Staff Engineer, Endpoint Security
Role details
Job location
Tech stack
Job description
privileged admin devices, and site-support endpoints. - Develop practical device standards for remote workers, office users, data center staff, contractors, and high-risk user populations. Access & Security Integration - Establish device posture requirements for access to enterprise applications, production systems, privileged workflows, and sensitive data. - Integrate endpoint posture with identity, privileged access, vulnerability management, and detection workflows. - Partner with Identity and Privileged Access teams to support high-risk application and production access decisions. Privilege Reduction & Endpoint Operations - Drive local admin reduction and controlled elevation patterns that reduce risk without creating operational dead ends. - Lead endpoint rollout readiness, including deployment sequencing, exception handling, user communication, rollback planning, and adoption metrics. - Create an exception model with clear ownership, risk documentation, compensating controls
Requirements
expiry, and review cadence. Telemetry, Evidence & Reporting - Define endpoint telemetry requirements to support investigations, detection engineering, audit evidence, and executive reporting. - Build visibility into device security posture through dashboards covering coverage, stale devices, unmanaged endpoints, local admin status, and telemetry health. - Measure progress through metrics such as coverage, unmanaged devices, local admin reduction, hardening compliance, and endpoint detection health. KPIs - Managed device coverage - Reduction in stale and unmanaged endpoints - Local admin reductionHardening compliance and endpoint detection health About You - 7+ years in endpoint security, device management, enterprise security engineering, infrastructure security, or related engineering roles - Hands-on experience securing Windows, macOS, and/or Linux endpoints in enterprise environments - Experience reducing standing local admin privileges or implementing controlled elevation models - Strong scripting, automation, packaging, configuration, or endpoint workflow engineering skills - Ability to balance strong endpoint controls with user experience, operational reliability, and business velocity - Experience partnering with IT, identity, infrastructure, security operations, legal, privacy, and business stakeholders - Experience securing high-risk engineering populations, data center support teams, privileged administrators, or remote-first workforces - Experience using device posture in conditional access, privileged access, or production access decisions - Experience producing audit-ready evidence for device controls and endpoint security posture What we can offer you