Role: Endpoint Protection Lead
Location: Milpitas, CA
Employment Type: Contract to hire
Top skills:
- USB blocking
- Crowdstrike
- Linux and Windows
We are seeking an Endpoint Protection Lead with deep, hands-on expertise in endpoint data egress control specifically the ability to block and govern removable media and USB device access and to restrict access to unsanctioned external cloud storage providers. This role will design, deploy, and operationalize device control policies across Customer's endpoint fleet, including USB and removable storage blocking, read-only and encryption-based exceptions, device allow-listing, and a defensible exception workflow for legitimate business needs. Equally important is the ability to control access to unapproved cloud storage and file-sharing services through a combination of endpoint policy, browser and network controls, and CASB or SSE tooling, working in close coordination with the Data Protection team so that endpoint enforcement and Cyera-based data discovery and DLP policy reinforce one another rather than operate in isolation. The ideal candidate has strong practical experience with Microsoft Defender for Endpoint and Microsoft Purview device control, CrowdStrike, and Microsoft 365 security configurations, understands how sensitive intellectual property, design, and manufacturing data moves through a global enterprise, and can balance restrictive controls against engineering and manufacturing productivity. This position will own policy standards, phased rollout and enforcement ramp, monitoring and reporting on blocked events and policy violations, and continuous tuning to close egress gaps while minimizing business disruption.