Staff Endpoint Security Engineer [Remote]
$174k - $320kIncluded Health
- Remote job
The Staff Endpoint Security Engineer is a critical, hands-on technical role responsible for designing, implementing, and maintaining robust security controls and detection mechanisms across all company and Bring-Your-Own-Device (BYOD) endpoints, including laptops, desktops, mobile phones, and other devices used by staff and contractors. This role is pivotal in protecting Included Health's sensitive data, particularly Protected Health Information (PHI), by preventing unauthorized exfiltration from endpoints and ensuring the security of devices accessing company resources. You will be instrumental in architecting and deploying advanced endpoint defenses, managing security tools, and contributing to threat response to reduce the number and criticality of HIPAA-related incidents. We are looking for deep technical expertise in endpoint security across diverse operating systems (Windows, macOS, ChromeOS, iOS, Android), strong automation skills for building and maintaining defenses, and a proactive approach to identifying and remediating vulnerabilities. This is a remote role reporting to the Chief Information Security Officer.
Responsibilities:
- Develop, implement, and maintain a comprehensive endpoint security strategy, architecture, and roadmap covering all corporate and BYOD endpoints, with a focus on proactive defense and detection engineering.
- Design and enforce security configurations, hardening standards, and baselines for diverse operating systems (Windows, macOS, ChromeOS, iOS, Android, and potentially others) to minimize attack surfaces.
- Lead the selection, deployment, administration, and optimization of endpoint security solutions, including Endpoint Detection and Response (EDR/XDR) for threat detection, Mobile Device Management (MDM/UEM) for policy enforcement, Data Loss Prevention (DLP) for data protection, anti-malware, and endpoint encryption.
- Develop and implement robust DLP policies and controls to prevent PHI and other sensitive data from leaving authorized systems via endpoints.
- Manage endpoint encryption technologies (e.g., BitLocker, FileVault, mobile encryption) to ensure data at rest is protected.
- Proactively look for threats on endpoints to identify gaps in defenses and inform the development of new detection capabilities.
- Support and provide expertise during incident response activities for endpoint-related security events, with a focus on root cause analysis to enhance preventative and detective controls.
- Conduct vulnerability assessments, manage endpoint patching and remediation efforts to address identified weaknesses in a timely manner, strengthening overall endpoint resilience.
- Develop, document, and enforce endpoint security policies, standards, and procedures, particularly for BYOD environments, ensuring compliance with HIPAA and other relevant regulations.
- Automate endpoint security tasks, compliance checks, defensive measure deployments, and reporting using scripting languages (e.g., Python, PowerShell, Bash) and security orchestration tools.
- Collaborate closely with IT operations, network security, application development, and legal/compliance teams to ensure a cohesive security posture and integrate endpoint defenses.
- Provide expert consultation and support to end-users and IT staff on endpoint security matters and best practices.
- Stay current with the latest endpoint threats, vulnerabilities, and security technologies to continuously improve our defenses.
Qualifications:
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- 5+ years of experience in endpoint security, with a strong emphasis on designing, building, implementing, and managing security controls, detection mechanisms, and defensive capabilities across a diverse range of endpoint operating systems (Windows, macOS, iOS, Android).
- Proven hands-on experience with leading Endpoint Detection and Response (EDR/XDR) solutions (e.g., CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, Carbon Black) for threat detection engineering and security policy enforcement.
- Demonstrable experience with Mobile Device Management (MDM) / Unified Endpoint Management (UEM) platforms (e.g., Microsoft Intune, Jamf Pro, VMware Workspace ONE, Kandji, MobileIron) for enforcing security configurations and policies.
- Strong knowledge of endpoint hardening techniques, security configuration management, and policy enforcement across multiple OS platforms, with a focus on building resilient systems.
- Experience designing and implementing endpoint Data Loss Prevention (DLP) strategies and tools.
- Proficiency in scripting languages (e.g., Python, PowerShell, Bash) for automating endpoint security tasks, tool integrations, and deployment of defensive measures.
- Experience with endpoint attack vectors, malware, persistence mechanisms, and designing effective mitigation and detection techniques.
- Experience with endpoint vulnerability management, patch management processes, and tools, focused on proactive remediation.
- Experience with network security principles (TCP/IP, DNS, DHCP, VPNs, firewalls) as they relate to designing and implementing endpoint security controls.
- Experience working in regulated environments and a strong understanding of HIPAA compliance requirements as they apply to endpoint protection and data handling.
Pay:
The United States new hire base salary target ranges for this full-time position are:
Zone A: $174,320 - $246,230 + equity + benefits
Zone B: $191,752 - $270,853 + equity + benefits
Zone C: $209,184 - $295,476 + equity + benefits
Zone D: $226,616 - $320,099 + equity + benefits
This range reflects the minimum and maximum target for new hire salaries for candidates based on their respective Zone. Below is additional information on Included Health's commitment to maintaining transparent and equitable compensation practices across our distinct geographic zones.
Starting base salary for you will depend on several job-related factors, unique to each candidate, which may include education; training; skills; years and depth of experience; certifications and licensure; our needs; internal peer equity; organizational considerations; and understanding of geographic and market data. Compensation structures and ranges are tailored to each zone's unique market conditions to ensure that all employees receive fair and great compensation package based on their roles and locations. Your Recruiter can share your geographic zone upon inquiry.
Benefits & Perks:
In addition to receiving a great compensation package, the compensation package may include, depending on the role, the following and more:
Remote-first culture
401(k) savings plan through Fidelity
Comprehensive medical, vision, and dental coverage through multiple medical plan options (including disability insurance)
Paid Time Off ("PTO") and Discretionary Time Off (“DTO")
12 weeks of 100% Paid Parental leave
Family Building & Compassionate Leave: Fertility coverage, $25,000 for surrogacy/adoption, and paid leave for failed treatments, adoption or pregnancies.
Work-From-Home reimbursement to support team collaboration home office work
Your recruiter will share more about the salary range and benefits package for your role during the hiring process.
About Included Health
Included Health is a new kind of healthcare company, delivering integrated virtual care and navigation. We’re on a mission to raise the standard of healthcare for everyone. We break down barriers to provide high-quality care for every person in every community — no matter where they are in their health journey or what type of care they need, from acute to chronic, behavioral to physical. We offer our members care guidance, advocacy, and access to personalized virtual and in-person care for everyday and urgent care, primary care, behavioral health, and specialty care. It’s all included. Learn more at** includedhealth.com .**
Included Health is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics or any other basis forbidden under federal, state, or local law. Included Health considers all qualified applicants with arrest or conviction records in accordance with the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance, and California law.
- ...Senior Endpoint Security Engineer - Carbon Black & Symantec Contract or Contract to Hire Remote USA **No Agencies Please Position Summary We are seeking a Senior Endpoint Security Engineer with deep expertise in VMware Carbon Black and Symantec endpoint...SuggestedContract workRemote work
- ...exclusive features. Responsibilities As a Endpoint Specialist at Tiktok USDS, you will play... ...ensure optimal system performance and security. As an Endpoint Security Specialist,... ...Trust & Safety, Security & Privacy, Engineering, User & Product Ops, Corporate Functions...SuggestedFull timeTemporary workRemote work
- ...Endpoint Security Engineer (Mid-Level) - Carbon Black & Symantec January Start Date Contract or Contract to hire **No Agencies Please Position Summary We are seeking a mid-level Endpoint Security Engineer with hands-on expertise in VMware Carbon Black and...SuggestedContract workJanuary startRemote work
- ...Job Description Focuses on securing all enterprise-managed endpoints through policy enforcement, compliance monitoring, device protection controls... ...Experience collaborating with enterprise security and engineering teams. • Strong understanding of MDM/MAM security...SuggestedRemote work
$80 - $90 per hour
...Details: Stefanini Group is looking for Sr Endpoint Security Engineer for a globally recognized company! For interested applicants, click the apply button or you may reach out to Alfher Hidalgo at (***) ***-****/****@*****.*** for faster processing...SuggestedRemote work$104k - $156k
A leading tech company seeks an Advanced Security Engineer specializing in endpoint security to design, build, and operate security controls that protect employee devices. The role involves hands-on software engineering with security oversight in a cloud environment. Candidates...Remote job$104k - $156k
A technology company is seeking an Advanced Security Engineer focused on Endpoint Security to design, build, and operate security controls that protect employee devices. The role involves implementing endpoint security measures, building automation solutions, and collaborating...Remote job$225k - $235k
Endpoint Security Engineer (Annapolis Junction, MD) Active TS/SCI w/Polygraph REQUIRED Please do not apply if you do not currently possess this level of clearance. Telework: None Basic Requirements: Bachelor’s degree in a technical field. 8 years of applicable professional...Full timeImmediate startRemote work$104k - $156k
A technology company is seeking an Advanced Security Engineer focused on Endpoint Security. This role involves designing and implementing security controls for employee endpoints, collaborating with IT and Security teams. The ideal candidate has a Bachelor's degree in Computer...Remote job- 6AM City, LLC is seeking a full-time Security Engineer to join their Information Security Office team in North Carolina. This role involves managing endpoint protection tools, conducting vulnerability management, and developing scripts for automation. Candidates should...Remote jobFull timeWork at office
$120k
RIVA Solutions Inc. is looking for a dedicated Endpoint Security Engineer to work remotely and support the Department of Health and Human Services. This pivotal role requires strong cybersecurity engineering skills, experience in federal environments, and compliance with...Remote jobFlexible hours$104k - $156k
A leading technology company is seeking an Advanced Security Engineer specializing in Endpoint Security to design and implement security controls for employee devices. The role blends software engineering with security ownership in a cloud environment, requiring strong...Remote job$120k
Title: Endpoint Security Engineer Location: Remote Terms: Full-Time Clearance: Must be a U.S. Citizen and able to obtain a Public Trust Travel: None RESULTS. INNOVATION. VALUES. ACCOUNTABILITY. That’s RIVA. Our employee-first approach has created a culture that attracts...Full timeTemporary workWork at officeRemote workFlexible hours$104k - $156k
A security-focused technology company is seeking an Advanced Security Engineer specializing in Endpoint Security. The ideal candidate will design and operate security controls across employee devices within a remote/hybrid setup. Responsibilities include building automation...Remote job$104k - $156k
A technology company is seeking an Advanced Security Engineer focused on Endpoint Security to design and implement security controls for employee endpoints. The role requires expertise in software development, endpoint protection, and cloud technologies. Candidates should...Remote job$104k - $156k
A tech company is seeking an Advanced Security Engineer focused on Endpoint Security to design and operate security controls for employee endpoints. The ideal candidate will have a Bachelor's degree in a relevant field and at least 2 years of experience in software development...Remote job$107.9k - $195.05k
Leidos is seeking an experienced M365 Security and Compliance Administrator to join our... ...a federal agency context. This senior engineering role sits at the center of the organization... ...enterprise Windows, macOS, iOS/iPadOS endpoints; ensuring compliant, reliable access to...Night shiftDay shift$145k - $200k
...Information Security Engineer Focused on Windows and Active Directory Palantir builds the world's leading software for data-driven decisions... ...environment: EDR, PAM, identity threat detection, and endpoint hardening controls. Build and maintain automation for security...Work experience placementWork at officeRemote workWork from homeRelocation package- ...each team or employee). The Impact you will have in this role: We are seeking a Senior Associate, Lead IT Security Endpoint Engineer to support the design, deployment, operation, and maintenance of Endpoint Security solutions within DTCC's Cybersecurity...Remote workFlexible hours
- ...that we serve. The Information Technology group delivers secure, reliable technology solutions that enable DTCC to be the trusted... ...Cybersecurity & Platform Strategy team, the Lead IT Security Endpoint Engineer will support the design, deployment, operation, and...Remote workFlexible hours
$112.7k - $193.2k
UnitedHealth Group is seeking an experienced Endpoint Security Engineer who will design and maintain security solutions across enterprise environments. The role offers the flexibility to work remotely from anywhere in the U.S. Ideal candidates will have 7+ years in cybersecurity...Remote work$112.7k - $193.2k
Optum is seeking a Cybersecurity Engineer to design and implement endpoint security solutions. This role requires 7+ years of experience in the cybersecurity field and expertise in EDR and antivirus solutions. The position offers remote work flexibility but requires some...Work at officeRemote work$293k - $385k
...About the Team Security is foundational to OpenAI's mission to ensure that artificial general intelligence benefits all of humanity... .... About the Role OpenAI is seeking a Security Engineer, Host Assurance to help build the trust foundations for bare-metal...Work at officeRelocation package- ...McAfee Consultant Downey, CA - Remote 12+ months Description: A Security Engineer serves as the security engineer of complex technology implementations in a product-centric environment; is comfortable with bridging the gap between legacy...Remote work
$104k - $156k
A technology company seeks an Advanced Security Engineer focused on Endpoint Security. The role involves designing and operating security controls for employee endpoints, automating security configurations, and partnering with IT on lifecycle security. Qualified candidates...Remote job- ...high-growth company that’s redefining security operations, Arctic Wolf is the right place... ...from cyber threats.As a **Staff Software Engineer,** you'll drive technical excellence across... ...backend services that power Arctic Wolf's endpoint security solutions. This role combines...Local areaRemote workWorldwideFlexible hours
$134.6k - $184.5k
...business requirements and how those requirements translate into security features and functionality. Assist with development of cyber... ...Expertise with implementation, administration, and maturation of Endpoint Detection and Response (EDR) Mobile Device Management (MDM) and...Work experience placementLocal areaRemote workWork from home$128.4k - $192.6k
...and technologies that connect the world. Our Chief Security Office ensures that our assets are safeguarded... ...Summary We are seeking a Senior Cybersecurity Engineer to secure and modernize our enterprise endpoint security environment . The role will support broader...Full timeTemporary workWork at officeLocal areaRemote workRelocation$140k - $180k
...Zachary Piper Solutions is currently seeking a talented Endpoint Security Technology Lead to support the DC3 (Defense Cyber Crimes Center) in Linthicum Heights, MD, with remote flexibility. As the Endpoint Security Technology Lead, you will play a crucial role in developing...Remote work$165k - $242k
...at What You'll Do: The Enterprise Security team at CoreWeave is responsible for securing... ...how our people work every day—identity, endpoints, networks, and SaaS—so the company can... ...About the Role: As a Senior Security Engineer, Enterprise Security , you'll design...Permanent employmentTemporary workFor contractorsCasual workWork at officeRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Endpoint Security Engineer [Remote]. Be the first to apply!
- software engineer staff Remote
- assistant engineer Remote
- technology administrator Remote
- staff data engineer Remote
- senior staff systems engineer Remote
- staff engineer Remote
- senior staff engineer Remote
- engineering aide Remote
- senior cloud security engineer Remote
- senior application security engineer Remote


