Junior Endpoint Protection Analyst - Washington DC

VetJobs

Washington (District of Columbia)

Hybrid

USD 90,000 - 120,000

Full time

27 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

VIATEQ is seeking a Junior Endpoint Protection Analyst to support enterprise cybersecurity operations for a federal government client. The role is based primarily at the client site in Washington, DC with approved remote/telework locations.

You will assist in endpoint protection platform administration, vulnerability management, incident response support, and compliance documentation while coordinating with senior security engineers. A government background check may be required.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related field.
  • Minimum 1–2 years of cybersecurity, IT operations, or endpoint security support experience.
  • Foundational knowledge of endpoint security concepts including antivirus/EDR, patch management, and MDM/UEM.
  • Foundational knowledge of Windows administration: Active Directory, Group Policy, Windows Event Logs.

Responsibilities

  • Administer and maintain enterprise endpoint protection platforms (EDR, antivirus, anti-malware) under guidance of senior engineers.
  • Monitor endpoint protection dashboards, investigate coverage gaps, and escalate threats per escalation procedures.
  • Assist in vulnerability scanning, patch tracking, and coordinating deployments with system admins.
  • Support endpoint hardening against DISA STIGs, CIS Benchmarks, and client security baselines.
  • Assist incident response activities: evidence collection, containment, and remediation under senior staff.
  • Support documentation, compliance artifacts, and status reporting for government stakeholders.

Job description

VIATEQ Corporation is looking for a Junior Endpoint Protection Analyst to support enterprise cybersecurity operations and IT administrative support services for a federal government client. This position requires the ability to obtain and maintain a government background investigation, PIV credentials, and all requisite IT access authorizations prior to performing work. Primary work will be performed at the client site in Washington, DC and approved remote/telework locations.

Responsibilities

Endpoint Protection Platform Administration:

  • Assist in the administration and maintenance of enterprise endpoint protection platforms, including Endpoint Detection and Response (EDR), antivirus, anti-malware, host-based intrusion detection, application control, and device management solutions under the guidance of senior security engineers.
  • Support the configuration, deployment, and management of endpoint security agents across managed endpoints, ensuring agent coverage is comprehensive, current, and accurately tracked.
  • Monitor endpoint protection platform dashboards and consoles, identifying endpoints with outdated agents, missing security policies, protection gaps, or active threats requiring investigation or remediation.
  • Assist in the development and maintenance of endpoint security policies, configurations, and deployment packages, ensuring policies are aligned with applicable security baselines, DISA STIGs, CIS Benchmarks, and client security requirements.
  • Support the management of endpoint protection platform exceptions, exclusions, and whitelists, ensuring all exceptions are properly documented, reviewed, and approved in accordance with defined governance procedures.
  • Assist in the administration and maintenance of Mobile Device Management (MDM) and Unified Endpoint Management (UEM) platforms, supporting the enrollment, configuration, monitoring, and compliance enforcement of managed mobile and remote devices.
  • Generate and distribute endpoint protection platform health and coverage reports, providing program leadership and Government stakeholders with accurate visibility into endpoint security posture and protection gaps.
Threat Detection & Alert Monitoring
  • Monitor endpoint protection platform alerts, EDR telemetry, and security event feeds, triaging security alerts and escalating confirmed or suspected security incidents to senior analysts and the incident response team in accordance with defined escalation procedures and SLA requirements.
  • Assist in the investigation of endpoint security alerts, gathering relevant event data, endpoint telemetry, and contextual information to support accurate triage and escalation decisions under the guidance of senior security personnel.
  • Support the development and maintenance of endpoint alert triage procedures, escalation playbooks, and response runbooks, contributing practical observations and lessons learned from daily monitoring activities.
  • Assist in identifying and documenting false positive alert patterns, supporting senior engineers in refining detection rules, alert thresholds, and EDR platform tuning to improve alert fidelity and reduce analyst fatigue.
  • Monitor endpoint protection platform health and availability, identifying and escalating platform performance issues, service disruptions, and coverage gaps that may impact the program's ability to detect and respond to endpoint threats.
Vulnerability & Patch Management Support
  • Assist in the execution of endpoint vulnerability scanning activities, supporting the scheduling, execution, and result collection of regular vulnerability scans across managed endpoints using enterprise vulnerability scanning platforms.
  • Support the analysis and triage of endpoint vulnerability scan results, assisting senior engineers in identifying, categorizing, and prioritizing vulnerabilities based on severity, exploitability, and asset criticality under defined risk-based prioritization criteria.
  • Assist in tracking and reporting on endpoint patch compliance status, monitoring patch deployment progress across managed endpoints and identifying systems with outstanding critical and high-severity patches requiring escalation.
  • Support coordination with system administrators and desktop support personnel to facilitate timely endpoint patch deployment, providing technical assistance and escalation support as needed.
  • Maintain accurate and current endpoint vulnerability and patch compliance records in the program's vulnerability management tracking system, supporting audit readiness and compliance reporting activities.
Endpoint Hardening & Compliance
  • Assist in the implementation and validation of endpoint hardening standards, supporting the application of DISA STIGs, CIS Benchmarks, and client-specific security baselines across managed Windows, Linux, and macOS endpoint environments.
  • Support configuration compliance scanning activities, assisting in the execution and analysis of Security Content Automation Protocol (SCAP) scans and configuration compliance assessments across managed endpoints.
  • Assist in tracking and reporting on endpoint configuration compliance status, identifying non-compliant endpoints and supporting remediation activities to bring endpoints into compliance with applicable security baselines.
  • Support the development and maintenance of endpoint hardening documentation, including hardening guides, configuration baseline specifications, and compliance reporting templates.
Incident Response Support
  • Support cybersecurity incident response activities involving endpoint security events, assisting senior analysts and engineers in evidence collection, endpoint isolation, malware containment, and remediation activities under defined incident response procedures.
  • Assist in the collection and preservation of endpoint forensic evidence, supporting chain of custody procedures and forensic acquisition activities under the guidance of senior digital forensics or incident response personnel.
  • Document incident response activities accurately and completely in the program's ITSM platform, ensuring incident records contain sufficient detail to support post-incident review, root cause analysis, and lessons learned activities.
  • Support post-incident review activities, contributing endpoint security observations and technical findings to root cause analysis discussions and corrective action development.
Compliance & Documentation Support
  • Assist in maintaining endpoint security compliance documentation, including security control implementation evidence, configuration compliance records, vulnerability remediation tracking data, and audit artifacts, supporting the program's ATO and continuous monitoring obligations.
  • Support the development and maintenance of endpoint security standard operating procedures, operational runbooks, and knowledge base articles, contributing practical operational knowledge to the program's documentation library.
  • Assist in the preparation of endpoint security status reports, compliance dashboards, and metrics summaries for program leadership and Government stakeholders.
  • Ensure all endpoint security activities are conducted in compliance with applicable Federal regulations, client security policies, and program security requirements, including FISMA, NIST SP 800-53, applicable DISA STIGs, and client-specific cybersecurity policies.
  • Ensure all activities involving personally identifiable information (PII), CUI, or other sensitive data categories are handled in accordance with applicable privacy protection requirements and data handling restrictions.
Professional Development & Learning
  • Actively pursue professional development and skills growth in endpoint security, cybersecurity operations, and Federal IT compliance, leveraging available training resources, mentorship from senior team members, and industry certifications to continuously expand technical capabilities.
  • Participate in team knowledge sharing sessions, security briefings, and technical training activities, contributing to a collaborative learning environment within the cybersecurity team.
  • Stay current with emerging endpoint security threats, vulnerabilities, attacker TTPs, and evolving Federal cybersecurity requirements, incorporating new knowledge into daily monitoring and analysis activities.
Auto req ID

483696BR

Minimum Education Required

Bachelors

Required Experience
Required Education and Experience
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related field from an accredited college or university. Equivalent combination of education and directly relevant experience or military service in a cybersecurity-related role may be considered.
  • Minimum of 1–2 years of experience in a cybersecurity, IT operations, or endpoint security support role, including internship, academic project, or entry-level professional experience in a relevant discipline.
  • Foundational knowledge of endpoint security concepts, including antivirus and anti-malware technologies, EDR platforms, endpoint hardening, patch management, and mobile device management.
  • Foundational knowledge of Windows operating system administration and security, including Active Directory, Group Policy, Windows Security Center, and Windows Event Logs.
  • Ability to obtain and maintain a government background investigation, PIV credentials, and all requisite IT access authorizations prior to performing work.
Compensation Range
  • $90,000 – 120,000. This represents the typical compensation range for this position based on experience, location, and other factors.
Preferred Experience
Preferred Education and Experience
  • Prior experience supporting endpoint security or cybersecurity operations in a federal government IT contracting environment.
  • Exposure to Linux or macOS endpoint security administration and hardening.
  • Familiarity with enterprise vulnerability scanning platforms such as Tenable Nessus, Qualys, or equivalent tools.
Required Skills
Required Skills and Competencies
  • Foundational technical knowledge of endpoint security technologies and concepts, including EDR platforms, antivirus and anti-malware solutions, host-based intrusion detection, application control, patch management, and mobile device management.
  • Basic understanding of cybersecurity principles, including the CIA triad, defense-in-depth, least-privilege access control, and common attack vectors targeting enterprise endpoints.
  • Familiarity with Windows operating system security, including Active Directory, Group Policy Objects, Windows Event Logs, Windows Defender, and common Windows-based security monitoring tools.
  • Basic understanding of Federal cybersecurity frameworks and compliance requirements, including NIST SP 800-53, FISMA, DISA STIGs, CIS Benchmarks, and applicable Federal endpoint security policies.
  • Strong analytical and attention-to-detail skills with the demonstrated ability to review security alerts, event logs, and platform dashboards systematically and accurately under the guidance of senior security personnel.
  • Strong written and verbal communication skills with the ability to document security events, alert triage findings, and operational activities clearly and accurately in ITSM tickets, incident records, and status reports.
  • Demonstrated ability to work effectively as a member of a cross-functional technical team, following established procedures, escalating issues appropriately, and actively seeking guidance from senior personnel.
  • Basic proficiency with Microsoft Office Suite and collaboration tools such as Microsoft Teams for documentation, reporting, and team communication activities.
  • Strong commitment to professional growth and continuous learning, with demonstrated motivation to develop cybersecurity knowledge, technical skills, and Federal compliance expertise over time.
  • Ability to manage multiple concurrent tasks and priorities with a high degree of accuracy and attention to detail in a fast-paced operational environment.
Preferred Skills
Preferred Skills and Competencies
  • CompTIA Security+ certification or active pursuit of CompTIA Security+ as a near-term professional development objective.
  • CompTIA A+, CompTIA Network+, or equivalent foundational IT certification demonstrating baseline technical knowledge.
  • Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900) or Microsoft Certified: Azure Fundamentals (AZ-900) certification.
  • Familiarity with enterprise EDR platforms such as CrowdStrike Falcon, Microsoft Defender for Endpoint, Carbon Black, SentinelOne, or equivalent tools.
  • Familiarity with enterprise vulnerability scanning platforms such as Tenable Nessus, Qualys, Rapid7 InsightVM, or equivalent tools.
  • Basic familiarity with SIEM platforms such as Splunk, Microsoft Sentinel, or equivalent tools for security event monitoring and alert triage support.
  • Familiarity with DISA STIG Viewer or SCAP Compliance Checker tools for endpoint configuration compliance assessment support.
  • Basic scripting knowledge in PowerShell, Python, or Bash for operational task automation and data parsing under the guidance of senior engineers.
  • Familiarity with ITIL-based IT Service Management concepts and enterprise ITSM platforms such as ServiceNow for incident documentation and ticket management.
  • Familiarity with the MITRE ATT&CK framework and its application to understanding common adversary tactics, techniques, and procedures targeting enterprise endpoints.
  • Basic familiarity with cloud security concepts as they relate to endpoint protection in hybrid on-premises and cloud environments, including Microsoft Azure and/or AWS.
  • Familiarity with mobile device security and MDM/UEM platform concepts, including device enrollment, compliance policy enforcement, and remote wipe capabilities.
  • Participation in cybersecurity competitions, Capture the Flag (CTF) events, academic cybersecurity programs, or equivalent hands-on learning activities demonstrating initiative and practical skill development.
Certificates/Security Clearances/Other
Preferred Skills and Competencies
  • CompTIA Security+ certification or active pursuit of CompTIA Security+ as a near-term professional development objective.
  • CompTIA A+, CompTIA Network+, or equivalent foundational IT certification demonstrating baseline technical knowledge.
  • Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900) or Microsoft Certified: Azure Fundamentals (AZ-900) certification.
City*

Washington

State*

District of Columbia

Job_Category

Cybersecurity

Job Code

IT Information Technology

Affiliate Sponsor

VIATEQ

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Junior Endpoint Protection Analyst
Junior Endpoint Protection Analyst

VIATEQ Corporation • Washington

On-site
USD 90,000 - 120,000
Medical insurance
Dental insurance
Vision insurance
+5
Security Engineer - Washington DC
Security Engineer - Washington DC

VetJobs • Washington

Hybrid
USD 100,000 - 130,000
Medical Insurance
Dental Insurance
Vision Insurance
+5
Junior DevSecOps Engineer
Junior DevSecOps Engineer

Viateq Corporation • Washington

On-site
USD 75,000 - 105,000
Cybersecurity Analyst – Intermediate
Cybersecurity Analyst – Intermediate

vgsystems • Fort Meade (MD)

On-site
USD 90,000 - 120,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Ampcus Inc • Washington

On-site
USD 90,000 - 120,000
Security Control Accessor
Security Control Accessor

Viateq Corporation • Washington

On-site
USD 100,000 - 130,000
Medical insurance
Dental insurance
Vision insurance
+3
Network Security Analyst 1
Network Security Analyst 1

My3tech • Austin (TX)

On-site
USD 60,000 - 90,000
Junior Federal Endpoint Security Analyst
Junior Federal Endpoint Security Analyst

VIATEQ Corporation • Washington

Hybrid
USD 90,000 - 120,000
Medical insurance
Dental insurance
Vision insurance
+5
Cybersecurity Analyst – Intermediate
Cybersecurity Analyst – Intermediate

VG SYSTEMS, LLC. • Fort Meade (MD)

On-site
USD 85,000 - 120,000
Cyber Security Engineer
Cyber Security Engineer

Beta Eight • Hicksville (NY)

On-site
USD 120,000 - 180,000