Job Description Everforth ECS is seeking an
Endpoint Engineer III to work
remotely .
At ECS Federal, we're driven by a commitment to excellence and innovation in solving complex challenges. As a premier provider of advanced technology solutions and services, our mission is to secure and optimize the most critical commercial, government, defense, and intelligence projects across the country. Our team is composed of dynamic professionals who thrive in a collaborative and empowering environment, where our team members leverage the latest technologies and insights to make a real-world impact. Join us and be part of a forward-thinking organization that values your expertise and supports your professional growth.
The Endpoint Engineer III is responsible for supporting the engineering, implementation, administration, and optimization of enterprise endpoint security and data protection technologies. This role works closely with the Security Engineering Manager, security operations teams, enterprise IT teams, infrastructure teams, and platform owners to ensure endpoint security controls are effectively deployed, maintained, and integrated across client environments. The Endpoint Engineer III serves as a senior technical resource for endpoint security along with supporting the Data Loss Prevention (DLP) program, providing advanced troubleshooting, platform administration, policy management, integration support, and technical guidance. The engineer will contribute to the continuous improvement of endpoint protection, data protection, security automation, and operational processes that strengthen the organization's overall cybersecurity posture.
Responsibilities - Endpoint Security Platform Administration: Administer, maintain, configure, and optimize enterprise endpoint security technologies including EDR/EPP, endpoint security agents, device controls, host-based security controls, and related technologies.
- DLP Platform Administration: Configure, administer, maintain, and optimize enterprise Data Loss Prevention and data protection platforms across endpoint, cloud, email, web, and other supported channels.
- Endpoint Security Policy Management: Develop, implement, maintain, and tune endpoint and data protection security policies and configurations to provide appropriate protection while minimizing unnecessary operational impact.
- Data Protection Engineering: Support the implementation and operation of data classification, labeling, encryption, device control, and other technical controls designed to protect sensitive organizational information.
- Platform Deployment & Lifecycle Management: Support enterprise deployment, upgrades, migrations, configuration changes, agent/sensor health, and lifecycle management of endpoint security and DLP technologies.
- Platform Integration: Collaborate with enterprise IT, cloud, identity, network, infrastructure, and security teams to integrate endpoint security and data protection technologies with enterprise systems and services.
- Advanced Troubleshooting: Serve as a senior escalation point for complex endpoint security and DLP platform issues, including agent/sensor problems, policy conflicts, performance issues, integration failures, and unexpected control behavior.
- Security Investigation Support: Provide technical expertise during security investigations involving endpoint activity, potential data exposure, DLP policy violations, malware, suspicious activity, and other endpoint security events.
- Policy Tuning & Optimization: Analyze endpoint and DLP platform activity to identify false positives, policy gaps, configuration issues, and opportunities to improve security effectiveness and user experience.
- Security Automation Support: Develop and maintain scripts, integrations, and automation workflows to improve endpoint security administration, platform management, data protection operations, reporting, and response activities.
- Operational Monitoring: Monitor the health, deployment status, reliability, and performance of security tool platforms, agents, sensors, policies, integrations, and supporting infrastructure.
- Technical Leadership: Provide technical guidance and mentorship to other engineers, assist with complex engineering initiatives, and contribute to technical decisions related to endpoint security.
- Technical Documentation: Develop and maintain engineering documentation, platform configurations, policy documentation, troubleshooting procedures, implementation guides, operational runbooks, and knowledge articles.
- Continuous Improvement: Identify opportunities to strengthen endpoint security and data protection coverage, improve platform reliability, optimize policies and configurations, increase automation, and improve engineering and operational workflows.
Education Requirements - Bachelor's degree in computer science, information security, or a related field. Will consider experience in lieu of a degree.
Salary Range: $130,000-$160,000
General Description of Benefits
Required Skills - Experience: Minimum of 5-8 years of cybersecurity or security engineering experience supporting enterprise security operations environments.
- Endpoint Security Experience: Hands-on experience administering and troubleshooting enterprise endpoint security technologies such as EDR/EPP, endpoint security agents, host-based security controls, device control, and related technologies.
- Endpoint Security Platform Experience: Experience with enterprise endpoint security technologies such as Microsoft Defender for Endpoint, CrowdStrike Falcon, Trellix, or similar platforms.
- Data Protection Knowledge: Strong understanding of DLP concepts, sensitive data identification, data classification and labeling, encryption, device control, and protection of data at rest, in use, and in transit.
- DLP Policy Administration: Experience implementing, testing, troubleshooting, and tuning DLP policies and rules, including reducing false positives and evaluating the operational impact of data protection controls.
- Enterprise Security Knowledge: Strong understanding of enterprise endpoint environments, Windows operating systems, identity and access technologies, networking concepts, cloud services, and security architecture.
- Endpoint Troubleshooting: Demonstrated ability to troubleshoot complex endpoint security issues involving agents, operating systems, policies, applications, network connectivity, and security platform integrations.
- Security Automation: Experience using scripting or automation to support security engineering, platform administration, troubleshooting, or operational activities.
- Security Framework Knowledge: Familiarity with cybersecurity and data protection frameworks and standards such as NIST Cybersecurity Framework, CIS Critical Security Controls, and ISO 27001.
Other Requirements of the position include: - Able and willing to obtain a US Security Clearance.
- On-Call Support: Participates in on-call support to assist with security incident response, operational issues, and investigation activities to maintain continuous SOC coverage and response capabilities.
Desired Skills - Endpoint Security Platform Experience: Experience administering enterprise endpoint security platforms such as Microsoft Defender and Purview, CrowdStrike Falcon, Trellix, or similar technologies, including endpoint protection, policy management, device control, and related security capabilities.
- Enterprise DLP Experience: Experience supporting DLP implementations across multiple enforcement channels such as endpoint, email, web, cloud applications, and SaaS platforms with tools such as Netskope, Zscaler, Skyhigh, or similar technologies.
- Cloud & SaaS Security: Experience integrating endpoint and data protection technologies with cloud and SaaS environments.
- Scripting and Automation: Experience with scripting languages such as PowerShell or Python to support platform administration, automation, troubleshooting, and operational tasks.
- Technical Leadership: Experience mentoring engineers, leading technical troubleshooting efforts, coordinating platform upgrades or migrations, and providing technical recommendations.
- Excellent analytical and problem-solving skills, with the ability to investigate and resolve complex technical security issues.
- Strong communication skills, with the ability to collaborate effectively with technical teams, business stakeholders, and security leadership.
Physical Demands - While performing the duties of this job, the employee is regularly required to sit at a desk and use a computer for extended periods.
- The position is generally sedentary but may require walking or standing for brief periods of time.
- Employee may occasionally be required to move, carry, push, pull and/or lift objects up to 10 pounds.
Work Environment - Job is performed in an office place setting.
- The noise level in the work environment is generally very low with minimal background noise.
- Comfortable climate control and adequate lighting.
#EverforthECS1ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.
Everforth ECS is the federal segment of
Everforth , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.
Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.
We value:
- Attracting and developing top talent and high-performing teams
- Fostering a culture that is engaging, accountable, and mission-driven
Meet the challenge. Make a difference with Everforth ECS!