Design, implement, and maintain endpoint hardening standards across workstations and servers, aligned with CIS benchmarks, internal standards, and risk-based guidance
Reduce enterprise attack surface by disabling unnecessary services, features, protocols, and tooling across endpoint environments
Engineer and support execution control mechanisms, including application control, script control, and prevention of unauthorized software
Partner with NetSec teams to reduce endpoint-to-network exposure, including protocol restrictions, dependency mapping, and Zero Trust enforcement considerations
Support DataSec initiatives by enabling endpoint-level controls that protect sensitive data and enforce approved software and data handling policies
Identify and assess unapproved or risky endpoint software, working with stakeholders on remediation, allow-listing, or removal paths
Collaborate with platform, infrastructure, and operations teams to ensure controls are scalable, reliable, and operationally sustainable
Contribute to security architecture documentation, standards, and roadmaps related to endpoint and defense platforms
Requirements
Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or a related discipline (or equivalent experience)
8+ years of experience in security engineering, endpoint security, or defensive cyber roles