Senior Endpoint Security Engineer (13+ years, CrowdStrike Falcon, Microsoft Defender, SentinelOne)

Triangle, Inc
Raleigh, NC, United States
4 days ago
Apply on www.techcareers.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Artificial Intelligence Antivirus Softwares Microsoft Antivirus Bash Shell Cyber Security Information Systems Computer Programming Computer Networks Query Languages Python (Programming Language) Machine Learning Windows PowerShell
+9 more
Kusto Query Language Security Information and Event Management SQL Databases EndPointSecurity Cyber Threat Analysis Information Technology Cybercrime Splunk SentinelOne Expertise

Job description

  • Engineer, deploy, and maintain Next-Gen Antivirus (NGAV) and Endpoint Detection & Response (EDR/XDR) agents across a diverse range of endpoints.
  • Implement behavioral protections against zero-day malware and advanced persistent threats.
  • Collaborate with application owners and business units to establish baseline behavior profiles.
  • Manage allowlisting, exception workflows, and phased ring deployments to ensure seamless protection.
  • Support SOC investigations and collaborate with system owners for enterprise security.

Requirements

  • U.S. Citizenship required.
  • 13+ years of relevant experience in cybersecurity engineering or infrastructure security roles.
  • Experience with enterprise-grade EDR/XDR platforms (CrowdStrike Falcon, Microsoft Defender, and/or SentinelOne SIEM) across extensive endpoint environments
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or equivalent experience (17 years total).
  • Proficiency in administering endpoint platforms across various operating systems.
  • Expertise in behavioral analysis, threat hunting, and using query languages like SQL, KQL, and YARA.
  • Strong programming skills in PowerShell, Python, or Bash for automation.
  • Fluency in using AI/ML technologies to automate security activities.
  • Ability to balance security controls with business operations, ensuring minimal disruption.
  • Experience in crisis leadership, operational scale management, and policy automation.

Preferred:

  • GIAC Certified Enterprise Defender (GCED), GCIH, or GCFA certification.
  • CISSP certification.
  • Vendor-specific credentials, such as CrowdStrike Certified Falcon Administrator or Microsoft Certified: Security Operations Analyst Associate.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.techcareers.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · World Congress 2022

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all