Endpoint Security Engineer III

Blue Origin LLC

United States

On-site

USD 150,000 - 190,000

Full time

10 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Blue Origin is seeking a senior member of the Enterprise Technology team to lead endpoint security across the fleet. You will own Defender for Endpoint, Tanium, and related tooling, and partner with engineering to secure our digital infrastructure in support of spaceflight missions.

The role emphasizes technical leadership, mentoring teammates, designing scalable security content, and ensuring posture against CIS/NIST benchmarks.

Qualifications

  • Experience building and maintaining endpoint security programs.
  • Ability to mentor engineers and lead security initiatives.
  • Familiarity with CIS, DISA STIG, NIST controls.

Responsibilities

  • Own endpoint detection and response coverage across the fleet.
  • Monitor sensor health and reconcile Defender coverage with inventory.
  • Manage antivirus policies and configuration settings.
  • Develop and maintain advanced hunting queries.
  • Contribute to endpoint security roadmap and best practices.
  • Provide technical leadership and mentorship.

Skills

Endpoint security
Technical leadership
Threat detection
Mentoring

Tools

Microsoft Defender for Endpoint
Tanium

Job description

Application close date: Applications will be accepted on an ongoing basis until the requisition is closed. At Blue Origin, we envision millions of people living and working in space for the benefit of Earth. We’re working to develop reusable, safe, and low-cost space vehicles and systems within a culture of safety, collaboration, and inclusion. Join our team of problem solvers as we add new chapters to the history of spaceflight! This role is part of Enterprise Technology (ET), where we’re developing the digital infrastructure needed to build the road to space, with an emphasis on digital capabilities required to advance Blue Origin’s mission. Enterprise Technology is the center of excellence for digital technology at Blue Origin, providing oversight and governance to align technology and business strategies. As part of a small, accomplished team of experts, you will protect and secure the endpoints that Blue Origin's engineers, technicians, and business teams depend on every day.

Responsibilities
  • Microsoft Defender for Endpoint - Own endpoint detection and response coverage across the fleet: onboarding and offboarding, agent lifecycle, platform build currency, and tamper protection, on Windows, macOS, and Linux.
  • Monitor and remediate sensor health, and continuously reconcile Defender coverage against authoritative inventory so that unmonitored endpoints are found and fixed rather than discovered during an incident.
  • Manage antivirus and protection policy — scan behavior, definition currency, at tack surface reduction rules, exclusions, and platform-specific configuration — balancing security outcome against engineering workload impact.
  • Write and maintain advanced hunting queries to answer posture and exposure questions, and understand the limits of what endpoint telemetry can and cannot show.
  • Operate diagnostic tooling (client analyzers and equivalent) and drive vendor cases to resolution when platform defects affect the fleet.
  • Act on security recommendations and vulnerability findings surfaced by the platform, prioritizing by real exposure rather than raw score.
  • Tanium - Own the architecture, configuration, and operation of the enterprise endpoint management and security platform, including content, permissions, and shared services.
  • Author and maintain platform content — sensors, packages, and saved questions — that returns correct answers across every supported operating system, including multi-distribution Linux.
  • Design and maintain the role-based access model: roles, personas, user groups, computer groups, and filter groups, scoped to least privilege across multiple consuming organizations.
  • Configure action groups and targeting tiers so that change lands predictably and progressively across the fleet.
  • Use the platform as the fleet's measurement and remediation instrument: build the content that reports security posture and closes the gap between "we have a policy" and "we can prove it is applied."
  • Posture reporting, requirements, and documentation - Instrument the fleet to report security posture against recognized benchmarks (CIS, DISA STIG) and to evidence control implementation for compliance obligations, including NIST 800-series and ISO 27000-series requirements.
  • Report on the state of adjacent security controls owned by partner engineers — including disk encryption and device control — using Defender and Tanium telemetry, so that coverage gaps are visible without duplicating ownership of those platforms.
  • Build platform content and collectors that triage endpoint and application performance problems — crashes, driver faults, and degradation — and attribute them to a responsible component, so fleet-wide issues are diagnosed from evidence rather than anecdote.
  • Work with engineering and development groups to provide endpoint security requirements for new applications and systems.
  • Document processes and procedures relating to endpoint security technologies, at a standard others can execute from.
  • Contribute to the endpoint security roadmap and to best practices at the department level.
  • Technical leadership - Contribute to the strategy of endpoint security within the team; independently determine and develop technical plans for complex problems and use technical judgement to select methods and techniques best suited to the problem.
  • As a senior member of the team, mentor other
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Endpoint Security Engineer III
Endpoint Security Engineer III

Blue Origin • Seattle (WA)

On-site
USD 140,000 - 190,000
Senior Endpoint Security Engineer: Defender & Tanium
Senior Endpoint Security Engineer: Defender & Tanium

Blue Origin LLC • United States

On-site
USD 150,000 - 190,000
Endpoint Security Lead: Defender for Endpoint & Tanium
Endpoint Security Lead: Defender for Endpoint & Tanium

Blue Origin • Seattle (WA)

On-site
USD 140,000 - 190,000
Principal Engineer/Microsoft Endpoint for Defender Enterprise
Principal Engineer/Microsoft Endpoint for Defender Enterprise

Fuse Eng • Fort Meade (MD), Northern (KY)

On-site
USD 120,000 - 180,000
Principal Engineer/Microsoft Endpoint for Defender Enterprise
Principal Engineer/Microsoft Endpoint for Defender Enterprise

Fuse Engineering LLC • Fort Meade (MD)

On-site
USD 180,000 - 240,000
Endpoint Security Engineer
Endpoint Security Engineer

PlanIT Group, LLC • Reston (VA)

On-site
USD 150,000 - 200,000
Endpoint & Security Platforms Engineer
Endpoint & Security Platforms Engineer

Greenhouse Software, Inc. • United States

Remote
USD 120,000 - 160,000
20 vacation days
10 sick leave days
Company holidays
+3
Endpoint Engineer III
Endpoint Engineer III

ecsfederal • Virginia (MN)

Hybrid
USD 130,000 - 160,000
Principal Engineer/Microsoft Endpoint for Defender Enterprise
Principal Engineer/Microsoft Endpoint for Defender Enterprise

Fuse Engineering • Fort Meade (MD)

On-site
USD 150,000 - 200,000
End-Point Security Architect
End-Point Security Architect

Stellent IT LLC • United States

Remote
USD 193,000 - 303,000