Transformez ce poste en entretien — un CV et une lettre de motivation conçus selon ce que cet employeur recherche.
Dyson is seeking an Endpoint Security Engineer to define hardening standards and baseline security controls across Windows, macOS, and Linux devices. You will lead risk reduction, configure Defender/EDR controls, and support incident response for a global enterprise.
The role requires 5–7 years in endpoint security, strong cross-OS expertise, and experience with security baselines, telemetry, and automation using PowerShell, Bash, or Python.
As the Endpoint Security Engineer, you are accountable for defining endpoint hardening standards and engineering baseline security controls across all Windows, macOS, and Linux device estates.
Operating as a hands-on technical lead, you will drive endpoint risk reduction across the enterprise. By configuring advanced EDR/XDR controls, managing device compliance frameworks, and supporting incident response teams, you will ensure end-user devices are continuously defended against modern compromise techniques.
In this role, you will lead and manage the following domains:
Deep understanding of OS internal security structures (Windows Defender, macOS Security Frameworks, Linux PAM/AppArmor/SELinux) and local attack mitigation controls.
Proficiency in Microsoft Defender for Endpoint, Intune, JAMF, Microsoft Security Baselines, CIS Benchmarks, and endpoint management systems.
Ability to prioritize OS-level misconfigurations and endpoint vulnerabilities based on active exploit availability and local device access rights.
Experience designing automated device compliance policies, device health attestation checks, and local privilege management controls.
Proven ability to manage endpoint security agent coverage, maintain health telemetry across global device estates, and minimize agent conflicts.
Skilled in analyzing endpoint telemetry, KQL querying, and generating clear health dashboards for device compliance and security posture.
Ability to partner with workplace platform engineering teams to push security updates and baseline policy changes without disrupting end-user productivity.
Ability to translate threat intelligence indicators (IoCs) and adversary techniques (MITRE ATT&CK) into tailored endpoint detection and block rules.
Proven ability to lead technical endpoint security workstreams, provide clear remediation directions, and mentor junior operational staff.
Experience driving security automation through script-based remediation (PowerShell, Bash, Python) and unified endpoint management integrations.
Accountability: Architect, deploy, and maintain standardized security baselines for all Windows, macOS, and Linux endpoints.
Success Measures: Greater than 98% compliance rate with established OS security baselines across the entire enterprise estate; 100% of managed devices bound by strict compliance and attestation requirements.
Accountability: Engineer Microsoft Defender capabilities, optimize detection engine rules, and ensure full agent health across all OS platforms.
Success Measures: >99% agent deployment health and active reporting across all connected devices; Dynamic detection policy coverage mapped directly against top MITRE ATT&CK techniques.
Accountability: Drive endpoint risk reduction programs aimed at mitigating configuration flaws, unpatched software, and high-risk local permissions.
Success Measures: Measurable structural reduction in high and critical endpoint security posture gaps; MTTR for critical endpoint configuration drift kept within defined SLA targets.
Dyson is an equal opportunity employer. We know that great minds don’t think alike, and it takes all kinds of minds to make our technology so unique. We welcome applications from all backgrounds and employment decisions are made without regard to race, colour, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other any other dimension of diversity.