Lead Engineer – Endpoint Security

Dyson GmbH

Kuala Lumpur

Sur place

MYR 120 000 - 240 000

Plein temps

Il y a 3 jours
Soyez parmi les premiers à postuler
Générateur de candidature

Transformez ce poste en entretien — un CV et une lettre de motivation conçus selon ce que cet employeur recherche.

Passez les filtres ATS

Résumé du poste

Dyson is seeking an Endpoint Security Engineer to define hardening standards and baseline security controls across Windows, macOS, and Linux devices. You will lead risk reduction, configure Defender/EDR controls, and support incident response for a global enterprise.

The role requires 5–7 years in endpoint security, strong cross-OS expertise, and experience with security baselines, telemetry, and automation using PowerShell, Bash, or Python.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent practical experience).
  • A minimum of 5-7 years' technical experience in endpoint security engineering, OS hardening, and endpoint management at scale.
  • Deep engineering knowledge of multi-OS security architectures (Windows, macOS, Linux) and cross-platform EDR deployment.
  • Relevant certifications such as Microsoft Certified: Security Operations Analyst Associate (SC-200), GIAC Endpoint Asset Protection (GCED), or CISSP are highly desirable.

Responsabilités

  • Define, implement, and enforce security baselines across Windows, macOS, and Linux fleets.
  • Manage and tune Defender endpoints and security capabilities.
  • Design and enforce device compliance policies.
  • Lead vulnerability and posture reduction initiatives.
  • Conduct endpoint security reviews and support incident response.
  • Automate remediation and integrate security tooling.

Connaissances

Endpoint security
OS hardening
Endpoint management
Multi-OS security
EDR deployment
Threat intel integration
Leadership

Formation

Bachelor's degree in Computer Science, IT, Cybersecurity, or related field

Outils

Microsoft Defender for Endpoint
Intune
JAMF
Microsoft Security Baselines
CIS Benchmarks
Endpoint management systems

Description du poste

Role Purpose

As the Endpoint Security Engineer, you are accountable for defining endpoint hardening standards and engineering baseline security controls across all Windows, macOS, and Linux device estates.

Operating as a hands-on technical lead, you will drive endpoint risk reduction across the enterprise. By configuring advanced EDR/XDR controls, managing device compliance frameworks, and supporting incident response teams, you will ensure end-user devices are continuously defended against modern compromise techniques.

In this role, you will lead and manage the following domains:

  • Endpoint Hardening & Baselines: Defining, implementing, and enforcing security baselines across Windows, macOS, and Linux fleets.
  • EDR/XDR Control Engineering: Managing and tuning Microsoft Defender endpoints and security capabilities.
  • Device Compliance Frameworks: Designing compliance policies that enforce endpoint health prior to granting corporate resource access.
  • Vulnerability & Posture Reduction: Leading targeted initiatives to mitigate system vulnerabilities, OS flaws, and configuration drift.
  • Security Reviews & Incident Support: Conducting technical endpoint security reviews and assisting incident response teams during major investigations.
Key Skills & Qualifications
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent practical experience).
  • A minimum of 5-7 years' technical experience in endpoint security engineering, OS hardening, and endpoint management at scale.
  • Deep engineering knowledge of multi-OS security architectures (Windows, macOS, Linux) and cross-platform EDR deployment.
  • Relevant certifications such as Microsoft Certified: Security Operations Analyst Associate (SC-200), GIAC Endpoint Asset Protection (GCED), or CISSP are highly desirable.
Security Expertise & Architecture

Deep understanding of OS internal security structures (Windows Defender, macOS Security Frameworks, Linux PAM/AppArmor/SELinux) and local attack mitigation controls.

Tooling & Technical Proficiency

Proficiency in Microsoft Defender for Endpoint, Intune, JAMF, Microsoft Security Baselines, CIS Benchmarks, and endpoint management systems.

Risk Management & Prioritisation

Ability to prioritize OS-level misconfigurations and endpoint vulnerabilities based on active exploit availability and local device access rights.

Governance, Process & Control Design

Experience designing automated device compliance policies, device health attestation checks, and local privilege management controls.

Service Delivery & Operational Management

Proven ability to manage endpoint security agent coverage, maintain health telemetry across global device estates, and minimize agent conflicts.

Data Analysis, Reporting & Insight

Skilled in analyzing endpoint telemetry, KQL querying, and generating clear health dashboards for device compliance and security posture.

Stakeholder Management & Influence

Ability to partner with workplace platform engineering teams to push security updates and baseline policy changes without disrupting end-user productivity.

Threat Intelligence Integration

Ability to translate threat intelligence indicators (IoCs) and adversary techniques (MITRE ATT&CK) into tailored endpoint detection and block rules.

Leadership & Collaboration

Proven ability to lead technical endpoint security workstreams, provide clear remediation directions, and mentor junior operational staff.

Continuous Improvement & Automation

Experience driving security automation through script-based remediation (PowerShell, Bash, Python) and unified endpoint management integrations.

Key Accountabilities & Success Measures
Endpoint Hardening & Security Baselines

Accountability: Architect, deploy, and maintain standardized security baselines for all Windows, macOS, and Linux endpoints.

Success Measures: Greater than 98% compliance rate with established OS security baselines across the entire enterprise estate; 100% of managed devices bound by strict compliance and attestation requirements.

Defender Suite Engineering & Telemetry

Accountability: Engineer Microsoft Defender capabilities, optimize detection engine rules, and ensure full agent health across all OS platforms.

Success Measures: >99% agent deployment health and active reporting across all connected devices; Dynamic detection policy coverage mapped directly against top MITRE ATT&CK techniques.

Vulnerability & Risk Reduction Initiatives

Accountability: Drive endpoint risk reduction programs aimed at mitigating configuration flaws, unpatched software, and high-risk local permissions.

Success Measures: Measurable structural reduction in high and critical endpoint security posture gaps; MTTR for critical endpoint configuration drift kept within defined SLA targets.

Equal Opportunity Employer

Dyson is an equal opportunity employer. We know that great minds don’t think alike, and it takes all kinds of minds to make our technology so unique. We welcome applications from all backgrounds and employment decisions are made without regard to race, colour, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other any other dimension of diversity.

Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Lead Engineer – Cloud & Endpoint
Lead Engineer – Cloud & Endpoint

Dyson GmbH • Kuala Lumpur

Sur place
MYR 180 000 - 300 000
Cybersecurity Engineer
Cybersecurity Engineer

Prometric • Kuala Lumpur

Sur place
MYR 120 000 - 180 000
Senior Endpoint Security Engineer
Senior Endpoint Security Engineer

Dyson GmbH • Kuala Lumpur

Sur place
MYR 120 000 - 240 000
Lead Engineer – Multi-Platform Endpoint
Lead Engineer – Multi-Platform Endpoint

Dyson GmbH • Kuala Lumpur

Sur place
MYR 120 000 - 180 000
EndPoint Security Subject Matter Expert
EndPoint Security Subject Matter Expert

DXC Technology • Petaling Jaya

Sur place
MYR 120 000 - 180 000
DXC University
Flexible leave options
Volunteer days
Lead Engineer – Endpoint Security
Lead Engineer – Endpoint Security

Dyson Institute • Kuala Lumpur

Sur place
MYR 150 000 - 210 000
Health insurance
Employee banking benefits
Lead Endpoint Security Engineer
Lead Endpoint Security Engineer

Dyson Institute • Kuala Lumpur

Sur place
MYR 150 000 - 210 000
Health insurance
Employee banking benefits
Endpoint, Network & IPS Security Subject Matter Expert
Endpoint, Network & IPS Security Subject Matter Expert

MY20 EntServ Malaysia Sdn. Bhd. • Petaling Jaya

Sur place
MYR 120 000 - 180 000
DXC University
Flexible leave options
Volunteer days
+1
Principal – Workspace Security Architecture and Engineering
Principal – Workspace Security Architecture and Engineering

Dyson GmbH • Kuala Lumpur

Sur place
MYR 360 000 - 520 000
Windows OS/ Desktop Security Developer
Windows OS/ Desktop Security Developer

Aventra Group • Kuala Lumpur

Sur place
MYR 60 000 - 80 000
Competitive compensation and benefits
Training and certification support
Career growth opportunities