Endpoint Security Engineer

Socket.dev

Washington (District of Columbia)

On-site

USD 150,000 - 190,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical — Health plan options
Dental — PPO coverage
Vision — annual exam & allowances
401(k) — employer match
Long-Term Disability — employer-paid
Life Insurance & AD&D — employer-paid
PTO — 15-25 days
Paid Federal Holidays — 11 holidays

Job summary

Dragonfli Group in Washington, DC is seeking an experienced Endpoint Security Engineer to design, deploy, and operationalize EDR/XDR capabilities protecting a large private and federal-facing fleet across on-prem, cloud, and hybrid environments.

You will partner with application owners to tune policies, drive automation via infrastructure-as-code, and provide tier-3/4 escalation support during active investigations within a multi-year federal contract.

Qualifications

  • 7+ years in technical cybersecurity engineering or infrastructure security roles.
  • 3–5 years engineering and administering EDR/XDR platforms across 50,000+ endpoints.
  • Expert-level proficiency across Windows, macOS, Linux and container runtimes.
  • Deep understanding of behavioral IOAs, Sysmon telemetry, and detection authoring (SQL, KQL, SPL, YARA).
  • Strong scripting ability in PowerShell, Python, or Bash for fleet-wide automation.
  • Bachelor’s degree and U.S. citizenship or PR; ability to work within the continental U.S.

Responsibilities

  • Engineer, deploy, and maintain NGAV and EDR/XDR agents across hundreds of thousands of endpoints.
  • Implement active protections against zero-day malware, LOtL binaries, fileless execution, credential dumping.
  • Partner with application owners to establish baseline behavior profiles to minimize false positives.
  • Manage allowlisting, exception workflows, and phased ring deployments (canary/pilot/production).
  • Act as endpoint security escalation lead for SOC analysts during high-severity events.
  • Perform advanced host forensics, memory analysis, and live remediation scripting.
  • Extend endpoint security standards across private data centers and multi-cloud infra.
  • Validate control efficacy using BAS tools and Purple Team exercises.
  • Track agent health, tamper-resistance, telemetry integrity, and coverage metrics.

Skills

EDR/XDR engineering
Behavioral threat hunting
Windows/Linux kernel internals
Multi-cloud security
Automation scripting
Host forensics & memory analysis
Attack simulation / BAS
Policy & baseline development

Education

Bachelor's degree in CS/Cybersecurity/IS or equivalent

Tools

CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne
Splunk
Databricks
Elastic
VMware/Nutanix

Job description

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.

As an Endpoint Security Engineer, you'll design, deploy, and operationalize behavior-based endpoint detection and response (EDR/XDR) capabilities protecting one of the largest private operational fleets in North America — spanning hundreds of thousands of end-user devices, on-premise and virtual servers, and multi-cloud workloads across AWS, Azure, and GCP. You'll partner directly with application owners to tune policies and eliminate friction, while providing tier-3/tier-4 technical escalation support to SOC analysts and IT Operations during active investigations. This is a high-visibility engineering role for someone who thinks in terms of infrastructure-as-code and policy automation rather than device-by-device intervention.

This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.

Responsibilities:
  • Engineer, deploy, and maintain Next-Gen Antivirus (NGAV) and EDR/XDR agents across hundreds of thousands of heterogeneous endpoints
  • Implement active behavioral protections against zero-day malware, living-off-the-land binaries, fileless execution, and credential dumping
  • Serve as primary technical partner to application owners and business units, establishing baseline behavior profiles to minimize false positives and operational disruption
  • Manage allowlisting, exception workflows, and phased ring deployments (canary/pilot/production)
  • Act as endpoint security escalation lead for SOC analysts and IT administrators during high-severity events
  • Perform advanced host forensics, process-tree reconstruction, memory analysis, and script-based live remediation
  • Extend endpoint security standards across private data center virtualization (VMware/Nutanix) and multi-cloud infrastructure
  • Continuously validate control efficacy using automated attack simulation (BAS) tools and Purple Team exercises
  • Track and report on agent health, tamper-resistance, telemetry integrity, and coverage metrics

Requirements

Must-Have:

  • 7+ years of progressive experience in technical cybersecurity engineering or infrastructure security roles
  • 3-5 years directly engineering and administering enterprise-grade EDR/XDR platforms across 50,000+ endpoints in a distributed hybrid environment
  • Expert-level proficiency administering EDR/XDR platforms across Windows, macOS, Linux, and container runtime environments
  • Deep understanding of behavioral IOAs, Sysmon telemetry, and detection authoring (SQL, KQL, Splunk SPL, or YARA)
  • Strong scripting ability in PowerShell, Python, or Bash for fleet-wide remediation and automation
  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or equivalent practical experience
  • U.S. Citizenship or Permanent Residency; ability to work within the continental United States

Preferred / Nice-to-Have:

  • GIAC Certified Enterprise Defender (GCED), GIAC Certified Incident Handler (GCIH), or GCFA
  • CISSP
  • Vendor credentials such as CrowdStrike Certified Falcon Administrator/Hunter or Microsoft SC-200
  • Prior experience supporting active SOC investigations in large-scale enterprise environments
  • Fluency applying AI/ML tooling (Splunk, Databricks, Elastic) to streamline security operations

Skill(s)

Technical Skills:

EDR/XDR engineering (CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne) · Behavioral threat hunting and detection authoring · Windows/Linux kernel internals and API hooking · Multi-cloud workload security (AWS, Azure, GCP) · PowerShell/Python/Bash automation · Host forensics and memory analysis · Attack simulation (BAS) and Purple Team exercises

Soft Skills:

Stakeholder empathy and business-impact analysis · Crisis leadership and composure under pressure · Cross-functional collaboration with SOC and IT Operations · Executive-level communication of technical risk


Benefits

Medical — Multiple POS health plan options including an HSA-compatible plan

Dental — PPO coverage for preventive, basic, and major services

Vision — Annual exam, frames, lenses, and contact lens allowance

401(k) — Employer match up to 5% of eligible compensation

Long-Term Disability — 100% employer-paid coverage at 50% of pre-disability earnings

Life Insurance & AD&D — 100% employer-paid coverage valued at $10,000 each

PTO — 15-25 days annually based on tenure

Paid Federal Holidays — All 11 federal holidays observed


Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Endpoint Security Engineer
Endpoint Security Engineer

PlanIT Group • Reston (VA), Northern (KY)

Hybrid
USD 120,000 - 160,000
Endpoint Security Engineer
Endpoint Security Engineer

NikSoft Systems Corp • United States

On-site
USD 120,000 - 190,000
Endpoint Security Engineer (EDR/XDR)
Endpoint Security Engineer (EDR/XDR)

NikSoft Systems Corporation • United States

On-site
USD 140,000 - 180,000
Security Engineer, Security Control Management
Security Engineer, Security Control Management

CyberMaxx, Inc. • Northern (KY)

Hybrid
USD 65,000 - 95,000
Flexible Paid Time Off
401k with a company match
Medical, Dental and Vision Coverage
+1
Endpoint Security Engineer
Endpoint Security Engineer

Castalia Systems • Morrisville (NC)

On-site
USD 140,000 - 190,000
Medical coverage
Dental coverage
Vision coverage
+5
Cyber Security Engineer
Cyber Security Engineer

Beta Eight • Hicksville (NY)

On-site
USD 120,000 - 180,000
Endpoint Detection & Response Engineer, Senior
Endpoint Detection & Response Engineer, Senior

Booz Allen Hamilton • Shiloh (IL)

On-site
USD 86,000 - 198,000
Health insurance
Tuition assistance
Paid leave
+1
Endpoint Detection & Response Engineer, Senior
Endpoint Detection & Response Engineer, Senior

Booz Allen Hamilton • Illinois

On-site
USD 86,000 - 198,000
Health insurance
Professional development
Tuition assistance
Associate Security Engineer, Security Control Management
Associate Security Engineer, Security Control Management

CyberMaxx • Maryland

On-site
USD 75,000 - 85,000
Flexible Paid Time Off
401k with company match
Medical, Dental and Vision Coverage
+3
Endpoint Engineer III
Endpoint Engineer III

Socket.dev • Virginia (IL)

Hybrid
USD 130,000 - 160,000