An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Grant Thornton International in Poznań is seeking an Endpoint Security Engineer to maintain the endpoint protection estate. You will deploy and troubleshoot agents across workstations and servers, implement policy changes, and triage alerts, while collaborating with LATAM/EMEA/NA teams to meet service levels.
The role emphasizes Windows administration with cross-platform familiarity (macOS/Linux), scripting in PowerShell, Bash, or Python, and fluency in English and Polish.
The Engineer for Endpoint Security keeps the endpoint protection estate healthy and current. The role handles agent deployment and remediation, executes policy changes designed with the senior engineers, and resolves the day-to-day exceptions raised by service desk and operations teams. It suits an engineer who has a solid grounding in endpoint administration and wants to develop into a specialist security engineering career.
Deploy, upgrade, and troubleshoot endpoint security agents across workstations and servers, and drive agent coverage and health metrics to target.
Implement approved policy, exclusion, and device control changes through the standard change process, with testing evidence and rollback plans.
Triage endpoint alerts and platform tickets, resolving routine issues directly and escalating complex detections with a clear technical summary.
Reconcile endpoint coverage against the asset inventory, investigate unprotected and stale hosts, and report gaps to the platform owner.
Maintain runbooks and knowledge base articles for recurring endpoint issues, and contribute scripts that reduce manual handling.
Three or more years in information technology, including at least one year working directly with endpoint security or systems management tooling .
Practical administration experience with an endpoint detection and response or anti-malware console, and with an enterprise software deployment tool such as Intune or SCCM.
Sound knowledge of Windows administration, with working familiarity with macOS or Linux endpoints.
Scripting ability in PowerShell, Bash, or Python sufficient to automate routine tasks and parse platform output.
Security certification such as CompTIA Security+, Microsoft SC-200, or a vendor endpoint certification.
Exposure to security operations center workflows, ticketing platforms, and change management in a regulated environment.
This role sits within the Information Security Platform Engineering function and shares a common operating model with the wider team. Engineers own the security platforms they build end to end: design, deployment, day-to-day operation, tuning, and lifecycle management. Work is delivered against agreed service levels and measured on control coverage, platform availability, and the quality of detection and prevention outcomes. Because the teams are distributed across LATAM, EMEA, and North America, all roles require reliable overlap with United States business hours and fluent written and spoken English.
Operate assigned security platforms as a service, including capacity planning, patching, upgrades, health monitoring, and vendor case management.
Automate repetitive configuration and operational tasks, and treat platform configuration as code wherever the tooling supports it.
Support incident response and forensic investigations with platform expertise , evidence, and rapid containment actions.
Maintain runbooks, architecture diagrams, and control documentation to a standard that satisfies internal audit and external assessment.
Participate in an on-call rotation and in scheduled change windows, including occasional work outside standard business hours.