EndPoint Security Engineer
$240k - $270kAres Management Corporation
OVER THE LAST 20 YEARS, ARES’ SUCCESS HAS BEEN DRIVEN BY OUR PEOPLE AND OUR CULTURE. TODAY, OUR TEAM IS GUIDED BY OUR CORE VALUES – COLLABORATIVE, RESPONSIBLE, ENTREPRENEURIAL, SELF-AWARE, TRUSTWORTHY – AND OUR PURPOSE TO BE A CATALYST FOR SHARED PROSPERITY AND A BETTER FUTURE. THROUGH OUR RECRUITMENT, CAREER DEVELOPMENT AND EMPLOYEE-FOCUSED PROGRAMMING, WE ARE COMMITTED TO FOSTERING A WELCOMING AND INCLUSIVE WORK ENVIRONMENT WHERE HIGH-PERFORMANCE TALENT OF DIVERSE BACKGROUNDS, EXPERIENCES, AND PERSPECTIVES CAN BUILD CAREERS
WITHIN THIS EXCITING AND GROWING INDUSTRY.
Job Description Cybersecurity Engineer – Infrastructure & Endpoint Security Engineer (Tech Lead) Job Family: Cybersecurity Engineering Direct Reports: None Position Summary: We are seeking an experienced Cybersecurity Engineer to serve as the technical lead for enterprise endpoint defense, Microsoft 365 collaboration security, secure browsing, endpoint privilege management, and measurable security control maturity. This role will lead the design, deployment, tuning, lifecycle management, and continuous improvement of security platforms that protect corporate endpoints, servers, Microsoft 365 collaboration services, SaaS platforms, and cloud-connected assets from advanced threats while enabling reliable and frictionless business workflows. This role will work closely with Security Operations, Infrastructure, Desktop Engineering, Collaboration Services, Platform Engineering, Identity, Cloud Security, Network Security, GRC, Legal, Compliance, and other cross-functional teams to ensure endpoint, Microsoft 365, SaaS, and infrastructure security controls are secure by design, consistently deployed, operationally resilient, auditable, measurable, and aligned with enterprise security standards. Detailed Responsibilities / Duties: * EDR/XDR Platforms: Lead the engineering, deployment, tuning, and scaling of CrowdStrike Falcon and/or Microsoft Defender for Endpoint platforms, including EDR, host firewall, identity protection, policy management, detection tuning, and exception handling, partnering with SOC CrowdStrike operational leadership * Lifecycle Management: Own endpoint security platform lifecycle management, including sensor deployment strategy, upgrade planning, health monitoring, coverage gap remediation, rollback procedures, and change management coordination, partnering with SOC and Workstation operational leadership * Secure Browsing Architecture: Architect, engineer, and enforce enterprise-wide security policies for secure enterprise browser technologies, including solutions such as Palo Alto Prisma Access Browser, partnering network operational leadership * Microsoft 365 Collaboration Security: Engineer and mature security controls across Exchange Online, SharePoint Online, OneDrive, Microsoft Teams, and related Microsoft 365 workloads, including external sharing governance, guest access, link-sharing controls, tenant configuration baselines, collaboration risk reduction, and secure productivity enablement. * Privilege Management: Engineer and maintain global Endpoint Privilege Management solutions using CyberArk and/or BeyondTrust to reduce or eliminate standing local administrator rights while preserving operational continuity. * Security Automation: Build robust automation workflows and playbooks using PowerShell, Python, APIs, or workflow platforms to streamline deployment validation, threat containment, reporting, exception review, and control compliance. * Engineering Escalation: Act as the engineering escalation point for complex endpoint incidents, security tooling issues, agent conflicts, detection gaps, and root-cause investigations in partnership with Security Operations and Infrastructure teams. * Posture Hardening: Develop and review baseline security configurations aligned with CIS Benchmarks, NIST guidance, and enterprise standards for Windows, macOS, and Linux endpoints. Partner with vulnerability threat management (VTM) team as they report and manage compliance in this space. * Ecosystem Integration: Integrate endpoint telemetry with SIEM, SOAR, XDR, vulnerability management, and reporting platforms to improve detection fidelity, response readiness, and measurable control effectiveness. * Microsoft Security & Compliance Integration: Partner on Microsoft Defender for Office 365, Microsoft Purview, audit logging, sensitivity labeling, DLP, retention, eDiscovery support, and Microsoft 365 Secure Score improvements to strengthen collaboration security and data protection outcomes. * Documentation & Audit: Create and maintain technical documentation, runbooks, dashboards, operational procedures, and audit evidence for endpoint security controls. Stakeholder Collaboration and Governance * Cross-Functional Alignment: Collaborate with Security Operations, Infrastructure, Desktop Engineering, Collaboration Services, Identity, Cloud Security, Platform Engineering, Network Security, GRC, Legal, Compliance, and other cross-functional partners to implement endpoint, Microsoft 365, SaaS, and infrastructure security improvements. * Risk Translation: Translate complex endpoint security risks, platform limitations, compliance needs, and technical issues into clear, actionable recommendations for both technical and non-technical stakeholders. * Vendor Governance: Support vendor governance activities, including technology evaluation, roadmap alignment, service provider coordination, issue escalation, operational performance reviews, and contract or capability assessments. * Change Management: Partner with change management, audit, and compliance teams to ensure endpoint security changes are properly assessed, documented, approved, implemented, validated, and evidenced. * Collaboration Governance: Partner with collaboration platform owners, business stakeholders, Legal, and Compliance to define and operationalize secure collaboration standards, including external sharing, guest access, sensitivity labeling, retention, and data loss prevention requirements. * Mentorship: Contribute to knowledge sharing across the team and mentor others on endpoint security architecture, troubleshooting practices, control validation, automation, and operational standards. Supervisory Responsibilities: None. This is an individual contributor role with strong expectations for technical ownership, cross-functional leadership, and mentoring through influence. Required Qualifications * 8+ years of cybersecurity, endpoint security engineering, endpoint infrastructure, or related enterprise security experience. * Strong hands-on expertise with endpoint security and Microsoft security platforms such as CrowdStrike Falcon, Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Palo Alto secure access or secure browser technologies, CyberArk, and/or BeyondTrust. * Strong knowledge of Windows, macOS, and Linux operating systems, including endpoint hardening, troubleshooting, agent behavior, security baselines, and enterprise-scale deployment considerations. * Strong understanding of endpoint networking, TLS traffic flows, proxy behavior, host firewall behavior, and how endpoint security controls interact across endpoint, network, cloud, identity, and SaaS environments. * Experience with enterprise endpoint management and deployment tools such as Microsoft Intune, MECM/SCCM, Group Policy, Jamf, or equivalent platforms. * Familiarity with cybersecurity controls for Microsoft 365 collaboration services, SaaS platforms, Microsoft Entra ID, Azure environments, conditional access, device posture, and Zero Trust concepts. * Experience securing or governing Microsoft 365 collaboration workloads such as Exchange Online, SharePoint Online, OneDrive, and Microsoft Teams, including external sharing, guest access, permissions, audit logs, and data protection controls. * Experience with endpoint firewall products, vulnerability management processes, patch coordination, and basic network security principles. * Deep critical-thinking skills with the ability to analyze detections, diagnose complex endpoint issues, distinguish true threats from false positives, and drive root-cause resolution under pressure. * Demonstrated ability to identify repeatable operational work and implement automation using scripting, APIs, workflows, or infrastructure-as-code concepts. * Experience developing endpoint security metrics, dashboards, compliance reports, exception tracking, or control effectiveness reporting. * Effective communication and collaboration skills with the ability to work across technical and non-technical stakeholder groups. Preferred Qualifications * Relevant certifications such as CrowdStrike Certified Falcon Administrator, GIAC, CISSP, Microsoft Security certifications, Azure Security Engineer Associate, or CyberArk/BeyondTrust platform certifications. * Experience with PowerShell, Python, REST APIs, Microsoft Graph API, workflow automation, or configuration-as-code approaches. * Experience with Microsoft Graph API, SharePoint Online Management Shell, Exchange Online PowerShell, Teams administration, or Microsoft 365 security and compliance automation. * Experience integrating endpoint security telemetry with corporate SIEM, SOAR, XDR, case management, vulnerability management, or data analytics ecosystems. * Experience implementing or supporting Microsoft 365 data protection capabilities such as sensitivity labels, DLP, retention policies, eDiscovery workflows, audit logging, Safe Links, Safe Attachments, and collaboration security reporting. * Experience supporting endpoint security controls in regulated, audit-driven, or financial-services environments. * Familiarity with Zero Trust security principles, identity-based access control, device posture, conditional access, and secure access service edge concepts. Leadership Qualifications- Strong sense of ownership, accountability, and attention to detail.
- Ability to lead through influence, establish technical direction, and drive
- LTD) and Short-Term Disability (STD) insurance; Employee Assistance Program
- EAP), and Commuter Benefits plan for parking and transit.
$10k
...place to do it.About the RoleYou'll be the architect of our endpoint security posture across the full fleet — macOS, Windows, and BYOD mobile... ...click the right button. You'll partner with IT, SecOps, and engineering teams to sharpen our telemetry and detections, mentor other...SuggestedFull timeWork at officeRemote workHome officeFlexible hours$230k - $260k
....We’re looking for a hands-on Detection Engineer to build and operate the systems and workflows... ...closely with Engineering, Corporate Security, and Infrastructure, with broad latitude... ...detections across cloud, identity, endpoints, and SaaS environments.Build and improve...SuggestedLocal area$150k - $250k
Hudson River Trading (HRT) is seeking a curious, innovative Security Engineer to join our Enterprise Security team and help safeguard the... ...hardening across infrastructure and Windows, Linux, and macOS endpoints, ownership of a comprehensive vulnerability management...SuggestedWork at officeLocal areaImmediate start$165k - $185k
...holidays). About the Role Betterment is hiring a Sr. Security Engineer, Corporate Information Security to be a principal member of... ...improving identity architecture, privileged access controls, endpoint hardening standards, and our overall workforce security...SuggestedTemporary workFor contractorsSummer holidayWork at officeLocal areaFlexible hours$104k - $156k
Posting Type Remote/Hybrid Job Overview The Advanced Security Engineer is a technically deep, hands-on practitioner who forms the operational... ...ensure failure redundancy through all security layers. Endpoint Security & Hardening Deploy, integrate, optimize and...SuggestedRemote work- ...Insight Global is seeking a Security Engineer (AVP / Associate AVP) for a leading global financial services firm in New York, NY. This individual... ...across multiple security domains (cloud, network, SIEM, endpoint, or identity) Strong knowledge of cloud platforms,...
$90k
...and help make a meaningful impact! Job Description: Security Engineer Location: Port Jefferson, NY (In-person, non-remote)... ...controls across on-premises networks, cloud infrastructure, endpoints, and clinical/administrative applications (EMR, lab, and medical...Temporary workRemote workMonday to Friday- ...and identity abuse spread faster than any security team can respond to. So we built... ...Palantir, ex-CTO/founders, and ex-Notion engineers, Outtake is designed for clarity, autonomy... .../ML systems and agent infrastructure Endpoint security operations (EDR/MDR) You've been...Full timeWork at officeFlexible hours
- ...right in.Who You AreJustworks is looking for an experienced security engineer skilled in detection and response, who can help enhance and... ...and refine detections using telemetry from EDR, threat intel, endpoint & cloud posture platforms and native AWS cloud...Casual workLocal area
- ...ManagementSelling Points Drive impactful security initiatives in a dynamic financial... ...security technologies across cloud, network, endpoint, and identity domains.Lead vulnerability... ...strategies.Support incident response, detection engineering, and automation workflows.Collaborate...Remote work
$139k - $204k
...and build the capabilities to stay left of boomWork alongside security partners who hold a high bar and expect you to raise itShape how... ...actionConducting deep technical investigations and hunts across endpoint, cloud, identity, and network data sources to establish scope,...Permanent employmentFull timeTemporary workCasual workWork at officeFlexible hours$118k - $157k
Datadog is seeking a motivated and experienced Security Sales Engineer to join our dynamic enterprise sales engineering team. In this role, you... ..., SOC workflows (alert triage, investigation, response), endpoint security (EDR/MDR), and the deployment and tuning of security...Work at office$106k - $170k
...our customers and for Position Overview:The Blackstone Security Operations - Engineering team is growing to support new cross-functional security... ...Experience with asset hardening (CIS/STIG)Experience with Endpoint Detection and Response systemsStrong written and oral...Full timeWork at officeLocal areaFlexible hours$192k - $240k
...and support you need to grow your career.Engineering at BrexEngineering at Brex is about... ...intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy... ...data pipelines, SOAR, domain monitoring, endpoint tooling, email protection tooling, cloud...Work at officeRemote workWork from home- Who are we?Cohere is the leading security-first enterprise AI company. We build cutting-edge... .... Cohere is a team of researchers, engineers, designers, and more, who are all passionate... ...(eg: SIEM, SOAR, domain monitoring, endpoint tooling, cloud security tooling)Respond...Full timeWork at officeLocal areaRemote workHome officeFlexible hours
$237.6k - $297k
...We are seeking a Senior Security Engineer with a specialty in Detection and Incident Response to join our Security Engineering team. This role sits at the intersection of security operations and software engineering - you won't just investigate incidents, you'll build...Full time$175.1k - $236.9k
...checkout retail, we push the boundaries of technology in every direction using the globe’s largest AWS deployment.As a Senior Security Engineer, you will collaborate with software development teams to ensure we keep our customers safe while developing these novel services...InternshipFlexible hours$110.7k - $218.3k
...& Resilience team as a forward deployed engineer supporting client patching and remediation... ...directly with client infrastructure, endpoint, server, and application teams to reduce... ...role ends on 12/31/2026.Work you'll doAs a Security Engineer II on the Cyber Defense &...Local area$195k - $240k
Here at Datadog, we think about offensive security a little bit differently. We embrace automation and AI to run adversary simulations... ...massive cloud-native environment, and we expect our offensive engineers to build the tooling that makes that possible. We're looking...Work at office$160k - $200k
...Security Engineer At Intenseye, we believe protecting people at work is non-negotiable. That's why we're building the world's most advanced... ...security, application security, data protection, endpoint, and identity. Own our compliance roadmap—including SOC 2...- ...Job Title: IT Security Engineer Work Location: New York, NY Duration: Long term Contract Position Summary: Experience... ..., CSPM configuration • Competencies: CrowdStrike Endpoint Detection And Response About Us: InterSources Inc ,...Long term contract
- ...Our client is seeking a Network & Security SME to join a Technology SWAT team focused on rapidly identifying, troubleshooting,... ...security, and access-control challenges while collaborating with engineering, endpoint, observability, and application teams to drive issues to...
- ...Security Engineer II The Security Engineer II will be responsible for analyzing external and internal threats to protect sensitive data... ...Security Incident and Event Management (SIEM), Network and Endpoint Detection and Response platforms (NDR/EDR), Advanced Malware...
- ...growing industry.Job DescriptionThe Senior Windows/SCCM/Intune Engineer is responsible for the architecture, engineering, automation, security, and lifecycle management of the firm's global Windows endpoint environment. This role serves as a senior technical leader within...Full timeTemporary workWorldwideFlexible hours
$200k - $300k
Hudson River Trading (HRT) is seeking an experienced Security Engineer to join our growing Enterprise Security team. This team is responsible... ...Access Management (IAM), Public Key Infrastructure (PKI), Endpoint Security, Vulnerability Management, and protecting HRT’s...Work at officeLocal areaImmediate startRemote work$225k - $300k
CLEAR is building THE secure identity company of the future. Our mission is to make experiences... ....As a Senior Product Security Engineer on our Product Security team you’ll help... ...management program across cloud, infrastructure, endpoints, and applications. You’ll operate the...Casual workWork at officeFlexible hours$154k - $231k
...NYC. Join Our Team... We are seeking a highly skilled Senior Security Engineer to join our advanced Security Operations team. This role is... ...detection and response across AWS, Windows, macOS, Linux, and endpoint security platforms, leveraging services such as GuardDuty,...Full timeTemporary workSecond jobWork at officeLocal areaRemote workWork from homeFlexible hours- ...Devices is responsible for ensuring that every client endpoint at Stripe adheres to our rigorous security standards. Our services play a crucial role in... ...while protecting user data.What you’ll doAs a software engineer on Secure Devices, you will work at the intersection...
- ...critical piece of financial infrastructure that allows for the improvement of global money movement.What you'll doWe're hiring a Security Engineer to build and scale the Bridge security foundation. This is a rare opportunity to design a security program from the ground up,...
$112.3k - $151.5k
...best version of themselves. As a technology-enabled business, our approach to security operations must evolve and grow alongside our services and members. We are looking for a Security Engineer with a diverse set of skills that can thrive in a challenging, fast-paced,...Local areaFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to EndPoint Security Engineer. Be the first to apply!
- staff security engineer New York, NY
- network security engineer New York, NY
- product security engineer New York, NY
- senior application security engineer New York, NY
- sr security engineer New York, NY
- security infrastructure engineer New York, NY
- entry level security engineer New York, NY
- senior security operations engineer New York, NY
- dlp security engineer New York, NY
- cloud security engineer New York, NY


