Location: Open (Candidates must confirm 5-day onsite availability)
Preferred Location: San Francisco, CA
Secondary Locations: Austin, New York, Washington DC
Position Summary
We are seeking an experienced Endpoint Security Engineer to build, implement, and operate enterprise endpoint security capabilities across the organization. The ideal candidate will have strong expertise in endpoint security, vulnerability management, device posture enforcement, certificate management, and security automation. This role will be responsible for developing scalable security controls aligned with Zero Trust principles while ensuring compliance, operational efficiency, and audit readiness.
Key Responsibilities
- Design, implement, and maintain enterprise endpoint security standards and controls.
- Establish and manage device posture assessment and conditional access enforcement policies.
- Implement and support endpoint security technologies such as WARP, SCEP, NAC, certificate management, EDR, and device compliance solutions.
- Develop and manage vulnerability identification, prioritization, remediation, and reporting processes.
- Integrate endpoint security controls and telemetry with identity, network security, and endpoint management platforms.
- Automate compliance validation, evidence collection, remediation workflows, and operational processes.
- Define and maintain exception management processes, approval workflows, security procedures, metrics, and audit documentation.
- Collaborate with cross-functional teams to translate business and security requirements into practical technical controls.
- Monitor security posture and continuously improve endpoint protection capabilities.
Required Qualifications
- 10+ years of experience in Endpoint Security, Security Engineering, or Enterprise Security Operations.
- Strong experience designing and operating vulnerability management and remediation programs.
- Solid understanding of:
- Device Posture Management
- Conditional Access
- Certificate-Based Authentication
- Public Key Infrastructure (PKI)
- Zero Trust Security Principles
- Hands-on experience with enterprise endpoint, identity, or network security platforms.
- Experience developing automation solutions using scripting languages such as Python, PowerShell, or Bash.
- Proven ability to implement security controls that balance risk reduction and business requirements.
- Strong analytical, troubleshooting, and problem-solving skills.
Preferred Qualifications
- Experience with:
- SCEP
- Network Access Control (NAC)
- Kandji
- Jamf
- Experience with identity and access management platforms such as Okta or equivalent enterprise identity solutions.
- Exposure to Infrastructure as Code (IaC) and Git-based deployment methodologies.
- Experience working within high-growth or rapidly scaling organizations.
- Relevant security certifications such as CISSP, Security+, CCSP, GIAC, or equivalent.