Senior Endpoint Security Systems Engineer

DirectViz Solutions, LLC

Adelphi (MD)

Hybrid

USD 130,000 - 170,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Competitive compensation
401(k) match
Medical benefits
PTO accrual
Professional development reimbursement

Job summary

DirectViz Solutions, LLC in Adelphi, MD is seeking a Senior Endpoint Security Systems Engineer to lead the design, deployment, and sustainment of enterprise host-based defenses across Windows, Linux, and macOS. You will manage Trellix ePO, Elastic Defend, and related tooling in a hybrid on-premise and cloud IaaS environment.

You will work with mission owners and defensive cyber teams to optimize agent lifecycles, tune policies, and ensure compliance with DISA STIGs.

Qualifications

  • Active Top Secret / SCI clearance (U.S. Citizenship required); Secret clearance to start.
  • Bachelor’s degree with 8+ years of relevant systems engineering/endpoint security experience or Master’s degree with 6+ years of experience.
  • DoD 8140-compliant certificates: CSSP-Infrastructure Support, CSSP-Analyst, or IAT Level II/III (e.g., CEH, CySA+, CISSP).

Responsibilities

  • Administer and upgrade Trellix ePO and endpoint consoles across multi-tier networks and cloud-connected environments.
  • Engineer, deploy and sustain Trellix suite with Elastic Agent/Elastic Defend; manage agent lifecycle.
  • Direct integration and lifecycle management for Windows, Linux, and macOS endpoints in on-prem and IaaS.
  • Design and tune scan exclusion policies, DLP rules, and content updates without impacting OS stability.
  • Troubleshoot agent connectivity, deployment, and policy inheritance issues across hybrid networks.
  • Collaborate with mission owners and CSSP teams to implement signatures, IOCs, and containment policies.
  • Maintain DISA STIGs and OPORD compliance across all endpoints.

Skills

Trellix ePolicy Orchestrator (ePO)
Trellix Agent
Trellix Endpoint Security (ENS)
Elastic Defend
Endpoint security
Linux/Windows/macOS management
IaaS/VM troubleshooting
Policy tuning

Education

Bachelor's degree in Cybersecurity/CS/STEM/IT
Master's degree in relevant field

Tools

ePolicy Orchestrator (ePO)
Elastic Defend

Job description

DirectViz Solutions (DVS) is a dynamic and rapidly growing government contractor committed to delivering innovative IT solutions that address the mission-critical needs of our government clients. Through the expertise and dedication of our talented team, we provide cutting-edge technology services designed to achieve success and exceed expectations.

At DVS, we prioritize our employees as our greatest asset. We offer competitive compensation, comprehensive medical benefits, a 401(k) match, generous PTO accrual, professional development reimbursement, corporate-funded

Endpoint Security Systems Engineer - Cyber Security Specialist - Senior

Location: Adelphi, MD (Hybrid - 3 days on site) Security Clearance: Active Top Secret / SCI (TS/SCI) Program: C5ISR Center Cyber Security Service Provider (CSSP) Schedule: Full Time / Day Shift

We are seeking a Senior Endpoint Security Systems Engineer to serve as an endpoint protection and architecture specialist. In this role, the candidate will lead the engineering, deployment, configuration, optimization, and sustainment of enterprise host-based defense capabilities across mission assets. Focus will center on managing and advancing our enterprise Trellix environment (ePolicy Orchestrator and Endpoint Security suite), while engineering and operationalizing Elastic Defend for Endpoint as a complementary host-based telemetry and detection capability within our multi-tiered defense architecture. Will partner closely with mission system owners, infrastructure architects, and defensive cyber operations teams to protect mission-critical Windows, Linux, and macOS platforms. While the CSSP defends a hybrid landscape of SaaS and PaaS offerings, specific endpoint agent engineering, deployment, and management focus will target systems residing in on-premises environments and cloud Infrastructure-as-a-Service (IaaS).

Key Responsibilities
  • Console Administration
  • Maintain, upgrade, and harden central endpoint management consoles (primarily Trellix ePO) across multi-tier networks, isolated enclaves, and cloud-connected management VPCs.
  • Multi-Tiered Endpoint Architecture
  • Engineer, deploy, and sustain the Trellix suite alongside Elastic Agent / Elastic Defend, establishing cohesive agent lifecycle management, mutual compatibility, and synchronized host-level protection.
  • Endpoint Environment Integration
  • Direct the integration, configuration, and agent lifecycle management for endpoints and servers specifically residing within on-premises environments and cloud IaaS instances covering Windows, Linux, and macOS.
  • Policy & Performance Tuning
  • Design, benchmark, and deploy scan exclusion policies, behavioral rules, DLP rules, and content updates to ensure host protection without degrading OS stability, server throughput, or cloud compute performance.
  • Troubleshooting & Liaison
  • Resolve complex system-level issues, including:
    • Diagnosing and remediating agent connectivity, registration, and communication failures across hybrid network boundaries.
    • Debugging product installation and deployment failures on mission hosts.
    • Partnering with mission owners to engineer precise performance exclusions and resolve mission-critical application blocks caused by security policies.
    • Investigating and rectifying ePO console misconfigurations, policy inheritance errors, or corrupt database events impacting the wider enterprise.
  • Compliance & Risk Alignment
  • Maintain compliance with DISA STIGs, OPORD, and endpoint security requirements across all supported host deployments (on-premises and IaaS), leveraging host reporting to support continuous monitoring frameworks.
  • Threat Detection Support
  • Collaborate with CSSP threat detection and hunt teams to implement custom endpoint signatures, indicators of compromise (IOCs), and automated containment policies.
Basic Qualifications
  • Clearance: Active Top Secret / SCI (U.S. Citizenship required). Secret active to start.
  • Education & Experience:
    • Bachelor's degree in Cybersecurity, Computer Science, STEM, or an IT-related field with 8+ years of relevant systems engineering/endpoint security experience.
    • Master's degree with 6+ years of relevant systems engineering/endpoint security experience
  • DoD 8140 compliance upon start: Active certification meeting CSSP-Infrastructure Support, CSSP-Analyst, or IAT Level II/III requirements (e.g., CEH, CySA+, GCIH, GCFA, GMON, CISSP, CASP+, or CISM).
  • Primary Technology Expertise:
    • Demonstrated hands‑on engineering experience administering and upgrading Trellix ePolicy Orchestrator (ePO), Trellix Agent, and the following core modules:
      • Trellix Endpoint Security (ENS) suite (specifically Threat Prevention and Firewall)
      • Trellix Data Loss Prevention (DLP)
      • Trellix Policy Auditor
    • Proven experience deploying and maintaining endpoint security agents across enterprise Linux (RHEL/CentOS/Rocky), Windows (Server & Desktop), and macOS environments.
  • Target Environment Engineering:
    • Practical experience managing and troubleshooting host-based security capabilities specifically across on-premises environments and cloud-based IaaS (VM) instances.
    • Strong troubleshooting capability in analyzing OS performance impacts, resource contention, and agent-server communication issues across complex network routing topologies.
Preferred Qualifications
  • Application Whitelisting & Integrity: Experience implementing and managing Trellix Solidcore (Application Control) for application whitelisting and file integrity monitoring (FIM).
  • Complementary Detection Technologies: Practical experience
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Endpoint Security Systems Engineer – Cyber Se
Endpoint Security Systems Engineer – Cyber Se

Special-Aerospace-Security-Services-Inc • Fort Meade (MD)

Hybrid
USD 125,000 - 160,000
Windows Systems Engineer
Windows Systems Engineer

VT Group (VTG) • Herndon (VA)

On-site
USD 140,000 - 190,000
Windows Systems Engineer
Windows Systems Engineer

VTG Defense • Herndon (VA)

On-site
USD 120,000 - 180,000
Senior Endpoint Security Architect (Trellix & Elastic Defend)
Senior Endpoint Security Architect (Trellix & Elastic Defend)

Special-Aerospace-Security-Services-Inc • Fort Meade (MD)

Hybrid
USD 125,000 - 160,000
Senior Endpoint Security Engineer — TS/SCI | Hybrid MD
Senior Endpoint Security Engineer — TS/SCI | Hybrid MD

DirectViz Solutions, LLC • Adelphi (MD)

Hybrid
USD 130,000 - 170,000
Competitive compensation
401(k) match
Medical benefits
+2
Cybersecurity Tools Administrator
Cybersecurity Tools Administrator

Saic • Newington (VA)

On-site
USD 80,000 - 120,000
Principal Engineer/Microsoft Endpoint for Defender Enterprise
Principal Engineer/Microsoft Endpoint for Defender Enterprise

Fuse Eng • Fort Meade (MD), Northern (KY)

On-site
USD 120,000 - 180,000
Principal Engineer/Microsoft Endpoint for Defender Enterprise
Principal Engineer/Microsoft Endpoint for Defender Enterprise

Fuse Engineering LLC • Fort Meade (MD)

On-site
USD 180,000 - 240,000
Endpoint Engineer (Trellix)
Endpoint Engineer (Trellix)

Crimson Phoenix • Springfield (VA)

On-site
USD 130,000 - 180,000
Cleared Cyber Security Engineer
Cleared Cyber Security Engineer

Trellix • Columbia (MD)

On-site
USD 120,000 - 170,000
Retirement Plans
Medical, Dental and Vision Coverage
Paid Time Off
+2