Senior Endpoint Protection Analyst

Koniag Government Services

Washington (District of Columbia)

On-site

USD 140,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental insurance
Vision insurance
401(k)
Paid time off
Parental leave
Life insurance
Disability insurance
Flexible spending accounts
Commuter benefits
Tuition reimbursement

Job summary

Koniag Government Services is seeking a Senior Endpoint Protection Analyst to join our cybersecurity team protecting critical IT infrastructure. You will lead administration and tuning of enterprise endpoint protection across the environment and drive incident response activities to mitigate threats.

You will apply your deep expertise in EDR and antivirus, coordinate with SOC and IT, and ensure alignment with NIST and FISMA requirements while mentoring junior staff and supporting government

Qualifications

  • Bachelor's degree in Cybersecurity, CS, IT, IS or related field.
  • 5+ years of cybersecurity experience with focus on endpoint security or incident response.
  • Experience administering enterprise endpoint protection/EDR platforms (CrowdStrike/Defender/Carbon Black/SentinelOne).
  • Experience conducting endpoint security investigations, forensic analysis, and malware analysis.

Responsibilities

  • Serve as senior technical authority for endpoint protection platforms (EDR, antivirus, HIDS, DLP).
  • Monitor, analyze, and respond to endpoint security alerts and incidents; conduct investigations.
  • Lead and support incident response activities for endpoint threats (malware, ransomware, unauthorized access).
  • Perform forensic analysis to identify IOCs, TTPs, and remediation actions.
  • Develop and tune endpoint detection rules, policies, and configurations.
  • Conduct regular vulnerability assessments and endpoint compliance reviews.
  • Collaborate with SOC, network security, and IT operations to correlate telemetry.
  • Manage and administer endpoint protection agents across endpoints.
  • Develop endpoint security policies and baselines aligned with NIST/FISMA standards.
  • Research emerging threats and provide actionable intelligence to leadership.
  • Support SOPs and runbooks; prepare security reports for stakeholders.
  • Mentor junior analysts and participate in audits and ATO activities.
  • Evaluate new endpoint security technologies and coordinate with IT operations for patching.

Skills

Endpoint protection
Incident response
Digital forensics
Threat hunting
Threat intel

Education

Bachelor's degree in Cybersecurity/CS/IT/IS

Tools

CrowdStrike Falcon
Microsoft Defender for Endpoint
Carbon Black
SentinelOne

Job description

Koniag Operation Services, a Koniag Government Services company, is seeking an experienced Senior Endpoint Protection Analyst to join a cybersecurity team dedicated to protecting critical IT infrastructure and ensuring the security and integrity of enterprise endpoint environments. This position requires the ability to obtain a Public Trust Clearance to support our government customer.

Benefits include medical, dental, and vision insurance, 401(k) retirement plan, paid time off, paid parental leave, life and disability insurance, flexible spending accounts, commuter benefits, and tuition reimbursement.

The ideal candidate is a highly skilled, proactive cybersecurity professional who is passionate about endpoint security, threat detection, and incident response, and possesses the technical depth and analytical expertise to identify, investigate, and mitigate complex endpoint threats in a fast-paced, mission-driven environment.

The Senior Endpoint Protection Analyst will serve as a senior-level subject matter expert responsible for the administration, monitoring, analysis, and continuous improvement of enterprise endpoint protection solutions. This individual will play a critical role in defending the organization’s endpoint infrastructure against cyber threats, leading incident response activities, and ensuring endpoint security tools and configurations remain current, effective, and compliant with applicable federal security standards and policies.

Principal responsibilities will include but are not limited to:

  • Serve as a senior technical authority for enterprise endpoint protection platforms, including endpoint detection and response (EDR), antivirus, anti-malware, host-based intrusion detection, and data loss prevention (DLP) solutions.

  • Monitor, analyze, and respond to endpoint security alerts, events, and incidents, conducting thorough investigations to determine scope, impact, and root cause.

  • Lead and support incident response activities related to endpoint threats, including malware infections, ransomware, unauthorized access, lateral movement, and data exfiltration attempts.

  • Perform in-depth forensic analysis of compromised endpoints to identify indicators of compromise (IOCs), threat actor techniques, tactics, and procedures (TTPs), and recommend remediation actions.

  • Develop, tune, and maintain endpoint detection rules, policies, and configurations to reduce false positives, improve detection fidelity, and ensure comprehensive coverage across the enterprise endpoint environment.

  • Conduct regular vulnerability assessments and endpoint compliance reviews, identifying gaps in endpoint security posture and recommending corrective actions.

  • Collaborate with the Security Operations Center (SOC), network security, and IT operations teams to correlate endpoint telemetry with broader threat intelligence and network security data.

  • Manage and administer endpoint protection platforms, ensuring agents are deployed, updated, and functioning correctly across all managed endpoints.

  • Develop and maintain endpoint security policies, standards, baselines, and hardening guidelines in alignment with federal security frameworks such as NIST, FISMA, and agency‑specific requirements.

  • Research and analyze emerging cyber threats, vulnerabilities, and attack techniques relevant to endpoint environments, providing actionable intelligence and recommendations to leadership and stakeholders.

  • Support the development and continuous improvement of endpoint security playbooks, standard operating procedures (SOPs), and incident response runbooks.

  • Prepare and deliver clear, accurate, and timely security reports, briefings, and documentation for technical teams and non‑technical stakeholders including government leadership.

  • Mentor and provide technical guidance to junior analysts, sharing knowledge and best practices to strengthen the overall capabilities of the cybersecurity team.

  • Participate in security audits, assessments, and Authorization to Operate (ATO) activities by providing endpoint security documentation, evidence, and subject matter expertise.

  • Evaluate and recommend new endpoint security technologies, tools, and capabilities to enhance the organization’s overall security posture.

  • Support patch management and vulnerability remediation efforts by validating endpoint compliance and coordinating with IT operations teams.

  • Actively contribute to threat hunting activities, proactively searching for hidden threats and anomalous behaviors within the endpoint environment.

Education and Experience:
Required:
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related field from an accredited college or university.

  • 5+ years of experience in cybersecurity, with a focus on endpoint security, endpoint protection, or incident response.

  • Demonstrated experience administering and operating enterprise endpoint protection and EDR platforms such as CrowdStrike Falcon, Microsoft Defender for Endpoint, Carbon Black, SentinelOne, or similar solutions.

  • Experience conducting endpoint security incident investigations, forensic analysis, and malware analysis.

Preferred:
  • 7+ years of experience in cybersecurity with a specialization in endpoint protection or security operations.

  • Experience supporting endpoint security operations in a federal government IT environment.

Required Skills and Competencies:
  • Deep technical expertise in endpoint protection technologies including EDR, antivirus, anti‑malware, host‑based intrusion detection systems (HIDS), and data loss prevention (DLP) solutions.

  • Proficiency in administering and operating at least one enterprise EDR platform such as CrowdStrike Falcon, Microsoft Defender for Endpoint, Carbon Black, SentinelOne, or equivalent.

  • Strong experience conducting security incident investigations, root cause analysis, and digital forensic analysis of compromised endpoints.

  • Solid understanding of malware analysis techniques, including static and dynamic analysis, and the ability to identify and document indicators of compromise (IOCs).

  • Familiarity with threat intelligence frameworks such as MITRE ATT<span>&CK and the ability to map observed adversary behaviors to known TTPs.

  • Experience developing and tuning endpoint detection rules, alerts, and security policies to improve detection accuracy and reduce alert fatigue.

  • Knowledge of federal cybersecurity frameworks, standards, and regulations including NIST SP 800-53, FISMA, and FIPS, and the ability to align endpoint security practices with these requirements.

  • Experience supporting vulnerability management and patch compliance activities within enterprise endpoint environments.

  • Proficiency with security information and event management (SIEM) platforms for correlating endpoint telemetry with broader security event data.

  • Strong analytical, critical thinking, and problem‑solving skills with the ability to assess complex security situations and make timely, informed decisions.

  • Excellent written and verbal communication skills in English, with the ability to produce clear and accurate security reports, documentation, and briefings for both technical and executive audiences.

  • Ability to mentor junior team members and contribute to the professional development of the broader cybersecurity team.

  • Ability to work effectively both independently and collaboratively within a cross‑functional cybersecurity team environment.

  • Ability to obtain and maintain a Public Trust Clearance.

Desired Skills and Competencies:
  • Experience working in a federal government cybersecurity environment, preferably supporting a civilian or defense agency.

  • One or more industry‑recognized cybersecurity certifications such as:

  • CompTIA Security+, CySA+, or CASP+ Certified Ethical Hacker (CEH)

  • GIAC Certified Enterprise Defender (GCED)

  • GIAC Certified Incident Handler (GCIH)

  • GIAC Certified Forensic Analyst (GCFA)

  • Certified Information Systems Security Professional (CISSP)

  • CrowdStrike Certified Falcon Responder (CCFR) or equivalent vendor certification

  • Experience with threat hunting methodologies and tools, including proactive identification of advanced persistent threats (APTs) within endpoint environments.

  • Familiarity with cloud endpoint security concepts and experience securing endpoints within Microsoft Azure, AWS, or hybrid cloud environments.

  • Experience with scripting languages such as Python, PowerShell, or Bash for automating security tasks and enhancing endpoint monitoring capabilities.

  • Knowledge of network security concepts including firewalls, proxies, and intrusion detection/prevention systems and how they correlate with endpoint security telemetry.

  • Experience participating in or supporting Authorization to Operate (ATO) processes and security control assessments.

  • Familiarity with zero trust architecture principles and their application to endpoint security strategies.

  • Experience supporting or contributing to Security Operations Center (SOC) operations, including shift‑based monitoring and escalation procedures.

Our Equal Employment Opportunity Policy:

The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.

The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or to apply to a position on our website, please contact Heaven Wood via e‑mail at accommodations@koniag-gs.com or by calling 703‑488‑9377 to request accommodations.

Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long‑term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com .

Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352

Job Details

Job Family IT, Cyber Security, Network Systems

Job Function Cyber Security Operations Analyst

Pay Type Salary

Hiring Min Rate 140,000 USD

Hiring Max Rate 180,000 USD

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Jr Endpoint Protection Analyst
Jr Endpoint Protection Analyst

Koniag Government Services • Washington

Hybrid
USD 90,000 - 120,000
Medical insurance
Dental insurance
Vision insurance
+8
Senior Endpoint Protection Analyst
Senior Endpoint Protection Analyst

Clear Destination Inc. • Washington, Northern (KY)

Hybrid
USD 120,000 - 150,000
Medical insurance
Dental insurance
Vision insurance
+8
Security Operations Center Analyst - Low
Security Operations Center Analyst - Low

Koniag Government Services • Washington

On-site
USD 60,000 - 85,000
Medical insurance
Dental insurance
Vision insurance
+7
Cyber Defense Analysts – Senior
Cyber Defense Analysts – Senior

Koniag Government Services • Washington

On-site
USD 140,000 - 190,000
Medical, dental, vision insurance
401(k) retirement plan
Paid time off
Security Engineer
Security Engineer

Koniag Services, Inc. • Washington, Northern (KY)

On-site
USD 110,000 - 140,000
Health insurance
401K with company matching
Paid holidays
+1
Principal Cybersecurity Engineer
Principal Cybersecurity Engineer

Koniag Government Services • Washington

On-site
USD 275,000 - 325,000
Medical, dental, vision insurance
401(k) retirement plan
Paid time off
+5
Senior Security Manager
Senior Security Manager

Koniag Government Services • Smyrna (GA)

On-site
USD 120,000 - 170,000
Health insurance
401K with company matching
Flexible spending accounts
+2
Jr Palo Alto Integration Tech
Jr Palo Alto Integration Tech

Koniag Government Services • Washington

Hybrid
USD 90,000 - 110,000
Medical Insurance
Dental Insurance
Vision Insurance
+7
AI Security Engineer - Mid
AI Security Engineer - Mid

Koniag Government Services • Washington

Hybrid
USD 110,000 - 140,000
Medical, dental, vision insurance
401(k) retirement plan
Paid time off
+4
Security Engineer
Security Engineer

Koniag Government Services • Washington

On-site
USD 140,000 - 190,000
Medical, dental, and vision insurance
401(k) retirement plan
Paid time off