DirectViz Solutions (DVS) is a dynamic and rapidly growing government contractor committed to delivering innovative IT solutions that address the mission-critical needs of our government clients. Through the expertise and dedication of our talented team, we provide cutting-edge technology services designed to achieve success and exceed expectations.
At DVS, we prioritize our employees as our greatest asset. We offer competitive compensation, comprehensive medical benefits, a 401(k) match, generous PTO accrual, professional development reimbursement, corporate-funded
Endpoint Security Systems Engineer - Cyber Security Specialist - Senior
Location: Adelphi, MD (Hybrid - 3 days on site) Security Clearance: Active Top Secret / SCI (TS/SCI) Program: C5ISR Center Cyber Security Service Provider (CSSP) Schedule: Full Time / Day Shift
We are seeking a Senior Endpoint Security Systems Engineer to serve as an endpoint protection and architecture specialist. In this role, the candidate will lead the engineering, deployment, configuration, optimization, and sustainment of enterprise host-based defense capabilities across mission assets. Focus will center on managing and advancing our enterprise Trellix environment (ePolicy Orchestrator and Endpoint Security suite), while engineering and operationalizing Elastic Defend for Endpoint as a complementary host-based telemetry and detection capability within our multi-tiered defense architecture. Will partner closely with mission system owners, infrastructure architects, and defensive cyber operations teams to protect mission-critical Windows, Linux, and macOS platforms. While the CSSP defends a hybrid landscape of SaaS and PaaS offerings, specific endpoint agent engineering, deployment, and management focus will target systems residing in on-premises environments and cloud Infrastructure-as-a-Service (IaaS).
Key Responsibilities
- Console Administration
- Maintain, upgrade, and harden central endpoint management consoles (primarily Trellix ePO) across multi-tier networks, isolated enclaves, and cloud-connected management VPCs.
- Multi-Tiered Endpoint Architecture
- Engineer, deploy, and sustain the Trellix suite alongside Elastic Agent / Elastic Defend, establishing cohesive agent lifecycle management, mutual compatibility, and synchronized host-level protection.
- Endpoint Environment Integration
- Direct the integration, configuration, and agent lifecycle management for endpoints and servers specifically residing within on-premises environments and cloud IaaS instances covering Windows, Linux, and macOS.
- Policy & Performance Tuning
- Design, benchmark, and deploy scan exclusion policies, behavioral rules, DLP rules, and content updates to ensure host protection without degrading OS stability, server throughput, or cloud compute performance.
- Troubleshooting & Liaison
- Resolve complex system-level issues, including:
- Diagnosing and remediating agent connectivity, registration, and communication failures across hybrid network boundaries.
- Debugging product installation and deployment failures on mission hosts.
- Partnering with mission owners to engineer precise performance exclusions and resolve mission-critical application blocks caused by security policies.
- Investigating and rectifying ePO console misconfigurations, policy inheritance errors, or corrupt database events impacting the wider enterprise.
- Compliance & Risk Alignment
- Maintain compliance with DISA STIGs, OPORD, and endpoint security requirements across all supported host deployments (on-premises and IaaS), leveraging host reporting to support continuous monitoring frameworks.
- Threat Detection Support
- Collaborate with CSSP threat detection and hunt teams to implement custom endpoint signatures, indicators of compromise (IOCs), and automated containment policies.
Basic Qualifications
- Clearance: Active Top Secret / SCI (U.S. Citizenship required). Secret active to start.
- Education & Experience:
- Bachelor's degree in Cybersecurity, Computer Science, STEM, or an IT-related field with 8+ years of relevant systems engineering/endpoint security experience.
- Master's degree with 6+ years of relevant systems engineering/endpoint security experience
- DoD 8140 compliance upon start: Active certification meeting CSSP-Infrastructure Support, CSSP-Analyst, or IAT Level II/III requirements (e.g., CEH, CySA+, GCIH, GCFA, GMON, CISSP, CASP+, or CISM).
- Primary Technology Expertise:
- Demonstrated hands‑on engineering experience administering and upgrading Trellix ePolicy Orchestrator (ePO), Trellix Agent, and the following core modules:
- Trellix Endpoint Security (ENS) suite (specifically Threat Prevention and Firewall)
- Trellix Data Loss Prevention (DLP)
- Trellix Policy Auditor
- Proven experience deploying and maintaining endpoint security agents across enterprise Linux (RHEL/CentOS/Rocky), Windows (Server & Desktop), and macOS environments.
- Target Environment Engineering:
- Practical experience managing and troubleshooting host-based security capabilities specifically across on-premises environments and cloud-based IaaS (VM) instances.
- Strong troubleshooting capability in analyzing OS performance impacts, resource contention, and agent-server communication issues across complex network routing topologies.
Preferred Qualifications
- Application Whitelisting & Integrity: Experience implementing and managing Trellix Solidcore (Application Control) for application whitelisting and file integrity monitoring (FIM).
- Complementary Detection Technologies: Practical experience