End-Point Security Architect
Location: Remote
Role Type: Contract
The Endpoint Security Architect serves as the technical authority for enterprise endpoint security strategy, architecture, and modernization initiatives across a highly regulated critical infrastructure environment. This role is responsible for developing endpoint security standards, defining future-state architectures, and leading endpoint security initiatives supporting corporate IT, remote workforce, cloud, and operational business environments.
The architect will partner closely with Cybersecurity, Infrastructure, Identity & Access Management, Network Security, Cloud Engineering, and Operations teams to design secure endpoint solutions that align with Zero Trust principles, regulatory requirements, and enterprise security objectives.
Key Responsibilities
Endpoint Security Architecture
- Develop, maintain, and govern enterprise endpoint security architectures and roadmaps.
- Define security standards, reference architectures, design patterns, and implementation guidance for endpoint technologies.
- Lead architecture reviews and ensure endpoint solutions align with enterprise security standards.
- Design endpoint security controls supporting Windows, macOS, mobile devices, and remote users.
- Support Zero Trust security initiatives and endpoint access strategies.
Endpoint Protection & Detection
- Design and govern endpoint protection platforms including:
- Microsoft Defender for Endpoint
- CrowdStrike Falcon
- SentinelOne
- Tanium
- Carbon Black
- Similar EDR/XDR solutions
- Define endpoint telemetry, logging, threat detection, and response requirements.
- Collaborate with Security Operations teams to improve endpoint visibility and threat detection coverage.
Endpoint Management & Modern Workplace
- Architect modern endpoint management solutions utilizing:
- Microsoft Intune
- Microsoft Autopilot
- Microsoft Configuration Manager (MECM/SCCM)
- Workspace ONE
- Jamf
- Develop endpoint compliance, configuration baseline, and device lifecycle management strategies.
- Support BYOD, mobile device management (MDM), and unified endpoint management (UEM) initiatives.
Identity & Zero Trust
- Partner with IAM teams to implement:
- Conditional Access
- Device Trust
- Multi-Factor Authentication (MFA)
- Least Privilege Access
- Privileged Access Management
- Align endpoint security architecture with NIST 800-207 Zero Trust principles.
Risk, Governance & Compliance
- Conduct endpoint security architecture reviews and risk assessments.
- Participate in architecture governance processes and technical design reviews.
- Develop security standards, configuration baselines, and hardening requirements.
- Support compliance initiatives aligned to:
- NERC-CIP
- NIST Cybersecurity Framework
- NIST 800-53
- CIS Controls
- Regulatory and audit requirements
Technical Leadership
- Provide technical leadership and mentorship to engineers and architects.
- Evaluate emerging endpoint security technologies and recommend future-state solutions.
- Influence architecture decisions across multiple technology teams and business units.
Required Qualifications
- 8+ years of experience in Endpoint Security, Security Architecture, Endpoint Engineering, or related disciplines.
- Experience designing and securing large enterprise endpoint environments.
- Deep knowledge of endpoint security concepts including:
- EDR/XDR
- Endpoint hardening
- Device compliance
- Privileged access controls
- Endpoint telemetry
- Experience with Microsoft Intune and Microsoft Defender for Endpoint.
- Experience with endpoint management and deployment platforms.
- Experience implementing Zero Trust security controls.
- Strong understanding of Windows endpoint security architecture.
- Experience developing enterprise security standards and technical documentation.
- Knowledge of NIST 800-53, NIST 800-207, CIS Controls, and defense-in-depth principles.
Preferred Qualifications
- Experience supporting highly regulated environments, critical infrastructure, energy, utility, nuclear, or government organizations.
- Experience with:
- CrowdStrike Falcon
- Tanium
- SentinelOne
- Jamf
- Workspace ONE
- ServiceNow
- Experience with cloud security integration across Microsoft 365, Azure, and AWS.
- Experience conducting threat modeling and endpoint risk assessments.
- Experience leading enterprise endpoint modernization initiatives.
Preferred Certifications
- CISSP
- Microsoft Certified: Endpoint Administrator Associate
- Microsoft Certified: Azure Security Engineer Associate
- Microsoft Certified: Security Operations Analyst Associate
- CrowdStrike Certified Falcon Administrator
- Tanium Certified Professional
- GIAC (GSEC, GCIH, GCED, GCIA)
- Microsoft Defender for Endpoint Certifications
Regards,
Ayush Sharma Sr. US Technical Recruiter
| Ext:149
| G-talk:
