Journeyman Endpoint Engineer

Eiservices Llc

Bethesda, Northern (MD, KY)

Hybrid

USD 110,000 - 170,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Paid holidays
Paid time off and sick leave
Medical, dental, and vision insurance

Job summary

Eagle Integrated Services (EIS) seeks a Journeyman Endpoint Engineer to lead the enterprise migration to Defender for Endpoint across 3,000+ endpoints and legacy Trellix removal. You will manage onboarding, scripting, and encryption validation while maintaining DoD security standards.

Responsibilities include deploying Defender, monitoring health, and coordinating with cybersecurity, infrastructure, and engineering teams to ensure a smooth migration with minimal disruption to operations.

Qualifications

  • 3–5 years of experience supporting endpoint administration, software distribution, endpoint security, or related enterprise engineering activities.
  • Active DoD Secret security clearance.
  • Current DoD IAT Level II-compliant certification.
  • Hands-on experience with enterprise endpoint-management and software-deployment technologies.
  • Experience deploying, configuring, and troubleshooting endpoint-security agents or similar enterprise software.

Responsibilities

  • Deploy and configure Defender for Endpoint across Windows, macOS, and Linux devices using automated deployment methods and enterprise tools.
  • Develop, execute, and maintain deployment packages, scripts, policies, and configurations.
  • Monitor endpoint enrollment, agent health, connectivity, and security telemetry and remediate devices that fail to onboard.
  • Remove legacy Trellix technologies following Defender implementation and decommission legacy ePO.
  • Configure and validate BitLocker and FileVault encryption and escrow recovery keys.
  • Troubleshoot endpoint-security and deployment issues, including conflicts and installation issues.
  • Support macOS security requirements and Linux Defender deployment via scripting and system tools.
  • Maintain compliance with DISA STIGs and DoD cybersecurity requirements.

Skills

Endpoint management
Security engineering
Scripting
Documentation
Communication

Education

DoD IAT Level II certification
MD-102 / Endpoint certification

Tools

SCCM/MECM
Microsoft Intune
JAMF
Bash/shell scripting
Trellix ePO

Job description

Eagle Integrated Services (EIS) is seeking a Journeyman Endpoint Engineer to support the enterprise migration and implementation of Microsoft Defender for Endpoint across approximately 3,000 Windows, macOS, and Linux endpoints at the Uniformed Services University of the Health Sciences (USUHS).

The Journeyman Endpoint Engineer will serve as a hands‑on technical resource responsible for endpoint onboarding, security-agent migration, configuration, troubleshooting, and the controlled removal of legacy Trellix technologies. This position will leverage enterprise endpoint-management and automation technologies to execute the migration efficiently while minimizing disruption to users and mission operations.

What You’ll Do:
  • Deploy and configure Microsoft Defender for Endpoint across Windows, macOS, and Linux devices using automated deployment methods and enterprise endpoint-management tools.
  • Develop, execute, and maintain deployment packages, scripts, policies, and configurations supporting enterprise endpoint onboarding.
  • Monitor endpoint enrollment, agent health, connectivity, and security telemetry and remediate devices that fail to onboard or report correctly.
  • Execute the controlled removal of legacy Trellix security agents following successful Defender implementation and validation and support decommissioning of the legacy Trellix/ePO environment.
  • Configure and validate native disk encryption, including BitLocker for Windows and FileVault for macOS, and verify encryption status and recovery‑key escrow before removing applicable legacy technologies.
  • Troubleshoot endpoint-security and deployment issues, including agent conflicts, installation failures, connectivity problems, policy conflicts, and operating‑system‑specific configuration issues.
  • Support macOS security requirements, including applicable system and security extensions, and Linux Defender deployment using shell scripting and Linux system‑management tools.
  • Maintain compliance with applicable DISA STIGs and DoD cybersecurity requirements across managed endpoints.
  • Test and validate endpoint configurations and support phased deployment activities, including pilot groups, production migration, exception handling, and remediation.
  • Track endpoint onboarding, migration, and remediation progress and provide status information supporting the master project schedule.
  • Develop and maintain SOPs, deployment procedures, troubleshooting guides, configuration documentation, and operational playbooks.
  • Coordinate with cybersecurity, infrastructure, service desk, and engineering personnel to resolve endpoint migration and operational issues.
What You Bring:

Required:

  • 3–5 years of experience supporting endpoint administration, software distribution, endpoint security, or related enterprise engineering activities.
  • Active DoD Secret security clearance.
  • Current DoD IAT Level II-compliant certification, as applicable to current DoD requirements.
  • Hands‑on experience with enterprise endpoint-management and software‑deployment technologies.
  • Experience supporting Windows endpoint configuration and administration.
  • Experience deploying, configuring, and troubleshooting endpoint‑security agents or similar enterprise software.
  • Working knowledge of Microsoft Defender for Endpoint or comparable endpoint detection and response (EDR) technologies.
  • Experience troubleshooting endpoint connectivity, software installation, policy, and configuration issues.
  • Familiarity with endpoint encryption technologies, including BitLocker and/or FileVault.
  • Working knowledge of cybersecurity configuration and compliance requirements in Federal or DoD environments.
  • Ability to develop technical documentation and effectively communicate technical issues with engineering and operational teams.

Preferred:

  • Experience with Microsoft Configuration Manager (SCCM/MECM) and/or Microsoft Intune.
  • Experience administering Microsoft Defender for Endpoint in an enterprise environment.
  • Experience supporting macOS through JAMF or another enterprise MDM platform.
  • Experience with Linux administration and Bash/shell scripting.
  • Experience with Trellix ePO, Trellix endpoint agents, or migrations from legacy Trellix technologies.
  • Experience supporting multi-OS enterprise environments.
  • Familiarity with DISA STIGs and DoD endpoint-security requirements.
  • Experience supporting large‑scale endpoint migrations, software deployments, or security‑tool transitions.
  • Current Microsoft Certified: Endpoint Administrator Associate (MD-102), Microsoft security/security-operations certification applicable to Defender technologies, or another relevant Microsoft endpoint, security, or cloud certification.
What We Offer:

EIS offers a competitive benefits package to include: paid holidays, paid time off including sick and vacation leave, medical, dental and vision insurance, flexible spending accounts, short and long term disability, company paid life insurance, 401(k) with a company match and discretionary profit sharing and tuition reimbursement.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Journeyman Endpoint Engineer
Journeyman Endpoint Engineer

Bristol Bay Native Corporation • Bethesda (MD), Northern (KY)

Hybrid
USD 95,000 - 130,000
Paid holidays
Medical, dental and vision insurance
401(k) with company match
Endpoint Security Engineer — Defender Migration Lead
Endpoint Security Engineer — Defender Migration Lead

Bristol Bay Native Corporation • Bethesda (MD), Northern (KY)

Hybrid
USD 95,000 - 130,000
Paid holidays
Medical, dental and vision insurance
401(k) with company match
DoD-Cleared Endpoint Migration Engineer (Defender)
DoD-Cleared Endpoint Migration Engineer (Defender)

Eiservices Llc • Bethesda (MD), Northern (KY)

Hybrid
USD 110,000 - 170,000
Paid holidays
Paid time off and sick leave
Medical, dental, and vision insurance
Senior Information System Security Engineer (ISSE)
Senior Information System Security Engineer (ISSE)

Bristol Bay Native Corporation • Bethesda (MD), Northern (KY)

Hybrid
USD 120,000 - 160,000
Paid holidays
PTO
Medical insurance
+3
Endpoint Security Architect
Endpoint Security Architect

Shield Consulting Solutions, Inc. • Maryland

On-site
USD 240,000 - 250,000
25 days PTO
11 paid holidays
Employer-paid healthcare for employees
+1
Endpoint Security Administration – Senior/SME
Endpoint Security Administration – Senior/SME

NS4 Inc • Virginia (IL), Northern (KY)

Hybrid
USD 120,000 - 160,000
Principal Engineer/Microsoft Endpoint for Defender Enterprise
Principal Engineer/Microsoft Endpoint for Defender Enterprise

Fuse Engineering • Fort Meade (MD)

On-site
USD 150,000 - 200,000
Principal Engineer/Microsoft Endpoint for Defender Enterprise
Principal Engineer/Microsoft Endpoint for Defender Enterprise

Fuse Eng • Fort Meade (MD), Northern (KY)

On-site
USD 120,000 - 180,000
Principal Engineer/Microsoft Endpoint for Defender Enterprise
Principal Engineer/Microsoft Endpoint for Defender Enterprise

Fuse Engineering LLC • Fort Meade (MD)

On-site
USD 180,000 - 240,000
Endpoint Engineer III
Endpoint Engineer III

Socket.dev • Virginia (IL)

Hybrid
USD 130,000 - 160,000