Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Endpoint Security & Exposure Engineer (Cyber Security)

Jacobs

The Endpoint Security & Exposure Management Engineer is responsible for the design, implementation, administration, and continuous improvement of endpoint security controls and enterprise exposure management capabilities. This role focuses on reducing organizational cyber risk through effective application control, privilege management, vulnerability management, and remediation governance.

The successful candidate will serve as a technical subject matter expert for endpoint security technologies and exposure management platforms, within the Cybersecurity Engineering team, working closely with infrastructure, desktop engineering, application support, cloud, and wider IT teams to strengthen the organization's security posture and ensure timely remediation of identified risks.

Key Responsibilities

Endpoint Security

  • Design, implement, and maintain endpoint security controls across Windows, Linux, and macOS environments.

  • Administer and optimize application control and application allowlisting solutions.

  • Develop and maintain privilege management policies based on Zero Trust and least-privilege principles.

  • Investigate and resolve endpoint security issues related to application execution, privilege elevation, and policy enforcement.

  • Collaborate with desktop engineering teams to develop secure endpoint standards and configurations.

  • Support endpoint hardening initiatives aligned with industry best practices and security frameworks.

  • Develop reporting and metrics to demonstrate endpoint security effectiveness and risk reduction.

Exposure Management & Vulnerability Management

  • Manage the enterprise vulnerability management lifecycle, including identification, assessment, prioritization, remediation, and validation.

  • Administer vulnerability scanning and assessment platforms across on-premises, cloud, and hybrid environments.

  • Analyze vulnerability findings and prioritize remediation activities based on risk, exploitability, asset criticality, and business impact.

  • Drive remediation efforts with infrastructure, application, cloud, and operations teams.

  • Monitor remediation performance against defined service level objectives and security policies.

  • Perform vulnerability trend analysis and identify recurring risk patterns.

  • Support attack surface reduction initiatives through proactive exposure identification and mitigation.

  • Administer and maintain ServiceNow Vulnerability Response.

  • Configure integrations between ServiceNow and vulnerability assessment platforms.

  • Develop and optimize vulnerability workflows, assignment rules, remediation tasks, and reporting.

  • Monitor remediation progress and ensure effective stakeholder engagement.

  • Create dashboards and executive-level reporting to communicate exposure trends and remediation performance.

Security Operations & Risk Management

  • Support security incident investigations involving vulnerable systems, unauthorized privilege use, or endpoint compromise.

  • Assess emerging vulnerabilities, threats, and security advisories to determine organizational impact.

  • Provide risk-based recommendations for remediation and compensating controls.

  • Participate in security assessments, audits, and compliance activities.

  • Contribute to cybersecurity standards, policies, and technical security roadmaps.

  • Act as a technical advisor for endpoint security and vulnerability management initiatives.

Key Technical Skills

Endpoint Security

  • Application control and allowlisting technologies

  • Privilege management solutions

  • Endpoint hardening methodologies

  • Zero Trust security principles

  • Least-privilege administration

  • Endpoint security architecture

Vulnerability & Exposure Management

  • Vulnerability assessment and management

  • Exposure management practices

  • Risk prioritization frameworks

  • Attack surface management

  • Patch and remediation management

  • Security risk analysis

Platforms & Technologies

  • Microsoft Windows Server and Windows 11

  • Linux operating systems

  • Active Directory and Entra ID

  • Microsoft Intune

  • Microsoft Defender for Endpoint

  • Cloud platforms (Azure, AWS, or Google Cloud)

  • ServiceNow Vulnerability Response

Scripting & Automation

  • PowerShell

  • Python

  • API integrations and workflow automation

  • Security reporting and dashboard development

  • Minimum 5 years of experience in cybersecurity, endpoint security, vulnerability management, or security engineering.

  • Hands-on experience administering application control and privilege management solutions.

  • Extensive experience managing enterprise vulnerability management programs.

  • Experience working with ServiceNow Vulnerability Response.

  • Experience using leading vulnerability management platforms such as:

  • Rapid7

  • Tenable

  • Qualys

  • Experience working within large enterprise environments.

  • Strong understanding of risk-based vulnerability management and remediation prioritization.

Preferred Qualifications

  • Experience implementing Zero Trust security controls.

  • Experience with endpoint detection and response (EDR) platforms.

  • Familiarity with security frameworks including:

  • NIST Cybersecurity Framework

  • CIS Controls

  • ISO 27001

  • NCSC Cyber Assessment Framework

  • Cyber Essentials Plus

  • Defence Cyber Certification, Levels 0-3

  • ACSC Essential Eight

  • Experience with cloud security and hybrid infrastructure environments.

  • Experience leading vulnerability remediation programs across multiple technology domains.

Preferred Certifications

  • CISSP

  • GIAC Security Certifications

  • CompTIA Security* Certified Information Security Manager (CISM)

  • ServiceNow Certified Implementation Specialist

  • Tenable Certified Professional

  • Qualys Certified Specialist

  • Microsoft Security Certifications

#LI-MB5

Jacobs is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, religion, creed, color, national origin, ancestry, sex (including pregnancy, childbirth, breastfeeding, or medical conditions related to pregnancy, childbirth, or breastfeeding), age, medical condition, marital or domestic partner status, sexual orientation, gender, gender identity, gender expression and transgender status, mental disability or physical disability, genetic information, military or veteran status, citizenship, low-income status or any other status or characteristic protected by applicable law. Learn more about your rights under Federal EEO laws and supplemental language.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Endpoint Security & Exposure Engineer (Cyber Security) in San Francisco, CA vacancy
  • $175k - $220k

     ...for a highly technical Senior Security Engineer who is passionate about...  ...across modern SaaS, cloud, endpoint, and analytics environments....  ...unauthorized access, sharing, or exposure of sensitive information....  ...Masters in Computer Science, Cyber Security, or similar fields.... 
    Suggested
    Full time
    Work at office

    Sigma Computing

    San Francisco, CA
    3 days ago
  •  ...Senior Security Engineer, Enterprise Security CoreWeave is The Essential Cloud for AI™. Built...  ...our people work every day—identity, endpoints, networks, and SaaS—so the company can...  ...into identity and access decisions. ~ Exposure to SIEM/detection ecosystems (e.g.,... 
    Suggested
    For contractors
    Remote work

    CoreWeave

    San Francisco, CA
    3 days ago
  • $170k - $205k

     ...Crusoe.About the Role:Crusoe is seeking a Security Engineer to join the Security Engineering team...  ...for implementing security defaults and endpoint visibility. This is a strategic,...  ...(ACSP) or equivalent MDM certification.Exposure to SIEM tooling and endpoint log pipelines... 
    Suggested
    Temporary work

    Crusoe

    San Francisco, CA
    4 days ago
  • $200k - $220k

     ...they rely on every day.We are looking for a hands-on Corporate Security Engineer to own and improve the technical controls that keep our...  ...building scalable controls and automation across identity, endpoints, SaaS, and workforce infrastructure, not a traditional IT support... 
    Suggested
    Work at office
    Local area

    Notion Labs

    San Francisco, CA
    10 hours ago
  • $234.4k - $385k

     ...artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are...  ...engaging a robust security culture. About the RoleAs a Security Engineer, Application Security you will be responsible for identifying and... 
    Suggested
    Work at office
    Remote work
    Relocation package
    Flexible hours

    OpenAI

    San Francisco, CA
    4 days ago
  •  ...Corporate Security Engineer Millions of people rely on Notion to do their most important work. Protecting that trust starts with protecting...  ...building scalable controls and automation across identity, endpoints, SaaS, and workforce infrastructure, not a traditional IT... 
    Local area

    Notion, LLC

    San Francisco, CA
    1 day ago
  • $155.6k - $306.8k

     ...Help clients reduce cyber risk by leading forward deployed engineering work focused on patching...  ...remediation, and continuous exposure reduction. As part of...  ..., middleware, endpoints, and applicationsDriving...  ...risk through stronger security, greater visibility, and... 
    Local area

    Deloitte

    San Francisco, CA
    4 days ago
  • $320k - $405k

     ...growing group of committed researchers, engineers, policy experts, and business leaders working...  ...AI systems.About the role Corporate Security protects the environment Anthropic's...  ...contributor role. Key responsibilities Drive endpoint hardening across macOS, Windows, Linux,... 
    Work at office
    Visa sponsorship
    Flexible hours

    Anthropic

    San Francisco, CA
    3 days ago
  • $117.2k - $176.7k

     ...the future of Salesforce.The ExperienceThe Product Security team is seeking a Mobile Security Engineer who will own the security posture of Salesforce's mobile...  ...security research, Common Vulnerabilities and Exposures (CVE) disclosures, or contributions to open-source mobile... 
    Full time

    Salesforce

    San Francisco, CA
    10 hours ago
  • $210k - $230k

     ...interview process.About the Role:We're looking for a Senior Staff Security Engineer to lead Gusto's edge and network security strategy, owning...  ...defense, container security, secrets management, and endpoint protection across the company. The team runs a modern stack... 
    Full time
    Work at office
    Local area
    Remote work
    2 days per week
    3 days per week

    Gusto

    San Francisco, CA
    2 days ago
  • $175k - $220k

     ...looking for a highly technical Senior Security Engineer who thrives on building security capabilities...  ...-as-code across cloud, identity, endpoint, SaaS, and application environments.Design...  ...or Masters in Computer Science, Cyber Security or similar roles.Strong software... 
    Full time
    Work at office

    Sigma Computing

    San Francisco, CA
    3 days ago
  •  ...in Continuous Threat Exposure Management (CTEM). The...  ...largest community of security researchers to continuously...  ...reduction of cyber risk for enterprises....  ...accountability.Senior Security Engineer, Detection and...  ...infrastructure, SaaS applications, endpoints, and identity systems,... 
    Apprenticeship
    Local area
    Remote work
    Flexible hours
    Shift work

    HackerOne

    San Francisco, CA
    4 days ago
  • $237.6k - $297k

    We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the... 
    Full time

    Scale AI

    San Francisco, CA
    4 days ago
  • $146.3k - $257.7k

     ...scalers to join us on our journey to create a better future of work with AI. About the roleThis is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you'll be building the security foundations that protect the AI systems... 
    Full time
    Work at office
    Local area

    Writer

    San Francisco, CA
    4 days ago
  • $190k - $225k

     ...Senior Security Engineer We are looking for a highly technical Senior Security Engineer who...  ...operations. Integrate cloud, identity, endpoint, SaaS, and security platforms through...  ...Bachelor or Masters in Computer Science, Cyber Security or similar roles. ~ Strong... 

    WinMax

    San Francisco, CA
    2 days ago
  • $174.5k - $240k

     ...ours.About the role:As a Senior Enterprise Security Engineer, you will help protect Faire's corporate environment across endpoint, network, identity, and SaaS, and play a key...  ...with AI quickly without creating new exposure, partnering with Engineering rather than duplicating... 
    Work experience placement
    Work at office
    Local area
    Remote work
    Monday to Friday
    Flexible hours
    3 days per week

    Faire

    San Francisco, CA
    4 days ago
  •  ...breaking speeds.About You and The Role Product security at Zipline protects systems that...  ...service outages, unsafe drone behavior, data exposure of patient/partner data, or regulatory...  ..., and field-ops teams. Expect hands-on engineering work, prioritized ownership of specific... 
    Local area

    Zipline

    South San Francisco, CA
    10 hours ago
  • $230k - $385k

     ...that artificial general intelligence benefits all of humanity.The Security team protects OpenAI’s technology, people, and products. We are...  ...security culture.About the RoleOpenAI is seeking a Security Engineer to join our Infrastructure Security (InfraSec) team. InfraSec protects... 
    Work at office
    Local area
    Flexible hours

    OpenAI

    San Francisco, CA
    10 hours ago
  • $82.6k - $162.8k

    Position Summary Join our Deloitte Cyber team to deliver powerful solutions to...  ...with confidence, and proactively manage to secure success. Identity security market is undergoing...  ...12/31/2026.Work you'll doAs a Security Engineer II on the Deloitte Cyber Identity &... 
    Local area
    Visa sponsorship

    Deloitte

    San Francisco, CA
    10 hours ago
  • $129.5k - $186.1k

     ...to join our Resilience team within the Cyber Security organization.This is not a traditional...  ...primary consultant to multiple product engineering teams and enterprise groups across UKG....  ...application architectures.Broad HA Domain Exposure: Familiarity assessing or designing... 

    Ultimate Software

    San Francisco, CA
    3 days ago
  • $145k - $210k

     ...Senior Cyber Security Engineer Cooley is seeking a Senior Cyber Security Engineer to join the Security...  ...help desk tickets to ensure minimum exposure of Firm assets under the direction of...  ...Detection and Prevention Systems ~ Endpoint Detection and Response (EDR) and... 
    Full time
    Temporary work
    Work at office
    Flexible hours
    Weekend work

    Cooley

    San Francisco, CA
    3 days ago
  • $347k

     ...that artificial general intelligence benefits all of humanity.The Security team protects OpenAI’s technology, people, and products. We are...  ...culture.About the RoleOpenAI is seeking a Principal Security Engineer to join our Infrastructure Security (InfraSec) team. InfraSec... 
    Work at office
    Local area
    Flexible hours

    OpenAI

    San Francisco, CA
    2 days ago
  •  ...Responsibilities Roles DescriptionThe Principal Enterprise Security Engineer serves as the senior technical authority and strategic...  ...to end enterprise security architecture blueprint, covering endpoint, identity, network, and data.Lead the architectural reviews... 
    Work at office
    Local area

    Atlassian

    San Francisco, CA
    4 days ago
  •  ...13, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. Security Engineering is the engineering function inside the Plaid security org that focuses on developing the industry-leading security systems and... 
    Full time
    Work experience placement
    Local area

    Plaid Inc.

    San Francisco, CA
    10 hours ago
  •  ...career, join us. About the team The Airwallex Information Security Team is a high calibre and highly proactive team that work...  ...across our infrastructure, app security, Corporate IT and broader engineering functions. What you’ll do As a Senior Software... 
    Full time
    Worldwide

    Airwallex

    San Francisco, CA
    10 hours ago
  • $110k - $160k

     ...AnalystII to join our growing Security Operations team and...  ...against evolving cyber threats. This role will...  ...enterprise systems, endpoints, cloud infrastructure,...  ...with senior security engineers, IT, and infrastructure...  ...MSSPs) Experience or exposure to enterprise security... 
    Contract work
    Work experience placement
    Casual work
    Relocation package

    CHAOS Industries

    San Francisco, CA
    2 days ago
  • $155.6k - $306.8k

    Position Summary As an Engineering Manager in Deloitte Cyber’s Digital Trust & Privacy practice, you will help clients solve complex identity...  ...(financial services, healthcare, public sector) and exposure to associated compliance regimes (SOX, PCI DSS, FFIEC,... 
    Local area
    Visa sponsorship

    Deloitte

    San Francisco, CA
    2 days ago
  •  ...organizations worldwide from increasingly sophisticated cyber and AI-driven threats, securing their AI transformation. Our prevention-first...  ...Job Description We're looking for an AI Security Engineer to join our Red Team and help us push the boundaries of... 
    Worldwide

    Check Point Software Technologies

    San Francisco, CA
    19 days ago
  •  ...advancing the state of AI while maintaining the highest standards of safety, security, and integrity in every aspect of our work. About the Team The Defensive Security Agent Engineering team plays a critical role in safeguarding OpenAI’s infrastructure, systems,... 
    Full time
    Work at office
    Relocation package
    3 days per week

    OpenAI

    San Francisco, CA
    10 hours ago
  • $122.4k - $228k

     ...professional for a Senior Cloud, AI & Data Security Engineer role who wants to design and...  ...to continuously monitor sensitive data exposure across cloud environments Establish...  ...training environments, and inference endpoints Knowledge of Generative AI security... 
    Contract work
    Part time
    Local area

    BMO Financial Group

    San Francisco, CA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Endpoint Security & Exposure Engineer (Cyber Security). Be the first to apply!