> Markdown version of [/jobs/ext/2554293-endpoint-security-engineer](https://www.wearedevelopers.com/jobs/ext/2554293-endpoint-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Endpoint Security Engineer - **Company:** Booz Allen Hamilton Inc. - **Location:** Reno, NV, United States - **Salary:** $99,000.0 - $225,000.0 - **Contract:** Permanent contract - **Skills:** Application Layers, Cyber Security, Distributed Systems, Intrusion Detection and Prevention, Automation of Marketing, Performance Tuning, CrowdStrike Falcon Management, Runbook, Security Information and Event Management, Symantec, Data Logging, Mitre Att&ck, SC Clearance, Information Technology, CIS Benchmarks, Splunk, SentinelOne Expertise, Vulnerability Analysis - **Published:** August 2, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/87929560/1 ## About the Role * Experience with incident response, threat detection, root cause analysis, and security operations within largescale enterprise environments * Experience applying CIS Benchmarks, NIST standards, CMMC requirements, CDM EDR criteria, and the CISA EDR Maturity Model to strengthen enterprise security posture * Experience developing and refining detection logic, tuning SIEM rules, and leveraging industry frameworks such as MITRE ATT&CK to strengthen detection accuracy * Knowledge of endpoint detection and response (EDR) concepts, including deployment, tuning, and optimization across extensive endpoint fleets * Knowledge of leading security tools, including Palo Alto, SentinelOne, CrowdStrike Falcon, Symantec, and Splunk * Ability to support and enhance operational workflows, documentation, and clear reporting for technical and nontechnical stakeholders * Ability to obtain a Secret clearance * Bachelor's degree in Computer Science ## Description We are seeking a cybersecurity professional who can perform security operations, endpoint security, and incident response within largescale enterprise environments. The ideal candidate will be deploying and maturing EDR platforms, enhancing detection coverage, and strengthening security workflows. This role requires a practitioner who has supported complex and distributed environments, contributed to operational reliability, and improved detection and response processes through refined logic, increased visibility, and optimized tooling. The candidate must demonstrate a strong ability to investigate and remediate security incidents, conduct proactive threat hunting, and perform detailed root cause analysis. Experience tuning detection rules, engineering advanced logging configurations, and contributing to incident response playbooks is essential. Familiarity with key frameworks, including MITRE ATT&CK, CIS Benchmarks, NIST standards, and federal maturity and compliance models will support success in this role. This position is ideal for an individual who excels at crossfunctional collaboration, clear documentation, and continuous improvement of security operations. The candidate should be comfortable working with modern EDR, SIEM, and automation platforms and demonstrate a strong commitment to maintaining service uptime and driving maturation of security capabilities. What You'll Work On: * Build strong relationships across teams and communicate complex security concepts to a wide range of audiences, including senior leadership. * Implement infrastructure and cybersecurity controls that enhance detection, improve vulnerability insights, and strengthen event correlation across large enterprises. * Conduct risk and vulnerability assessments across network, system, and application layers, leveraging bigdata analytics and traditional security event types to identify advanced threats and indicators of compromise. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)