Endpoint Security Engineer

GuidePoint Security
United States
Workplace: RemoteFull timeFunction: CybersecurityExperience: 7+ yearsEducation: bachelorsSkills: ["Stakeholder empathy","Crisis leadership","Cross-functional collaboration","Triage under pressure","Operational scale mindset"]

Design, deploy, and operationalize behavior-based endpoint detection and response (EDR/XDR) across a large, heterogeneous fleet. Partner with application owners to tune policies, reduce false positives, and maintain business continuity, while serving as tier-3/tier-4 escalation for SOC and IT Operations during active investigations. Extend protections across hybrid and multi-cloud workloads, validate control efficacy via simulations, and drive automated remediation at scale.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
GuidePoint Security
GuidePoint Security
2 days ago

Endpoint Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 4 hours agoStatus: Live

Job Summary

Design, deploy, and operationalize behavior-based endpoint detection and response (EDR/XDR) across a large, heterogeneous fleet. Partner with application owners to tune policies, reduce false positives, and maintain business continuity, while serving as tier-3/tier-4 escalation for SOC and IT Operations during active investigations. Extend protections across hybrid and multi-cloud workloads, validate control efficacy via simulations, and drive automated remediation at scale.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Engineer, deploy, and maintain NGAV and EDR/XDR agents (e.g., CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne) across hundreds of thousands of endpoints.
  • •Implement active behavioral protections against zero-day malware, living-off-the-land binaries (LotLBs), fileless execution, and credential dumping.
  • •Partner with application owners and business units to establish baseline behavior profiles, manage allowlisting/exception workflows, and run phased ring deployments to avoid operational disruption.
  • •Serve as escalation lead for SOC analysts and IT administrators during high-severity events; perform advanced host forensics, process-tree reconstruction, memory analysis, and live remediation.
  • •Extend endpoint security standards across virtualization layers and ephemeral multi-cloud/container workloads, continuously validate control efficacy, and report on agent health, telemetry integrity, and coverage metrics.
Travel: Low travel

Pay and Benefits

Perks:Health InsuranceDental

Key Requirements

  • •7+ years of progressive technical cybersecurity engineering or infrastructure security experience, including EDR/XDR administration and engineering in distributed hybrid environments.
  • •3–5 years engineering and administering enterprise-grade EDR/XDR platforms across 50,000+ endpoints.
  • •Expert proficiency administering endpoint platforms across Windows, macOS, Linux, and container runtime environments.
  • •Advanced behavioral analysis and threat hunting using process lineage, Sysmon telemetry, and detection authoring with SQL, KQL, Splunk SPL, and/or YARA.
  • •Bachelor’s degree in CS/Cybersecurity/Information Systems (or related experience as an alternative), plus demonstrated collaboration in large enterprise SOC investigations.
Experience:7+ yearsCybersecurityEDR/XDRSOCHybrid infrastructureMulti-cloud
Education:Bachelor's in computer science, Cybersecurity, Information Systems
Skills:Stakeholder empathyCrisis leadershipCross-functional collaborationTriage under pressureOperational scale mindset
Certifications:GIAC Certified Enterprise Defender (GCED)GIAC Certified Incident Handler (GCIH)GIAC GCFACISSPCrowdStrike Certified Falcon Administrator/HunterMicrosoft Certified: Security Operations Analyst Associate / SC-200
Languages:English
Tech Stack:EDR/XDRNGAVCrowdStrike FalconMicrosoft Defender for EndpointSentinelOneAWSAzureGCPEC2VMwareNutanixKusto Query Language (KQL)Splunk SPLYARASysmonPowerShellPythonBashSQLElastic

Eligibility

Nationality:US National

Company Brief

GuidePoint Security
Provides cybersecurity consulting, managed security services, incident response, cloud and network security, and compliance solutions to enterprises and government organizations, helping clients identify, mitigate, and respond to cyber threats across complex environments.
Industry: Cybersecurity
Company Size: Large (251 to 1,000 employees)
Growth: Established Company
Headquarters: Herndon, United States
Founded: 2010
WebsiteLinkedIn