Endpoint Security Engineer

PlanIT Group

Reston, Northern (VA, KY)

Hybrid

USD 120,000 - 160,000

Full time

4 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

PlanIT Group in Reston, VA seeks an Endpoint Security Engineer to design, deploy, and operationalize EDR/XDR capabilities across a large, distributed fleet. You will work with EUC devices, on-premises servers, and multi-cloud workloads to maintain a strong security posture while minimizing business disruption.

You will partner with application owners and SOC teams, handle advanced forensics, threat hunting, and automated remediation, and contribute to policy tuning and evidence-based reporting.

Qualifications

  • 7+ years in technical cybersecurity engineering or infrastructure security roles.
  • 3–5 years engineering and administering EDR/XDR platforms across 50k+ endpoints.
  • Experience supporting active SOC investigations and cross-functional collaboration with system owners.
  • Bachelor's degree in CS, Cybersecurity, Information Systems (or 4 extra years of related experience).
  • GIAC/CISSP or vendor credentials are a plus.

Responsibilities

  • Design, deploy, and maintain NGAV and EDR/XDR agents across endpoints.
  • Implement protections against zero-day malware, LOTLBs, fileless execution, credential dumping.
  • Partner with application owners to minimize false positives and downtime.
  • Serve as escalation lead for SOC analysts and IT operations during high-severity events.
  • Extend security to multi-cloud workloads and private data centers.
  • Measure and validate control efficacy with automated attack simulations and telemetry monitoring.

Skills

EDR/XDR Engineering
Behavioral Analysis & Threat Hunting
Hybrid Infrastructure & OS Internals
Automation & Scripting
AI/ML in Security

Education

Bachelor's degree (CS/Cybersecurity/IS)

Tools

CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne

Job description

Reston, VA Contract On-Site Flexibility/Remote: 100%

Endpoint Security Engineer

As an Endpoint Security Engineer, you will design, deploy, and operationalize active, behavior-based endpoint detection and response (EDR/XDR) capabilities across one of the largest private operational fleets in North America. Protecting an enterprise comprising 600,000+ employees and 30,000+ physical sites, you will maintain rigorous security posture across traditional end-user computing (EUC) devices (laptop, desktop, mobile devices & retail terminals), on-premise physical & virtual servers & containerized workloads, and dynamic multi-cloud workloads (AWS, Azure, GCP).

In this role, you will balance proactive protection with business continuity—partnering directly with end-users and application owners to tune policies and eliminate operational friction, while providing tier-3/tier-4 technical escalations to Security Operations Center (SOC) analysts and IT Operations staff during active investigations.

Duties and Responsibilities
Fleet-Wide Behavioral Defense & Control Engineering

Engineer, deploy, and maintain Next-Gen Antivirus (NGAV) and Endpoint Detection & Response (EDR/XDR) agents (e.g., CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne) across hundreds of thousands of heterogeneous endpoints.

Implement active behavioral protections against zero-day malware, living-off-the-land binaries (LotLBs), fileless execution, and credential dumping.

Application Owner & End-User Engagement (Business Impact Management)

Serve as the primary technical partner to application owners and business units, establishing baseline behavior profiles to minimize false positives, performance degradation, or operational downtime across critical retail, logistics, and supply chain applications.

Manage allowlisting, exception workflows, and phased ring deployments (canary/pilot/production) to ensure silent, high-efficacy protection without disrupting day-to-day warehouse or logistics operations.

SOC & IT Operations Event Investigation Support

Act as endpoint security escalation lead for SOC analysts during high-severity threat detection and response events.

Act as endpoint operations escalation lead for IT administrators during high-impact event investigation and remediation efforts.

Perform advanced host forensics, process-tree reconstruction, memory analysis, and script-based live remediation (e.g., host isolation, automated artifact collection, registry rollbacks).

Hybrid & Multi-Cloud Workload Protection

Extend endpoint security standards across private data center virtualization layers (VMware/Nutanix) and episodic multi-cloud infrastructure (EC2, Azure VMs, Compute Engine, containerized hosts).

Control Efficacy & Continuous Validation

Continuously measure and test security control efficacy using automated attack simulation (Client) tools and Purple Team exercises.

Track and report on agent health, tamper-resistance, telemetry pipeline integrity, and coverage metrics aligned with enterprise asset management systems.

Required Knowledge, Skills, and Abilities (KSAs)
Technical Skills

EDR/XDR Engineering: Expert-level proficiency administering enterprise-scale endpoint platforms across Windows, macOS, Linux distributions, and container runtime environments.

Behavioral Analysis & Threat Hunting: Deep mastery of process lineage, behavioral IOAs (Indicators of Attack), Sysmon telemetry, and detection authoring using query languages such as SQL, KQL (Kusto Query Language), Splunk SPL, or YARA.

Hybrid Infrastructure & OS Internals: Deep understanding of Windows/Linux kernel architectures, API hooking, hypervisor isolation, and multi-cloud workload identity integrations.

Automation & Scripting: Strong programming/scripting abilities in PowerShell, Python, or Bash to orchestrate fleet-wide remediations and automate policy compliance at scale.

Artificial Intelligence & Machine Learning: Fluency applying appropriate AI/ML technologies and analytics platforms (Splunk, Databricks, Elastic) to streamline and/or automate activities including but not limited to research, developing documentation, and supporting development of executive communications. Fluency applying appropriate AI/ML technologies to automate security activities to improve timeliness or full automation of event response activities.

Abilities & Core Competencies
Stakeholder Empathy & Impact Analysis

Proven ability to balance stringent security controls with business operational velocity, ensuring minimal disruption to end-user productivity and mission-critical COTS/proprietary software.

Crisis Leadership & Composure: Capable of methodically triaging active enterprise threats under pressure and articulating complex host-based attacks to executive leadership.

Operational Scale Management: Mindset geared toward 'Infrastructure-as-Code' and policy automation rather than manual device-by-device intervention.

Required Education and Experience Requirements

Experience: * 7+ years of progressive experience in technical cybersecurity engineering or infrastructure security roles.

At least 3–5 years directly engineering and administering enterprise-grade EDR/XDR platforms across 50,000+ endpoints in a distributed hybrid environment.

Demonstrated track record supporting active SOC investigations and collaborating cross-functionally with system owners in large-scale enterprise environments.

Education: *Bachelor's degree in Computer Science, Cybersecurity, Information Systems. If the individual's degree is not in the applicable field then four additional years of related experience is required.

Preferred Certifications
  • GIAC Certified Enterprise Defender (GCED), GIAC Certified Incident Handler (GCIH), or GCFA (Forensic Analyst).
  • CISSP (Certified Information Systems Security Professional).
  • Specialized Vendor Engineering Credentials (e.g., CrowdStrike Certified Falcon Administrator/Hunter, Microsoft Certified: Security Operations Analyst Associate / SC-200).
Additional Provisions
  • Pass a client mandated clearance process to include drug screening, criminal history check and credit check.
  • Once candidate's resume is approved and interview passed, the agency is responsible for providing drug screening. Failure to submit the drug screening results will delay the security clearance process.
  • If a candidate is given an interim clearance, continuation of employment is then based on the candidate receiving a sensitive clearance.
  • All candidates must be a US Citizen or permanent status Green Card holder.
  • Cannot have more than 6 months travel outside the United States within the last five years. Military Service excluded. (Exception does not include military family members).
  • All overtime must be pre-approved in writing by the client manager or his/her designated representative.
  • Agency will not be reimbursed for overtime charges without previous written authorization. Authorized overtime will be reimbursed at straight time.
  • The enforced dress code is business casual, i.e., collared shirt with slacks for men, no skirts above the knee for women.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Endpoint Security Engineer
Endpoint Security Engineer

Socket.dev • Washington

On-site
USD 150,000 - 190,000
Medical — Health plan options
Dental — PPO coverage
Vision — annual exam & allowances
+5
Endpoint Security Engineer
Endpoint Security Engineer

NikSoft Systems Corp • United States

On-site
USD 120,000 - 190,000
Endpoint Security Engineer (EDR/XDR)
Endpoint Security Engineer (EDR/XDR)

NikSoft Systems Corporation • United States

On-site
USD 140,000 - 180,000
Endpoint Security Engineer
Endpoint Security Engineer

Castalia Systems • Morrisville (NC)

On-site
USD 140,000 - 190,000
Medical coverage
Dental coverage
Vision coverage
+5
Associate Security Engineer, Security Control Management
Associate Security Engineer, Security Control Management

CyberMaxx • Maryland

On-site
USD 75,000 - 85,000
Flexible Paid Time Off
401k with company match
Medical, Dental and Vision Coverage
+3
Security Engineer, Security Control Management
Security Engineer, Security Control Management

CyberMaxx, Inc. • Northern (KY)

Hybrid
USD 65,000 - 95,000
Flexible Paid Time Off
401k with a company match
Medical, Dental and Vision Coverage
+1
Endpoint Engineer III
Endpoint Engineer III

Socket.dev • Virginia (IL)

Hybrid
USD 130,000 - 160,000
Cybersecurity Engineer
Cybersecurity Engineer

Vortalsoft Inc • New Jersey

On-site
USD 90,000 - 130,000
Security Engineer
Security Engineer

Eleven Recruiting • San Francisco (CA)

On-site
USD 120,000 - 160,000
Cyber Security Engineer
Cyber Security Engineer

Beta Eight • Hicksville (NY)

On-site
USD 120,000 - 180,000