Job Summary
The L3 Endpoint Security Engineer serves as the technical Subject Matter Expert (SME) for Antivirus (AV), Next-Generation Antivirus (NGAV), and Endpoint Detection & Response (EDR) platforms. This role is responsible for solution architecture, advanced threat investigations, platform optimization, governance, and escalation support for complex security incidents and infrastructure issues. The position provides technical leadership to L1/L2 teams and drives continuous improvement of endpoint security services
Key Responsibilities
Must have 8+ years of experience in Endpoint Security and Implementation (MS Defender, SentinelOne, CrowdStrike, JAMF Protect, Zimperium) • Act as the Subject Matter Expert (SME) for enterprise Antivirus (AV), Next-Generation Antivirus (NGAV), and Endpoint Detection & Response (EDR) platforms. • Design, implement, administer, and optimize endpoint security solutions across enterprise environments. • Lead deployment, migration, upgrade, and integration projects for endpoint security technologies. • Define and maintain endpoint security baselines, standards, policies, and governance controls for AV, EDR, Firewall, ASR, Device Control, and Web Protection • Lead investigation and resolution of critical security incidents, malware outbreaks, ransomware attacks, and advanced threats. • Perform advanced threat hunting, malware analysis, forensic investigations, and root cause analysis activities. • Develop and implement containment, remediation, recovery, and detection enhancement strategies to improve security posture. • Review and optimize security policies, exclusions, detections, alerts, and response workflows to improve protection effectiveness and reduce false positives. • Act as the highest technical escalation point for complex endpoint security, agent health, onboarding, telemetry, policy, and integration-related issues. • Design and support integrations with Microsoft Intune, Active Directory, Entra ID, SIEM platforms, Microsoft Sentinel, Splunk, and SOC monitoring solutions • Drive continuous service improvement initiatives through platform tuning, automation, orchestration, and operational process optimization. • Conduct Proof of Concepts (POCs), evaluate emerging endpoint security technologies, and provide strategic recommendations for future security enhancements. • Collaborate with SOC, Infrastructure, Cloud, and Endpoint Management teams to strengthen detection, response, and security operations capabilities. • Develop and maintain technical documentation, architecture diagrams, SOPs, runbooks, standards, and knowledge base articles. • Provide technical leadership, mentoring, training, and knowledge transfer to L1 and L2 engineers. • Prepare executive reports, security posture assessments, compliance reports, risk analyses, and strategic recommendations for stakeholders and management. • Support audit, compliance, and governance activities while ensuring adherence to organizational security requirements and best practices.
Skill Requirements
MS Defender, SentinelOne, CrowdStrike, JAMF Protect, Zimperium
Other Requirements