Information Security Engineer II - End Point
Listed on 2026-07-01
-
IT/Tech
Cybersecurity, Network Security, Information Security
Information Security Engineer II - End Point
The Information Security Engineer II is responsible for the day-to-day operations, maintenance, and continuous improvement of the organization's endpoint security program. This role centers on the administration of Extended Detection and Response (EDR) technologies, primarily Crowd Strike Falcon, encompassing agent lifecycle management, policy configuration, alert response, threat hunting, and platform reporting. The engineer will manage endpoint firewall policies within Crowd Strike and administer Data Loss Prevention (DLP) solutions including Digital Guardian and/or Microsoft Purview to protect sensitive organizational data.
Additionally, this role supports the development and maintenance of secure endpoint baseline configurations aligned to CIS Level 1 Benchmarks. The engineer will provide backup support for vulnerability management functions and will have exposure to complementary security technologies including Palo Alto Next-Generation Firewalls, Forescout Counter Act (Network Access Control), and Mimecast email security. This position operates within a collaborative security team and contributes to the broader corporate security strategy, supporting compliance requirements such as FFIEC, PCI DSS, GDPR, and SOX.
Major duties and responsibilities include administering, configuring, and maintaining the Crowd Strike Falcon platform; monitoring and triaging EDR alerts; conducting proactive threat hunting; staying current with Crowd Strike product updates; managing endpoint firewall policies; implementing, operating, and maintaining Data Loss Prevention (DLP) solutions; contributing to the development and maintenance of secure endpoint baseline configurations; supporting vulnerability management operations; assisting with Palo Alto Networks Next-Generation Firewall (NGFW) operations;
supporting Forescout Counter Act operations; assisting with Mimecast email security administration; documenting security processes, procedures, configurations, alert triage activities, and investigation findings; participating in change management processes; collaborating with outsourced Security Operations Center (SOC) analysts, IT teams, and third-party vendors; supporting compliance with applicable regulatory frameworks; producing operational reports and metrics; researching and evaluating emerging security technologies, threat trends, and industry best practices;
and participating in on-call rotation for security incident response.
Employee specifications include a bachelor's degree in Cybersecurity, Computer Science, Information Assurance, Management Information Systems, or a related field; 3–5 years of experience in cybersecurity engineering or related IT/security operations roles, with demonstrated hands-on experience in endpoint security; and preferred certifications such as Crowd Strike Certified Falcon Administrator (CCFA), CompTIA CySA+, CompTIA Security+, CEH, GCIA, GCIH, or equivalent industry certification. Knowledge and/or hands-on experience in operating Crowd Strike Falcon or equivalent EDR platform, endpoint DLP tools, endpoint firewall management concepts, endpoint hardening standards, vulnerability management tools, network access control concepts and technologies, Next-Generation Firewall platforms, email security gateways, threat hunting methodologies, behavioral analytics, common attack techniques, malware analysis and digital forensics concepts, Windows, macOS, and Linux operating systems from a security and endpoint management perspective, SIEM platforms, and basic scripting ability are also required.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).