Senior Security Endpoint Engineer

Stefanini
United States
2 months ago

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$83,200.0 - $104,000.0
Working hours
Regular working hours
Job source

Tech stack

Bash Shell Identity and Access Management Intrusion Detection and Prevention Python (Programming Language) Azure Active Directory Zero Trust Network Access Security Information and Event Management Okta Deployment Automation Casper Suite Gsuite CIS Benchmarks
+2 more
Splunk Api Management

Job description

  • We’re looking for a Senior Endpoint Security Engineer to own and evolve our endpoint security and identity ecosystem across a modern, cloud-first environment.
  • This is a high-impact role where you’ll lead strategy and hands-on execution across:
  • macOS endpoint management (Jamf Pro)
  • Apple Business Manager
  • Identity platforms (Entra ID, Okta, Google Workspace)
  • EDR/XDR (CrowdStrike or similar, including managed SOC integrations)
  • You’ll help drive Zero Trust architecture, automate device lifecycle management, and improve enterprise security posture at scale.

What You’ll Do

  • Endpoint Security (macOS-Focused)
  • Own and manage Jamf Pro for macOS fleet (configuration, compliance, patching)
  • Lead Apple Business Manager integration for automated device enrollment & lifecycle
  • Implement endpoint hardening (CIS benchmarks, encryption, policy enforcement)
  • Threat Detection & Response
  • Deploy & optimize CrowdStrike (or equivalent EDR/XDR)
  • Partner with MDR/MSSP providers for 24/7 threat coverage
  • Investigate alerts, tune detections, and improve response playbooks
  • Identity & Access (Zero Trust Enablement)
  • Integrate and manage:
  • Microsoft Entra ID (Azure AD)
  • Okta (SSO, MFA, lifecycle)
  • Google Workspace (existing identity layer)
  • Build conditional access policies tied to device posture
  • Enable seamless SSO and identity federation
  • Automation & Integration
  • Automate provisioning/deprovisioning across Jamf, Okta, Entra ID, Google Workspace
  • Build scripts (Python/Bash) and API integrations
  • Integrate with SIEM/SOAR platforms (e.g., Sentinel, Splunk)
  • Compliance & Governance
  • Support SOX / SOC 2 / ISO audit readiness
  • Maintain endpoint and identity security documentation
  • Deliver reporting on device compliance, vulnerabilities, and incidents

Requirements

Do you have experience in Endpoint Security?, * Endpoint Security Engineering: 3 years (Required)

  • JAMF Pro: 3 years (Required)
  • IAM Platforms: 3 years (Required)
  • EDR/XDR: 3 years (Required)

Benefits & conditions

$40 - $50 an hour - Contract

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · WWC 2023

Videos

See all

Related articles

See all