybersecurity Framework, PCI DSS, or SOC 2 requirements.