Senior Endpoint Security Engineer
Listed on 2026-01-02
-
IT/Tech
Cybersecurity, Systems Engineer -
Engineering
Cybersecurity, Systems Engineer
Truveta is the world’s first health provider‑led data platform with a vision of Saving Lives with Data. Our mission is to enable researchers to find cures faster, empower every clinician to be an expert, and help families make the most informed decisions about their care. Achieving Truveta’s ambitious vision requires an incredible team of talented and inspired people with a special combination of health, software, and big data experience who share our company values.
WhoWe Need
Truveta is rapidly building a talented and diverse team to tackle complex health and technical challenges. We seek candidates inspired by the opportunity to securely apply data in the development of real‑world health solutions. Beyond core capabilities, we value problem solvers, passionate and collaborative teammates, and individuals willing to roll up their sleeves while making a difference. We do things the right way.
Our commitment to security and compliance assurance cannot be stressed enough. This position is critical to ensuring we are successful.
The Endpoint Security Engineer will design and support solutions that advance the company’s Digital Workplace strategy. They will work with cutting‑edge technologies that modernize endpoint management by leveraging the cloud to quickly deliver end‑user improvements.
Responsibilities- Device Management: Define, implement, and maintain endpoint hardening baselines for Windows, macOS, and Linux systems using MDM solutions such as Microsoft Intune and JAMF.
- Policy & Hardening: Develop and enforce security policies, standards, and procedures for all endpoint devices. Implement system hardening configurations based on industry best practices.
- Deploy & Manage Security Tools: Implement, configure, and maintain endpoint security solutions, including Endpoint Detection and Response (EDR), Extended Detection and Response (XDR), antivirus/anti‑malware software, and host‑based firewalls.
- Incident Response: Collaborate with IT and Security teams to respond to endpoint‑related incidents. Triage, remediate, and contain security incidents and threats on endpoints. Perform forensic analysis when necessary.
- Vulnerability Management: Manage the endpoint vulnerability lifecycle, from discovery and assessment to remediation, using scanning tools and patch management systems.
- Patch Management: Design and oversee the deployment of updates and security patches for operating systems and applications.
- Automation & Scripting: Develop scripts and automation (e.g., using Python, Power Shell) to streamline security operations, automate repetitive tasks, and improve response times.
- AI Protection: Secure endpoints used for AI development, including devices accessing model weights, training data, and production inference systems. Implement guardrails on AI tool usage (e.g., prompt injection prevention in local LLM dev tools, restricted plugins/add‑ons).
- Data Loss Prevention: Enforce data loss prevention (DLP) and encryption policies on devices handling sensitive AI training datasets, including PHI/PII and proprietary corporate data.
- On‑call: Participate in the on‑call rotation.
- On‑site: This position requires daily onsite work at Truveta office in Bellevue, WA.
- Experience: 5+ years of hands‑on experience in endpoint security, cybersecurity engineering, or a similar role.
- Technical Proficiency: Deep understanding of modern operating systems (Windows, macOS) and their architecture, configuration, and deployment in a large enterprise environment.
- Cloud
Experience:
Hands‑on experience with Azure Cloud PC, VM, Azure Firewall, and Azure Networking. - MDM Expertise: Hands‑on experience managing Microsoft Intune and JAMF, including device enrollment, OS upgrade/patch, configuration, and profile management.
- Policy Management: Define and assign compliance/security policies to ensure corporate devices meet organizational security standards.
- Application Management: Hands‑on experience with application control, deployment, patching, and upgrade.
- EPM: Proven experience with industry‑leading EPM platforms such as Cyber Ark and Beyond Trust to control privileged access and provide advanced threat…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).