Endpoint Security Engineer
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 1d ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 60d ago
The date the source published, not the day we noticed it (2026-07-16). Last seen at its source 2h ago.
Is it remote?
Remote, Europe
That is the location the employer filed this posting under. Quoted as written — we do not re-word the source's own location.
Who may apply?
Europe
The description states no restriction of its own. This is the source's own tag.
Pay not stated
Similar roles pay €75k–114.5k/yr
Middle 50% of 80 listings that do state pay — Engineering · all levels · Europe · EUR/year. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
greenhouse employer's own board first seen 38d ago · last seen 2h ago
The listing
You will ensure reliable endpoint visibility, strong security baselines, effective telemetry collection, and containment capabilities across Windows, Linux, and macOS environments. You will work closely with IT, Cyber Defense, IAM, and Compliance teams to maintain measurable endpoint protection coverage and reduce security risks.
- Deploy, operate, and tune endpoint security controls (EDR/XDR, EPP, MDM) across corporate endpoints, servers, and critical infrastructure
- Monitor endpoint telemetry health, investigate security events, and identify potential security incidents
- Implement and maintain OS security baselines and hardening standards across Windows, Linux, and macOS environments based on CIS Benchmarks, DISA STIG, and internal policies
- Support vulnerability remediation, patching activities, and endpoint security improvements in collaboration with IT and infrastructure teams
- Configure and maintain endpoint protection capabilities, including file integrity monitoring and endpoint isolation readiness for critical systems
- Support containment and response activities for compromised or non-compliant devices together with SOC and Cyber Defense teams
- Assist with tracking endpoint security gaps, remediation actions, and configuration improvements
- Document endpoint security configurations, operational procedures, and investigation findings
Requirements
- 3+ years of hands-on experience in Endpoint Security, Endpoint Protection, Infrastructure Security, System Security, or a similar cybersecurity role
- Higher education in Computer Science, Information Security, Software Engineering, or a related technical field is preferred
- Practical experience securing both desktop endpoints and server workloads in enterprise environments
- Experience supporting environments with 1,000+ managed endpoints is highly preferred
- Strong hands-on experience with EDR/XDR, Endpoint Protection Platforms (EPP), and Mobile Device Management (MDM) solutions
- Deep understanding of Windows, Linux, and macOS architecture, services, processes, logging, and security mechanisms
- Experience implementing OS hardening based on CIS Benchmarks, DISA STIG, or similar security standards
- Knowledge of operating system access control models, RBAC, and least-privilege principles
- Experience with native operating system security features such as Microsoft Defender, Attack Surface Reduction (ASR), BitLocker, SELinux, AppArmor, Gatekeeper, System Integrity Protection (SIP), and FileVault
- Understanding of endpoint telemetry, file integrity monitoring, and endpoint isolation techniques
- Scripting skills for automation using PowerShell and Python
- English - Intermediate\Upper-Intermediate level
- Ukrainian - Fluent
We offer
- 20 paid vacation days per year
- 10 paid sick leave days per year
- Public holidays as per the company’s approved Public holiday list
- Medical budget
- Opportunity to work remotely
- Professional education budget
- Language learning budget
- Wellness budget (gym membership, sports gear and related expenses)
Role mission
Operate endpoint controls so devices produce reliable telemetry and can be contained when authorized.
Requirements hard skills
1. EDR/XDR, MDM, EPP strong hands-on knowledge on 1000+ fleets.
2. Strong knowledge of Windows, macOS and Linux operating systems (architecture, processes, services, file systems, logging).
3.OS hardening and security baselines (CIS Benchmarks, DISA STIG).
4.OS-level access control and privilege management (RBAC, least privilege)
5.Native OS security mechanisms (Windows Defender/ASR, BitLocker, SELinux/AppArmor, Gatekeeper/SIP, FileVault)
Requirements soft skills
1. Strong analytical and problem-solving skills.
2. Ability to prioritize and stay calm under pressure during security incidents.
3. attention to detail and a methodical approach to documentation.
4. Clear written and verbal communication for reporting to technical and non-technical stakeholders.
5. ownership and accountability for assigned systems and tasks.
6. adaptability and willingness to learn in a fast-changing threat landscape.
7. strong sense of confidentiality and integrity when handling sensitive data
Responsibilities
1. Deploy, operate and tune endpoint security controls (EDR/XDR, MDM) across managed devices.
2. Monitor endpoint telemetry health and investigate anomalies to identify potential security incidents.
3. Harden Windows, macOS and Linux operating systems in line with security baselines (CIS Benchmarks, DISA STIG) and internal policies.
4. Manage patch and vulnerability remediation across endpoint fleets in coordination with IT.
5. Contain and isolate compromised or non-compliant devices when authorized, working closely with the SOC/incident response team.
6. Work closely with IAM team to review OS-level access controls and privilege configurations to reduce attack surface.
7. Document endpoint security processes, configurations and incident findings.
8. Collaborate with IT, SOC and compliance teams to align endpoint controls with organizational security requirements.