Endpoint Engineer

Eliassen Group
Reston, VA, United States
5 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$140,000.0 - $170,000.0
Working hours
Regular working hours

Tech stack

Cyber Security Microsoft Exchange Server Executive Information Systems Identity and Access Management Intrusion Detection and Prevention Python (Programming Language) Windows PowerShell Security Information and Event Management Systems Integration System Availability Cyber Threat Analysis Restful APIs
+1 more
Security Orchestration, Automation & Response

Job description

As a Sr. Security Engineer (Trellix), you will serve as the technical lead for our client’s endpoint security and data protection ecosystem. You will balance day-to-day operational support with strategic cybersecurity engineering initiatives while partnering with security operations, infrastructure, application teams, and leadership to strengthen the overall security posture., Lead engineering and administration of Trellix security platforms, including ePO, ENS, EDR, DLP, Drive Encryption (FRP/FRMP), TIE, DXL, Policy Auditor, Rogue System Detection, Trellix Security for Microsoft Exchange (TSME), Application and Change Control (Solidcore), and File Integrity Monitoring (FIM). Implement and manage application whitelisting, endpoint hardening, encryption, and data protection technologies. Integrate endpoint security with SIEM, SOAR, threat intelligence, and identity management solutions. Develop and maintain DLP policies, device control mechanisms, and data exfiltration prevention controls. Support SOC operations and enhance 24x7 monitoring and incident response capabilities. Create and maintain security engineering standards, SOPs, playbooks, and operational procedures. Support compliance initiatives aligned to federal cybersecurity frameworks and regulations. Perform analytical troubleshooting and root-cause analysis to improve platform reliability and security outcomes.

Requirements

5+ years administering and engineering Trellix solutions in a large enterprise. Hands-on expertise with Trellix ePO, ENS, EDR, DLP, Drive Encryption (FRP/FRMP), TIE, DXL, Policy Auditor, Rogue System Detection, TSME, Solidcore, and FIM. Experience with application whitelisting, endpoint hardening, encryption, and data protection. Integration experience with SIEM, SOAR, threat intelligence, and identity platforms. Strong understanding of endpoint security architecture, threat detection, incident response, and risk management. Experience developing DLP policies, device control, and data exfiltration prevention. Experience supporting SOCs and enhancing 24x7 monitoring and response. Ability to develop standards, SOPs, playbooks, and operational procedures. Experience supporting compliance initiatives aligned with federal frameworks; strong analytical and troubleshooting skills. Nice to Haves: Insider Risk, Data Protection, or UAM program support; knowledge of CNSSD 504, NIST 800-53, NIST 800-207, and NIST CSF; automation with PowerShell, Python, and REST APIs; integrating Trellix telemetry with SIEM and SOAR; executive dashboards and metrics; FIM implementation for compliance and forensics; JCIP, FISMA, or federal assessment support; familiarity with threat-informed defense and automation frameworks; relevant Trellix, cybersecurity, or cloud certifications.

Benefits & conditions

Due to federal security clearance requirements, applicant must be a United States Citizen with an active Top Secret clearance. This is a full-time, permanent opportunity, offering a competitive salary and comprehensive benefits package. Qualified applicants must be willing and able to work on a w2 basis.

Salary: $140,000 - $170,000/ yr. w2

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:22 min

Troubleshooting commands with the Intelligent Terminal

Noraa Junker Noraa Junker · Europe 2026 Virtual

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:59 min

The danger of adopting default REST APIs

Stefan Priebsch · World Congress 2021

1:53 min

Using Rust-based Linux core utilities on Windows

Noraa Junker Noraa Junker · Europe 2026 Virtual

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all