Stop applying to jobs that are already dead.
Every listing verified, aged honestly, expired when filled.

All listings

JustMarkets via Greenhouse

Endpoint & Security Platforms Engineer

Level not stated Europe
still open verified 5h ago posted 9h ago checked just now
Apply at job-boards.eu.greenhouse.io

This is the employer's own posting, not a copy on a job board.

What we know

Is it still open?

Confirmed still open

Last checked 5h ago — checked against the employer's own applicant tracking system, which is the company answering directly.

We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.

Check this listing's status as JSON

How old is it?

Posted 9h ago

The date the source published, not the day we noticed it (2026-09-15). Last seen at its source just now.

Is it remote?

The listing says yes

The location field doesn't say remote, so our assessment is based on the title or the description. Read the listing before applying.

Who may apply?

Europe

The description states no restriction of its own. This is the source's own tag.

Pay not stated

Similar roles pay €75k–114.4k/yr

Middle 50% of 81 listings that do state pay — Engineering · all levels · Europe · EUR/year. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.

Skills named in the ad

AnsibleBashKnowledge BaseLinuxPythonSIEMTroubleshooting

Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.

Carried by 1 source

The listing

We are looking for a hands-on Endpoint & Security Platforms Engineer to build and operate the controls that protect our employee devices and server workloads, working across the full lifecycle from deployment and hardening to troubleshooting, automation, and authorized containment.

This is a chance to influence technical decisions that improve protection without disrupting critical services, and to broaden your engineering skills through hands-on work with security platforms and automation. You will work closely with IT, Infrastructure, Cyber Defense, and data security colleagues to make protection reliable and effective without creating unnecessary friction for users or critical systems.

Responsibilities

  • Deploy and maintain EDR/XDR agents and endpoint protection policies across Windows, Linux, and macOS workstations and production servers, managing the full agent lifecycle: upgrades, policy tuning, exclusions, and controlled rollback
  • Resolve agent failures, telemetry gaps, policy conflicts, and performance issues. Coordinate deployments with IT, which provides first-line support, and take ownership of complex security cases
  • Implement risk-based OS hardening baselines together with application and infrastructure owners: test compatibility, prepare rollback steps, and deploy changes safely across production systems
  • Operate endpoint DLP controls: maintain agents, implement policies agreed with data security colleagues, and reduce unnecessary blocking without weakening protection
  • Maintain assigned security platforms (e.g. SIEM), including service health, access configuration, updates, storage, backups, and recovery
  • Monitor telemetry and control health, investigating stale agents, coverage gaps, and unmanaged systems, and drive fixes through automation and improved runbooks
  • Support Cyber Defense investigations with endpoint expertise and execute approved containment actions, escalating anything that could disrupt production
  • Automate recurring administration, validation, and reporting tasks using scripts and APIs, and maintain clear documentation for configurations and procedures

Requirements

  • 4+ years of hands-on experience in endpoint security, infrastructure security, system security, or a related security engineering role
  • Practical experience deploying and operating an enterprise EDR/XDR or endpoint protection platform across a mixed workstation and server environment
  • Strong Linux administration skills, plus the ability to support and troubleshoot protection on Windows workstations and servers using logs, services, permissions, network connections, and resource usage
  • Experience introducing security controls into production, including testing, controlled deployment, and rollback
  • Experience implementing OS hardening and working with native security controls
  • Understanding of access-control models, least privilege, endpoint telemetry, file-integrity monitoring, and host-isolation techniques
  • Ability to automate operational work using at least one scripting language such as Python, Bash, or PowerShell
  • Clear communication with technical colleagues and system owners, reliable documentation, and the ability to follow issues through to a verified result
  • Upper-Intermediate English
  • Fluent Ukrainian

Will be a plus

  • Experience administering a self-managed Elastic or another SIEM platform
  • Experience with endpoint DLP solutions or Microsoft Defender
  • macOS security and device-management tools such as Mosyle, ManageEngine, Ansible, or Puppet
  • Experience with CIS Benchmarks, DISA STIG, or native OS security controls (SELinux, AppArmor, FileVault, BitLocker, etc.)
  • Experience supporting a large, distributed fleet of endpoints or servers, ideally in fintech, trading, or another performance-critical environment
  • Technical education in Information Security, Computer Science, or a related field

We offer

  • 20 paid vacation days per year
  • 10 paid sick leave days per year
  • Public holidays according to the company’s approved holiday calendar
  • Medical budget
  • Remote work
  • Professional education budget
  • Language-learning budget
  • Wellness budget covering gym membership, sports equipment, and related expenses

Role mission

Operate endpoint controls so devices produce reliable telemetry and can be contained when authorized.

Requirements hard skills

1. EDR/XDR, MDM, EPP strong hands-on knowledge on 1000+ fleets.
2. Strong knowledge of Windows, macOS and Linux operating systems (architecture, processes, services, file systems, logging).
3.OS hardening and security baselines (CIS Benchmarks, DISA STIG).
4.OS-level access control and privilege management (RBAC, least privilege)
5.Native OS security mechanisms (Windows Defender/ASR, BitLocker, SELinux/AppArmor, Gatekeeper/SIP, FileVault)

Requirements soft skills

1. Strong analytical and problem-solving skills.
2. Ability to prioritize and stay calm under pressure during security incidents.
3. attention to detail and a methodical approach to documentation.
4. Clear written and verbal communication for reporting to technical and non-technical stakeholders.
5. ownership and accountability for assigned systems and tasks.
6. adaptability and willingness to learn in a fast-changing threat landscape.
7. strong sense of confidentiality and integrity when handling sensitive data

Responsibilities

1. Deploy, operate and tune endpoint security controls (EDR/XDR, MDM) across managed devices.
2. Monitor endpoint telemetry health and investigate anomalies to identify potential security incidents.
3. Harden Windows, macOS and Linux operating systems in line with security baselines (CIS Benchmarks, DISA STIG) and internal policies.
4. Manage patch and vulnerability remediation across endpoint fleets in coordination with IT.
5. Contain and isolate compromised or non-compliant devices when authorized, working closely with the SOC/incident response team.
6. Work closely with IAM team to review OS-level access controls and privilege configurations to reduce attack surface.
7. Document endpoint security processes, configurations and incident findings.
8. Collaborate with IT, SOC and compliance teams to align endpoint controls with organizational security requirements.

Apply at job-boards.eu.greenhouse.io