Journeyman Endpoint Engineer

Vista Global Solutions, LLC

Bethesda, Northern (MD, KY)

Hybrid

USD 120,000 - 160,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Paid holidays
PTO
Insurance: medical/dental/vision
401(k) with match
Tuition reimbursement

Job summary

Vista Global Solutions, LLC seeks a Journeyman Endpoint Engineer to lead the enterprise migration to Microsoft Defender for Endpoint across 3,000+ endpoints on Windows, macOS and Linux. You will onboard devices, migrate security agents from Trellix, configure BitLocker/FileVault, and ensure DISA STIG and DoD requirements are met while minimizing user disruption.

The role emphasizes hands-on deployment, automation, and cross-team coordination with cybersecurity, infrastructure, and service desk

Qualifications

  • 3–5 years of endpoint administration or related enterprise engineering.
  • Active DoD Secret clearance.
  • DoD IAT Level II certification.
  • Experience with enterprise endpoint-management and software deployment.
  • Experience with Windows endpoint configuration and administration.
  • Experience deploying and troubleshooting endpoint-security agents.
  • Knowledge of Defender for Endpoint or other EDR tech.
  • Familiarity with endpoint encryption (BitLocker/FileVault).

Responsibilities

  • Deploy Defender for Endpoint across Windows, macOS, Linux using automated deployment.
  • Develop and maintain deployment packages, scripts, policies, configurations.
  • Monitor enrollment, agent health, connectivity, and remediation of onboarding issues.
  • Remove legacy Trellix agents and decommission Trellix/ePO environment.
  • Configure and validate BitLocker/FileVault and escrow recovery keys.
  • Troubleshoot deployment issues, agent conflicts, and connectivity problems.
  • Support macOS security extensions and Linux Defender deployment via scripting.
  • Maintain DISA STIG and DoD cybersecurity compliance across endpoints.
  • Test configurations and support phased deployment (pilot to production).
  • Track onboarding progress and provide status updates for the master schedule.
  • Develop SOPs, deployment procedures, guides, and playbooks.
  • Coordinate with cybersecurity, infrastructure, service desk, and engineering teams.

Skills

Endpoint administration
Software deployment
EDR technologies
Security compliance
Technical documentation

Education

DoD IAT Level II
MD-102 or related Microsoft cert

Tools

SCCM/MECM
Microsoft Intune
JAMF
Bash scripting

Job description

Vista Global Solutions (VGS) is seeking a Journeyman Endpoint Engineer to support the enterprise migration and implementation of Microsoft Defender for Endpoint across approximately 3,000 Windows, macOS, and Linux endpoints at the Uniformed Services University of the Health Sciences (USUHS).

The Journeyman Endpoint Engineer will serve as a hands‑on technical resource responsible for endpoint onboarding, security‑agent migration, configuration, troubleshooting, and the controlled removal of legacy Trellix technologies. This position will leverage enterprise endpoint‑management and automation technologies to execute the migration efficiently while minimizing disruption to users and mission operations.

What You’ll Do:
  • Deploy and configure Microsoft Defender for Endpoint across Windows, macOS, and Linux devices using automated deployment methods and enterprise endpoint‑management tools.
  • Develop, execute, and maintain deployment packages, scripts, policies, and configurations supporting enterprise endpoint onboarding.
  • Monitor endpoint enrollment, agent health, connectivity, and security telemetry and remediate devices that fail to onboard or report correctly.
  • Execute the controlled removal of legacy Trellix security agents following successful Defender implementation and validation and support decommissioning of the legacy Trellix/ePO environment.
  • Configure and validate native disk encryption, including BitLocker for Windows and FileVault for macOS, and verify encryption status and recovery‑key escrow before removing applicable legacy technologies.
  • Troubleshoot endpoint‑security and deployment issues, including agent conflicts, installation failures, connectivity problems, policy conflicts, and operating‑system‑specific configuration issues.
  • Support macOS security requirements, including applicable system and security extensions, and Linux Defender deployment using shell scripting and Linux system‑management tools.
  • Maintain compliance with applicable DISA STIGs and DoD cybersecurity requirements across managed endpoints.
  • Test and validate endpoint configurations and support phased deployment activities, including pilot groups, production migration, exception handling, and remediation.
  • Track endpoint onboarding, migration, and remediation progress and provide status information supporting the master project schedule.
  • Develop and maintain SOPs, deployment procedures, troubleshooting guides, configuration documentation, and operational playbooks.
  • Coordinate with cybersecurity, infrastructure, service desk, and engineering personnel to resolve endpoint migration and operational issues.
What You Bring:

Required:

  • 3–5 years of experience supporting endpoint administration, software distribution, endpoint security, or related enterprise engineering activities.
  • Active DoD Secret security clearance.
  • Current DoD IAT Level II‑compliant certification, as applicable to current DoD requirements.
  • Hands‑on experience with enterprise endpoint‑management and software‑deployment technologies.
  • Experience supporting Windows endpoint configuration and administration.
  • Experience deploying, configuring, and troubleshooting endpoint‑security agents or similar enterprise software.
  • Working knowledge of Microsoft Defender for Endpoint or comparable endpoint detection and response (EDR) technologies.
  • Experience troubleshooting endpoint connectivity, software installation, policy, and configuration issues.
  • Familiarity with endpoint encryption technologies, including BitLocker and/or FileVault.
  • Working knowledge of cybersecurity configuration and compliance requirements in Federal or DoD environments.
  • Ability to develop technical documentation and effectively communicate technical issues with engineering and operational teams.
Preferred:
  • Experience with Microsoft Configuration Manager (SCCM/MECM) and/or Microsoft Intune.
  • Experience administering Microsoft Defender for Endpoint in an enterprise environment.
  • Experience supporting macOS through JAMF or another enterprise MDM platform.
  • Experience with Linux administration and Bash/shell scripting.
  • Experience with Trellix ePO, Trellix endpoint agents, or migrations from legacy Trellix technologies.
  • Experience supporting multi‑OS enterprise environments.
  • Familiarity with DISA STIGs and DoD endpoint‑security requirements.
  • Experience supporting large‑scale endpoint migrations, software deployments, or security‑tool transitions.
  • Current Microsoft Certified: Endpoint Administrator Associate (MD-102), Microsoft security/security‑operations certification applicable to Defender technologies, or another relevant Microsoft endpoint, security, or cloud certification.
What We Offer:

VGS offers a competitive benefits package to include: paid holidays, paid time off including sick and vacation leave, medical, dental and vision insurance, flexible spending accounts, short and long term disability, company paid life insurance, 401(k) with a company match and discretionary profit sharing and tuition reimbursement.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Information System Security Engineer (ISSE)
Senior Information System Security Engineer (ISSE)

Vista Global Solutions, LLC • Bethesda (MD), Northern (KY)

Hybrid
USD 120,000 - 150,000
Paid holidays
Paid time off
Medical insurance
+4
Senior Information System Security Engineer (ISSE)
Senior Information System Security Engineer (ISSE)

BRS • Bethesda (MD)

On-site
USD 120,000 - 150,000
Health insurance
Paid holidays
Paid time off
Senior Information System Security Engineer (ISSE)
Senior Information System Security Engineer (ISSE)

Bristol Bay Native Corporation • Bethesda (MD), Northern (KY)

Hybrid
USD 120,000 - 160,000
Paid holidays
PTO
Medical insurance
+3
Endpoint Security Engineer: Defender Migration & DoD Compliance
Endpoint Security Engineer: Defender Migration & DoD Compliance

Vista Global Solutions, LLC • Bethesda (MD), Northern (KY)

Hybrid
USD 120,000 - 160,000
Paid holidays
PTO
Insurance: medical/dental/vision
+2
Junior Endpoint Engineer
Junior Endpoint Engineer

Paycom - ATS • Bethesda (MD), Northern (KY)

On-site
USD 70,000 - 85,000
Endpoint & Security Platforms Engineer
Endpoint & Security Platforms Engineer

Greenhouse Software, Inc. • United States

Remote
USD 120,000 - 160,000
20 vacation days
10 sick leave days
Company holidays
+3
Principal Engineer/Microsoft Endpoint for Defender Enterprise
Principal Engineer/Microsoft Endpoint for Defender Enterprise

Fuse Engineering LLC • Fort Meade (MD)

On-site
USD 180,000 - 240,000
Security Endpoint Engineer/Admin
Security Endpoint Engineer/Admin

AHU Technologies Inc • Washington

On-site
USD 85,000 - 110,000
Principal Engineer/Microsoft Endpoint for Defender Enterprise
Principal Engineer/Microsoft Endpoint for Defender Enterprise

Fuse Eng • Fort Meade (MD), Northern (KY)

On-site
USD 120,000 - 180,000
Endpoint Security Administration – Senior/SME
Endpoint Security Administration – Senior/SME

NS4 Inc • Virginia (IL), Northern (KY)

On-site
USD 120,000 - 160,000