Overview
ITC is a Woman Owned Small Business delivering exceptional consultancy to the U.S. Government in Systems/Software Engineering, Cybersecurity Solutions, Mission Operations and INTEL Analysis, and Management Services. We are searching for a Top‑Secret SCI with polygraph clearance to serve as a Senior‑Level Systems Engineer (Level 3). The engineer will serve as a principal technical leader and subject‑matter expert within the National Security Agency’s Enterprise Endpoint Detection and Response (EDR) Program.
Responsibilities
The systems engineer will:
- Drive the strategic architectural design, end‑to‑end integration, deployment, and optimization of premier endpoint security platforms, specifically Microsoft Defender for Endpoint (MDE) and Trellix HX.
- Lead the lifecycle engineering and scale‑out architecture of MDE and Trellix HX across hybrid environments, including on‑premises, cloud, and virtual desktop infrastructures (VDI).
- Create complex system engineering and implementation plans, tune agent configurations and exclusion policies, and monitor overall endpoint health at scale.
- Collaborate closely with threat hunting and intelligence analysts to translate actionable threat intelligence into custom technical indicators of compromise (IOCs) using Kusto Query Language (KQL) and YARA rules.
- Act as a primary technical advisor to Government stakeholders on system risks and engineering considerations.
- Provide advanced forensic support to the SOC during critical high‑priority incidents.
- Mentor junior and mid‑level engineering personnel within the program.
Requirements
- TS/SCI with FullScope Polygraph
- A Bachelor’s degree in a qualified engineering field.
- Proven engineering experience with Microsoft Defender for Endpoint (MDE) architecture, deployment strategies via MECM/SCCM or Intune, policy ring management, and advanced hunting using Kusto Query Language (KQL).
- Demonstrated experience engineering, deploying, and managing Trellix HX (formerly FireEye) controllers and agents within air‑gapped or highly restricted networks, including the creation of OpenIOC and YARA rules.
- In‑depth technical understanding of Windows, Linux, and macOS internals, including file systems, registry structures, and process execution mechanics.
- Compliance with DoD 8570/8140 IAM Level II or III baseline certifications.
Desired
- Vendor certifications: Microsoft Certified: Security Operations Analyst Associate (SC‑200), Azure Security Engineer Associate (AZ‑500), or Trellix Certified Engineering credentials.
- Experience with Model‑Based Systems Engineering (MBSE), Cameo, and workflow management within the Atlassian Suite (Jira, Confluence).
- Familiarity with NSA Technical Manual Standards (e.g., NSA DS‑89) and defense‑in‑depth engineering principles.
- Strong record of team collaboration, exceptional transparency in managing high‑consequence infrastructure, and an aptitude for developing technical leadership pipelines.
Benefits
- 401(k) plan with company contributions (safe harbor and profit sharing)
- 11 Federal holidays plus 21 days PTO
- Medical, Dental, & Vision with substantial company contributions
- Company‑provided Life, LTD, and STD insurance
- Health Savings Account / Flexible Spending Account
- Referral bonusesPerformance bonuses
- Tuition assistance for education, training, and professional certifications
- Career development opportunities
The salary range for this position is: $160,000 – $240,000.
ITC is an Equal Opportunity employer. Qualified applicants or employees will receive consideration for employment without regard to race, color, religion, ethnicity or national origin, ancestry, age, sex, sexual orientation, gender identity, pregnancy (including childbirth or related condition) citizenship, familial status, mental or physical disability status, veteran status, genetic information, other non‑disqualifying disability, or any other characteristic protected by law.