Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Endpoint Security Engineer III

$130.71k - $182.99k
Full-time

BLUE ORIGIN

Application close date:Applications will be accepted on an ongoing basis until the requisition is closed.

At Blue Origin, we envision millions of people living and working in space for the benefit of Earth. We’re working to develop reusable, safe, and low-cost space vehicles and systems within a culture of safety, collaboration, and inclusion. Join our team of problem solvers as we add new chapters to the history of spaceflight!

This role is part of Enterprise Technology (ET), where we’re developing the digital infrastructure needed to build the road to space, with an emphasis on digital capabilities required to advance Blue Origin’s mission. Enterprise Technology is the center of excellence for digital technology at Blue Origin, providing oversight and governance to align technology and business strategies.

As part of a small, accomplished team of experts, you will protect and secure the endpoints that Blue Origin's engineers, technicians, and business teams depend on every day. You will share in the team's impact on all aspects of endpoint security, and you will lead and assist with many aspects of operations and engineering on the Endpoint Experience team.

Security engineers evaluate, select, procure, implement, and operate security technology supporting enterprise and space systems. This role is the technical lead for our AV and EDR stack — Microsoft Defender for Endpoint and Tanium — and it is deliberately operating-system agnostic. You will be expected to reason about detection coverage, agent health, and security posture with equal fluency across all systems.

We are looking for someone to apply their technical expertise, leadership skills, and commitment to quality to positively impact safe human spaceflight. Passion for our mission and vision is required.

Responsibilities

Microsoft Defender for Endpoint
- Own endpoint detection and response coverage across the fleet: onboarding and offboarding, agent lifecycle, platform build currency, and tamper protection, on Windows, macOS, and Linux.
- Monitor and remediate sensor health, and continuously reconcile Defender coverage against authoritative inventory so that unmonitored endpoints are found and fixed rather than discovered during an incident.
- Manage antivirus and protection policy — scan behavior, definition currency, at tack surface reduction rules, exclusions, and platform-specific configuration — balancing security outcome against engineering workload impact.
- Write and maintain advanced hunting queries to answer posture and exposure questions, and understand the limits of what endpoint telemetry can and cannot show.
- Operate diagnostic tooling (client analyzers and equivalent) and drive vendor cases to resolution when platform defects affect the fleet.
- Act on security recommendations and vulnerability findings surfaced by the platform, prioritizing by real exposure rather than raw score.

Tanium
- Own the architecture, configuration, and operation of the enterprise endpoint management and security platform, including content, permissions, and shared services.
- Author and maintain platform content — sensors, packages, and saved questions — that returns correct answers across every supported operating system, including multi-distribution Linux.
- Design and maintain the role-based access model: roles, personas, user groups, computer groups, and filter groups, scoped to least privilege across multiple consuming organizations.
- Configure action groups and targeting tiers so that change lands predictably and progressively across the fleet.
- Use the platform as the fleet's measurement and remediation instrument: build the content that reports security posture and closes the gap between "we have a policy" and "we can prove it is applied."

Posture reporting, requirements, and documentation
- Instrument the fleet to report security posture against recognized benchmarks (CIS, DISA STIG) and to evidence control implementation for compliance obligations, including NIST 800-series and ISO 27000-series requirements.
- Report on the state of adjacent security controls owned by partner engineers — including disk encryption and device control — using Defender and Tanium telemetry, so that coverage gaps are visible without duplicating ownership of those platforms.
- Build platform content and collectors that triage endpoint and application performance problems — crashes, driver faults, and degradation — and attribute them to a responsible component, so that fleet-wide issues are diagnosed from evidence rather than anecdote.
- Work with engineering and development groups to provide endpoint security requirements for new applications and systems.
- Document processes and procedures relating to endpoint security technologies, at a standard others can execute from.
- Contribute to the endpoint security roadmap and to best practices at the department level.

Technical leadership
- Contribute to the strategy of endpoint security within the team; independently determine and develop technical plans for complex problems and use technical judgement to select methods and techniques best suited to the problem.
- As a senior member of the team, mentor other team members on security technologies and standards.
- Review the work of other team members and be accountable for technical analysis within your discipline.
- Interface effectively with all levels of the organization, up to and including executive staff, as well as external customers and vendors.
- Work closely with the Cyber Security Threat Operations team and partner IT teams to build and maintain endpoint security technologies.
- Regular participation in on-call rotation.
- Available to support flexible work hours to support various organizational objectives.

Qualifications

- Minimum of a bachelor's degree in Information Systems, Computer Science, or equivalent practical experience.
- 5+ years performing deployments and managing endpoint security tooling.
- Hands-on engineering experience operating an enterprise antivirus and endpoint detection and response stack at fleet scale. Microsoft Defender for Endpoint strongly preferred, including onboarding, antivirus and ASR policy configuration, sensor health management, and advanced hunting.
- Hands-on administration and engineering experience with an enterprise endpoint management platform. Tanium strongly preferred.
- Familiarity with endpoint encryption, and with application performance monitoring and troubleshooting.
- Genuine multi-platform depth. Demonstrated ability to administer, instrument, and troubleshoot security tooling on Windows, macOS, and Linux — not deep expertise in one with passing familiarity with the others. Candidates should be able to speak to endpoint security work they have personally done on all three.
- Demonstrated experience executing a platform migration or major version cutover: planning, phased execution, validation, and operational handoff.
- Strong scripting and automation skills across platforms — PowerShell, Python, and/or Bash — to optimize for consistency and efficiency.
- Familiarity with host, network, and cloud-based security technologies.
- Experience with NIST 800-series standards, including 800-30, 800-53, 800-82, and 800-171.
- Experience with ISO 27000-series standards.
- Active Directory and Entra ID concepts as they apply to endpoint identity, scoping, and access.
- Ability to interface with all levels of an organization up to the executive staff and external customers.
- Ability to earn trust, maintain positive and professional relationships, and contribute to a culture of inclusion.
- Ability to convey technical information to technical and non-technical users, and to document epics, stories, and tasks in the enterprise ticketing system.

Desired
- Applicable security certifications — CISSP, GIAC certifications, CISM, CISA, or Security+.
- Experience operating security platforms in a FedRAMP, GCC High, or otherwise accredited cloud environment.
- Experience with Microsoft Intune for endpoint security policy delivery.
- Experience authoring Tanium sensors for Linux across multiple distributions, and an understanding of why cross-platform content is harder than it looks.
- Experience with CMMC-driven control implementation and CUI handling requirements.
- Experience with security automation and orchestration, and with platform APIs for programmatic administration.
- Understanding of incident response processes and the role endpoint telemetry plays in them.
- Experience supporting engineering or manufacturing workstation fleets with specialized hardware and software requirements.
- Exposure to infrastructure-as-code and configuration management (Ansible or equivalent).
- Experience mentoring engineers and raising the operational maturity of a platform beyond single-owner dependency.

Export Control Regulations

Applicants for employment at Blue Origin must be a U.S. citizen or national, U.S. permanent resident (i.e. current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.

Base Pay Range for:

WA applicants is $130,706.00 - $182,987.70

Other site ranges may differ

Culture Statement

Don’t meet all desired requirements? Studies have shown that some people are less likely to apply to jobs unless they meet every single desired qualification. At Blue Origin, we are dedicated to building an authentic workplace, so if you’re excited about this role but your past experience doesn’t align perfectly with every desired qualification in the job description, we encourage you to apply anyway. You may be just the right candidate for this or other roles.

Export Control Regulations

Applicants for employment at Blue Origin must be a U.S. citizen or national, U.S. permanent resident (i.e. current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.

Background Check

  • Required for all positions: Blue’s Standard Background Check
  • Required for Certain Job Profiles: Defense Biometric Identification System (DBIDS) background check if at any time the role requires one to be on a military installation
  • Required for Certain Job Profiles: Drivers who operate Commercial Motor Vehicles with a Gross Vehicle Weight (GVW), Gross Vehicle Weight Rating (GVWR) or combination of power unit and trailer that meets or exceeds 10,001 lbs. and/or transports placardable amounts of hazardous materials by ground in any vehicle on a public road while in commerce, may be subject to additional Federal Motor Carrier Safety Regulations including: Driver Qualification Files, Medical Certification (obtained before onboarding), Road Test, Hours of Service, Drug and Alcohol Testing, vehicle inspection requirements, CDL requirements (if applicable) and hazardous materials transportation/shipping training.
  • Required for certain Job Profiles: Ability to obtain and maintain Merchant Mariner Credential, which includes pre-employment and random drug testing as well as DOT physical

Benefits

  • Benefits include: Medical, dental, vision, basic and supplemental life insurance, paid parental leave, short and long-term disability, 401(k) with a company match of up to 5%, and an Education Support Program.
  • Stock Options for all regular employees (working at least 20 hours/week)
  • Paid Time Off: Up to four (4) weeks per year based on weekly scheduled hours, and up to 14 company-paid holidays.
  • Dependent on role type and job level, employees may be eligible for benefits and bonuses based on the company's intent to reward individual contributions and enable them to share in the company's results, or other factors at the company's sole discretion. Bonus amounts and eligibility are not guaranteed and subject to change and cancellation. Please check with your recruiter for more details.

Equal Employment Opportunity

Blue Origin is proud to be an Equal Opportunity/Affirmative Action Employer and is committed to attracting, retaining, and developing a highly qualified and dedicated work force. Blue Origin hires and promotes people on the basis of their qualifications, performance, and abilities. We support the establishment and maintenance of a workplace that fosters trust, equality, and teamwork. We provide all qualified applicants for employment and employees with equal opportunities for hire, promotion, and other terms and conditions of employment, regardless of their race, color, religion, sex, sexual orientation, gender identity, national origin/ethnicity, age, physical or mental disability, genetic factors, military/veteran status, or any other status or characteristic protected by federal, state, and/or local law. Blue Origin will consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state, and local laws, including the Washington Fair Chance Act, the California Fair Chance Act, the Los Angeles Fair Chance in Hiring Ordinance, and other applicable laws. For more information on “Know Your Rights,” please see here.

Affirmative Action and Disability Accommodation

Applicants wishing to receive information on Blue Origin’s Affirmative Action Plans, or applicants requiring a reasonable accommodation in order to participate in the application and/or interview process, please contact us at View email address on aiapply.co. Please note this is a publicly managed inbox. Please do not include any personal medical information in your request.

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Endpoint Security Engineer III in Seattle, WA vacancy
  •  ...The Endpoint Security & Exposure Management Engineer is responsible for the design, implementation, administration, and continuous improvement of endpoint security controls and enterprise exposure management capabilities. This role focuses on reducing organizational cyber... 
    Suggested

    Jacobs

    Seattle, WA
    2 days ago
  • $120k - $145k

    Systems Engineer III - Windows - Hyper-V and Defender Endpoint ManagementLocation: Lynnwood, WA -mainly remote. We are open to hiring in WA and out of state...  ...Windows Server management, Active Directory and identity security, endpoint engineering, automation, and ensuring... 
    Suggested
    Remote work

    CyberCoders

    Seattle, WA
    1 day ago
  • $146k

     ...careers and have the flexibility, benefits, and support to do their best work. Join us and build for travelers everywhere. Security Engineer III Our Technology Team partners with teams across Expedia Group to create innovative products, services, and tools to... 
    Suggested
    Shift work

    Expedia Group

    Seattle, WA
    6 days ago
  •  ...organizations across the globe to create, secure, and run applications that enhance how...  ...where each individual can thrive.Security Engineer III _ Incident ResponseF5 Office of the CISO...  ...support across cloud, identity, endpoint, application, API, Kubernetes, WAAP, DDoS... 
    Suggested
    Full time
    Work at office
    Local area

    F5 Networks

    Seattle, WA
    3 days ago
  • $165k - $242k

     ...'ll Do: The Enterprise Security team at CoreWeave is responsible...  ...work every day-identity, endpoints, networks, and SaaS-so the company...  ...: As a Senior Security Engineer, Enterprise Security , you'...  ...(green card holder), (iii) refugee under 8 U.S.C. § 115... 
    Suggested
    Permanent employment
    Full time
    Temporary work
    For contractors
    Casual work
    Work at office
    Remote work
    Flexible hours

    CoreWeave

    Bellevue, WA
    1 day ago
  • $175.1k - $236.9k

     ...we’re looking for talented people who want to help.You’ll join a diverse team of software, hardware, and network engineers, supply chain specialists, security experts, operations managers, and other vital roles. You’ll collaborate with people across AWS to help us... 
    Remote work
    Flexible hours

    Amazon

    Seattle, WA
    1 day ago
  • $159.3k - $202.4k

    Amazon Healthcare Security's (HealthSec) Detections & Monitoring team is hiring a Security Engineer II to design, build, and operate detection and monitoring capabilities...  ...across cloud infrastructure, applications, endpoints, and AI-powered systems. You will work at the... 
    Flexible hours

    Amazon

    Seattle, WA
    2 days ago
  • $218.4k - $365.2k

     ...Salesforce.The ExperienceThe Enterprise Security Technology team builds and operates highly...  ...services. Our key investments are in Endpoint Security along with Network, Email, and...  ...goalsPartner with product management and engineering leads to drive technical roadmaps and platform... 
    Full time

    Salesforce

    Bellevue, WA
    11 hours ago
  • $166k - $253k

     ...ABOUT THE JOB  We're seeking a Security Software Engineer to develop novel security tooling for securing embedded Linux systems and Android...  ...devices. The ideal candidate can develop, test, and debug an endpoint detection and response agent with mission critical... 
    Full time
    Work experience placement
    Immediate start
    Relocation package

    Anduril Industries

    Seattle, WA
    13 hours ago
  • $146k

     ...Product Security Architect III At Expedia Group, we help travelers explore the world, one journey at a time. As a global travel company...  ...multiple platforms and services. Partner with product, engineering, and infrastructure teams to design secure system architectures... 

    Expedia Group

    Seattle, WA
    2 days ago
  • $168k - $210k

     ...customers sending money globally, providing secure, simple, and reliable ways to manage...  ...About the Role:About the Role As a Security Engineer on Remitly's Corporate Security team,...  ...maintainable not one-off scripts.Secure endpoints & devices manage and improve MDM... 
    Full time
    Work at office
    Worldwide
    3 days per week

    Remitly

    Seattle, WA
    1 day ago
  • $116.2k - $229.1k

    Position Summary Cloud Infrastructure Engineer III - Workplace Engineering/M365 AI &...  ...across Microsoft 365, Active Directory, endpoint management, digital employee experience...  ...AI governance, adoption, compliance, security, and change management initiativesExperience... 
    Local area

    Deloitte

    Seattle, WA
    13 hours ago
  • $320k - $405k

     ...Security Engineer, Corporate Security San Francisco, CA | Seattle, WA | New York City, NY | Washington, DC About Anthropic Anthropic...  ...contributor role. Key Responsibilities Drive endpoint hardening across macOS, Windows, Linux, and ChromeOS, including... 
    Visa sponsorship
    Flexible hours

    Anthropic

    Seattle, WA
    2 days ago
  • $134.5k - $265.1k

     ...Summary As a Cyber Forward Deployed Engineer (FDE), you will work at the intersection...  ...doAs an Engineering and Product Engineer III on the Cyber Engineering team, you will...  ...cybersecurity concepts (e.g., application security, cloud security, identity, detection... 
    Local area
    Visa sponsorship

    Deloitte

    Seattle, WA
    1 day ago
  • $2,000 per month

     ...Senior Security Research EngineerElastic, the Search AI Company, enables everyone to find...  ...the promise of AI.The Elastic Security Endpoint Protections team researches, designs, and...  ...looking for a Senior Security Research Engineer to help lead our efforts to build innovative... 
    Local area
    Flexible hours

    Elastic

    Seattle, WA
    13 hours ago
  • $96.68k - $157.59k

     ...Security Engineer Salary Range: $96,680.00 to $157,590.00 USD Would you like to have a career that makes a daily difference in people...  ...access, and policy breaches. Conduct log-based and endpoint-based threat detection to detect and protect against threats... 
    Full time
    Local area
    Shift work

    Admin Campus

    Renton, WA
    4 days ago
  • $146k - $260k

     ...What we are looking for We're searching for a Senior Security Engineer to join our Enterprise Security Engineering team, reporting...  ...implementation, and hardening of enterprise security controls across endpoint, identity, network, and data domains Help configure, tune... 
    Full time
    Work at office
    Local area
    3 days per week

    Aurora

    Seattle, WA
    1 day ago
  • $176k - $253k

     ...redefine the future of how work gets done.We are hiring a Senior Security Engineer, dedicated to Product Security Incident Response. In this...  ...'s AI operational infrastructure - from model serving endpoints to Cortex Search indexes and Snowpark ML pipelines.Lead with... 

    Snowflake

    Bellevue, WA
    2 days ago
  •  ...Seattle, WA to drive high-impact Identity Security initiatives across our enterprise IAM...  ...organization and partners closely with engineering, architecture, compliance, and business...  ...programs using BeyondTrust Password Safe, Endpoint Privilege Management (EPM), and Privileged... 
    Temporary work
    Remote work

    Confiz

    Seattle, WA
    a month ago
  • $180k - $220k

     ...Network Security EngineerSan Francisco, California, United States; Seattle, Washington,...  ...ForWe're looking for a Network Security Engineer to design, implement, and maintain secure...  ...vulnerability scanners (e.g., Nessus, Qualys), and endpoint security solutions.Relevant... 
    Work at office
    Work from home
    Flexible hours
    2 days per week

    Lightning AI

    Seattle, WA
    1 day ago
  • $192k - $240k

     ...and support you need to grow your career.Engineering at BrexEngineering at Brex is about...  ...intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy...  ...data pipelines, SOAR, domain monitoring, endpoint tooling, email protection tooling, cloud... 
    Work at office
    Remote work
    Work from home

    Brex

    Seattle, WA
    13 hours ago
  • $126k - $188k

     ...Indeed’s applications and services by identifying security risks early, partnering closely with product and engineering teams, and guiding practical remediation. This...  ...maintain and mature Indeed’s ZTNA solution and Endpoint Security domain through further tool... 
    Work experience placement
    Local area
    Remote work

    Indeed

    Seattle, WA
    4 days ago
  •  ..., and the financial world.The role: We’re seeking a Staff Security Detection Engineer to build and mature SoFi’s machine learning-driven detection...  ..., and rollback).Engineer and tune features from identity, endpoint, network, cloud, SaaS, and application telemetry stored in... 
    Remote work

    SoFi

    Seattle, WA
    4 days ago
  • $2,000 per month

     ...all structured and unstructured data — securing and protecting private information more...  ...adversary behavior through malware reverse engineering, threat hunting, and vulnerability...  ...threats. Work through data from millions of endpoints to surface the activity worth... 
    Local area
    Flexible hours

    Elasticsearch B.V.

    Seattle, WA
    4 days ago
  • As a Principal Security Engineer at JPMorganChase within the Cybersecurity and Technology Controls organization, you lead at least one technical...  ...risk identification and remediation, as well as firm‑wide endpoint and server anti‑virus capabilities. You will partner closely... 

    JP Morgan Chase

    Seattle, WA
    13 hours ago
  •  ...Senior Security Engineer The Security Engineering team is responsible for protecting Sift's products, infrastructure, and data while enabling...  ...(e.g., IAM policies, network controls, secrets management, endpoint protections, container and workload security). Embed with... 

    Sift

    Seattle, WA
    2 days ago
  • $142k - $220.5k

     ...days/week to be considered for this position. The Senior Security Engineer on the TIDE team is a hybrid practitioner who writes detection...  ...rules in CrowdStrike NG-SIEM (LogScale/CQL) across endpoint, email, identity, network, and cloud domains ~ Operationalize... 
    Full time
    Work at office

    Nordstrom

    Seattle, WA
    1 day ago
  • $159.3k - $202.4k

    Amazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within the Amazon Security Incident Response Team (SIRT). SIRT Security Engineers respond to security events, conduct analysis of threats... 
    Internship
    Flexible hours

    Amazon

    Seattle, WA
    3 days ago
  • $178.4k - $226.7k

    The Ads Security organization at Amazon is dedicated to creating innovative technical solutions that detect, assess, and mitigate security...  ...inherently secure. We are seeking a talented Senior Security Engineer to join our team, where you will have the opportunity to... 
    Flexible hours

    Amazon

    Bellevue, WA
    4 days ago
  • $136k - $184k

     ...to no-checkout retail, we push the boundaries of technology in every direction using the globe’s largest AWS deployment.As a Security Engineer, you will collaborate with software development teams to ensure we keep our customers safe while developing these novel services... 
    Internship
    Flexible hours

    Amazon

    Seattle, WA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Endpoint Security Engineer III. Be the first to apply!