Core4ce is a data-driven national security partner based in Arlington, Virginia, focused on advancing research and development, delivering innovative technology solutions, and prot
Endpoint Security Engineer
Location
United States
Posted
40 days ago
Salary
$120K - $130K / year
Seniority
Mid Level
Job Description
Endpoint Security Engineer
Core4ce
Role Description This role is a hands-on Windows Endpoint Security Specialist supporting a Cisco ISE team, focused on endpoint compliance, posture validation, and automated remediation. - Develop, test, and maintain advanced PowerShell scripts to automate endpoint compliance validation, data collection, and reporting aligned with security and DISA STIG requirements. - Design and implement automated remediation scripts to restore non-compliant endpoints to required baselines, including STIG configurations and endpoint security agent health. - Deploy and manage remediation solutions through Cisco Secure Client to support automated compliance enforcement. - Collaborate with Cisco ISE engineers to implement, optimize, and troubleshoot posture assessment workflows and NAC policy enforcement. - Investigate and resolve endpoint-side issues impacting network access compliance and client provisioning. - Correlate vulnerability scan results with endpoint configuration gaps to drive remediation efforts. - Validate and monitor patch management systems (WSUS, SCCM, Intune) to ensure endpoint update compliance. - Support endpoint certificate management and PKI-related requirements as needed. - This position is designed to be flexible, with responsibilities evolving to meet business needs and enable individual growth. Qualifications - Must be able to obtain Secret security clearance. - Advanced PowerShell scripting for automated compliance checks (registry, services, file permissions). - PowerShell scripting for automated remediation of non-compliant endpoint configurations and STIG settings. - Ability to create scripts for data gathering and compliance status reporting. - Deep knowledge of Windows endpoint internals and endpoint security tooling. - Strong EPP/EDR experience, including validating agent install status, service health, versioning, and signature/definition updates. - Experience configuring and auditing host-based firewalls (Windows Defender Firewall). - Understanding of data-at-rest encryption and verification methods (e.g., BitLocker). - Familiarity with application whitelisting/application control concepts and enforcement. - Ability to interpret vulnerability scan results and correlate them with endpoint configuration and STIG findings. - Practical experience auditing and implementing DISA STIG requirements for Windows endpoints. - Proficiency with Cisco ISE posture assessment and policy configuration for endpoint compliance. - Ability to integrate endpoints with ISE for posture/NAC and troubleshoot posture/client provisioning issues. - Understanding of patch management processes and validating patching agent health (WSUS, SCCM, Intune). - Working knowledge of PKI/certificate management on endpoints, including trusted root certificates. Preferred Qualifications - B.A or B.S. in a degree such as Computer Science, Information Systems or Information Technology or 7 years related experience. - Experience working in a DoD healthcare IT environment. Benefits - 401(k) with 100% company match on the first 6% deferred, with immediate vesting. - Comprehensive medical, dental, and vision coverage—employee portion paid 100% by Core4ce. - Unlimited access to training and certifications, with no pre-set cap on eligible professional development. - Tuition assistance for job-related degrees and courses. - Paid parental leave, PTO that grows with tenure, and generous holiday schedules. - Got a big idea? At Core4ce, The Forge gives every employee the chance to propose bold innovations and help bring them to life with internal backing. - Join us to build a career that matters—supported by a company that invests in you.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
We are knowmad mood! Somos una compañía líder en transformación digital, en constante evolución y a la vanguardia de la tecnología. Nacimos para provocar un cambio real a través de la innovación y el desarrollo sostenible, con la misión de aportar valor a los clientes e impulsar nuestro talento. Formado por más de 3.000 personas creativas, digitales e innovadoras conectadas a un propósito y capaces de generar conexiones con personas de todo el mundo. Un equipo responsable, flexible y con alta capacidad de adaptación a las necesidades de nuestros clientes y del mercado, a la vez que proporciona valor, visión, creatividad, expertise, profesionalidad y pasión por la tecnología en cada proyecto. Los valores que marcan nuestro rumbo y nos guían hacia la excelencia son la colaboración, la innovación, el compromiso, la diversión y la confianza. ¿Qué es lo que valoramos? Experiencia profesional de más de 3 años en: Tecnologias: - Active Directory (AD), Azure Active Directory / Microsoft Entra ID. LDAP (OpenLDAP, RedHat Directory Services u otros). Servicios de Federación: ADFS SAML / OAuth2 / OpenID Connect - Plataformas IAM (Identity & Access Management): SailPoint IdentityIQ / IdentityNow, CyberArk (gestión de cuentas privilegiadas), Ping Identity, Okta, Forgerock, IBM Security Verify (antiguo ISIM / IGI) - Bases de Datos y Consultas Técnicas: SQL Server, Oracle, MySQL, PostgreSQL. Uso de SQL avanzado: - Monitorización, Logging y Trazabilidad: Splunk, ELK Stack (Elastic, Logstash, Kibana), Grafana / Prometheus, Azure Monitor / Log Analytics, Sentry, Datadog (menos común pero posible) ¿Cuáles serían tus funciones? · Liderazgo, coordinación, gestión y liderazgo de equipos pequeños. • Gestión de incidencias N2: resolución de incidencias técnicas no procedimentadas, con capacidad de análisis autónomo. • Análisis técnico: consultas SQL, revisión de logs, identificación de causas raíz. • Colaboración con N1: escalado eficiente y retroalimentación continua. • Gestión del conocimiento: documentación de soluciones y procedimientos emergentes. Además, valoraremos muy positivamente si tienes experiencia y/o conocimientos en: Automatización, Scripting y Herramientas de Línea de Comandos · PowerShell (fundamental en Identity), Bash, Python (para validaciones y automatizaciones en algunos clientes) · CLI de Azure o Microsoft Graph para consultas a directorios Herramientas de Gestión de Incidencias y DevOps · Jira, ServiceNow, GLPI, Remedy · Confluence (documentación) · Git / GitLab / GitHub (control de versiones de scripts o configuraciones) · Metodologías Agile / Kanban Y con nosotros podrás disfrutar de: ✅Contrato Indefinido ✅ 100% REMOTO ✅Formación interna y acceso a certificaciones ♻Consulta nuestro calendario aquí: https://www.knowmadmood.com/es/talento/formacion ✅Plan de retribución flexible (seguro médico, transporte, tickets guardería, tickets restaurante) ✅Embajador de nuestra marca, a través de nuestro plan amigo ¡Recomienda a tus amigos y llévate un extra! ✅¡Eventos, meetups, techdays, charlas...y mucho más! ✅ 26 días de descanso (22 días vacaciones, 2 días de libre disposición y 24 y 31 diciembre festivos por defecto) ✅ Horario: 8.30 a 18h ( flexible) L-J y V 8 a 15h e Intensiva de Verano Julio y Agosto de 8 a 15h Para estar al corriente de nuestras novedades síguenos aquí -> knowmad mood En knowmad mood nos comprometemos con la igualdad de oportunidades y el respeto a la diversidad. Aplicamos nuestro Plan de Igualdad y el principio de no discriminación en todos nuestros procesos de selección.
AI Security Engineer
CIVIECIVIE provides equal employment opportunity for all applicants and employees. All qualified applicants will be considered regardless of an individual’s race, color, sex, gender identity or expression, religion, age, national origin, citizenship, physical or mental disability, medical condition, family care status, marital status, domestic partner status, sexual orientation, military or veteran status, or any other basis protected by federal, state or local laws. If you cannot submit your application due to a disability, please email hr@civie.com; we will reasonably accommodate individuals with disabilities to the extent required by applicable law.
Role Description We're looking for an AI Security Engineer to help secure a modern platform that combines cloud infrastructure, large language models, and autonomous agents. You'll play a key role in designing and operating security controls across Azure environments, AI/LLM systems, and regulated data workflows. This is a hands-on role for someone who understands both traditional cloud security and emerging AI security risks, and can translate that into practical, scalable protections. - Implement security architecture across Azure (networking, identity, compute, storage) - Support developers in securing AI/LLM systems, including model access, prompt handling, data leakage prevention, and abuse mitigation - Maintain detection and response capabilities (SIEM, EDR, SOAR) - Lead threat modeling and risk assessments for new features, especially AI agents and APIs - Implement and enforce security controls for regulated environments - Manage identity and access controls (Azure AD / Entra ID, RBAC, least privilege) - Investigate and respond to security incidents - Partner with engineering to embed security into CI/CD pipelines and SDLC - Conduct security reviews of infrastructure-as-code, APIs, and application architecture - Drive compliance efforts (HIPAA, SOC 2, HITRUST, NIST and related frameworks) - Evaluate and integrate security tools across cloud, endpoint, and application layers - Work with technical teams on implementing patches and vulnerabilities management Qualifications - Minimum of 4 years’ experience in security engineering and cloud security - Strong hands-on experience with Microsoft Azure security services (Defender for Cloud, Sentinel, etc.) - Experience securing AI/ML systems or strong familiarity with AI/LLM security risks (prompt injection, data exfiltration, model abuse) - Deep understanding of identity and access management (IAM), networking, and secure architecture - Experience with SIEM/SOAR tools, EDR technologies and Vulnerability management Requirements - Experience working in HIPAA-regulated environments - Experience with infrastructure as code (Terraform, ARM, or similar) - Experience securing LLM-based products or agent frameworks - Familiarity with securing AI systems or adversarial testing - Knowledge of data security (DLP, encryption, tokenization) - Experience with container and Kubernetes security - Certifications such as CISSP, CCSP, Azure Security Engineer Associate, or similar - Experience in high-growth startups or fast-paced environments What We're Looking For - Practical, builder mindset — you can design and implement, not just advise - Ability to balance security with product velocity - Strong communication skills and ability to work cross-functionally - Curiosity about emerging AI threats and willingness to stay ahead of them Benefits - Paid vacation, sick time, and personal days - 11 company paid holidays - Quarterly UberEats voucher - Monthly Fringe benefits - Flexible work schedules - Education and professional development stipend - Health, dental, and vision benefits, with employer HSA contribution - Long-term, short-term, and life insurances - 401(k) with company match & profit sharing Salary Information The typical base salary range for this position is $130,000 - $160,000. Company Description CIVIE provides equal employment opportunity for all applicants and employees. All qualified applicants will be considered regardless of an individual’s race, color, sex, gender identity or expression, religion, age, national origin, citizenship, physical or mental disability, medical condition, family care status, marital status, domestic partner status, sexual orientation, military or veteran status, or any other basis protected by federal, state or local laws. If you cannot submit your application due to a disability, please email hr@civie.com; we will reasonably accommodate individuals with disabilities to the extent required by applicable law.
Principal Information Security Engineer
UnitedHealth GroupUnitedHealth Group is a healthcare and well-being company that’s dedicated to improving the health outcomes of millions around the world. We are comprised of
Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by diversity and inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health equity on a global scale. Join us to start Caring. Connecting. Growing together. You will enjoy the flexibility to telecommute* from anywhere within the U.S. as you take on some tough challenges. Primary Responsibilities: - Serve as the functional subject matter expert for TrendMicro Technology - Some on-call and irregular work hours may be required - Transition core entities from hardware/data centers to Optum supported technology in cloud - Develop perimeter security / architecture to protect cloud assets - Create infrastructure as code in support of new entities transition to cloud - Identify and implement workload optimization in AWS, Azure and GCP - Participate in incident response for supported cloud projects - Train and educate team members to become self-sufficient in public cloud - Participate in workload placement strategy sessions with other Optum Teams Leverage enterprise-approved AI tools to streamline workflows, automate tasks, and drive continuous improvement. You’ll be rewarded and recognized for your performance in an environment that will challenge you and give you clear directions on what it takes to succeed in your role as well as provide development for other roles you may be interested in. Required Qualifications: - Bachelor’s degree - 15 years of proven work experience as a cloud developer, architect or systems administrator - 3+ years of experience in cloud development, infrastructure as code and automation/deployment - 2+ years of experience with cloud deployments of TrendMicro - 2+ years of experience with cloud architecture and networking Preferred Qualifications: - Strong planning and problem-solving skills - Ability to troubleshoot in highly complex, technical situations within a matrixed organization *All Telecommuters will be required to adhere to UnitedHealth Group’s Telecommuter Policy. Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you’ll find a far-reaching choice of benefits and incentives. The salary for this role will range from $112,700 to $193,200 annually based on full-time employment. We comply with all minimum wage laws as applicable. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants. At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone–of every race, gender, sexuality, age, location, and income–deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups, and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes — an enterprise priority reflected in our mission. UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment. #RPO #GREEN
Cloud Security Engineer
ZensarAt Zensar, we’re “experience-led everything”. We are committed to conceptualizing, designing, engineering, marketing, and managing digital solutions and experiences for over 130 leading enterprises. We are a company driven by a bold purpose: Together, we shape experiences for better futures. Whether for our clients, our people, or the world around us, this belief powers everything we do. At the heart of our culture is ONE with Client - a set of four core values that reflect who we are and how we work: One Zensar, Nurturing, Empowering, and Client Focus. Part of the $4.8 billion RPG Group, we’re a community of 10,000+ innovators across 30+ global locations, including Milpitas, Seattle, Princeton, Cape Town, London, Zurich, Singapore, and Mexico City. We believe the best work happens when individuality is celebrated, growth is encouraged, and well-being is prioritized. We are an equal employment opportunity (EEO) and affirmative action employer, committed to creating an inclusive workplace. All qualified applicants will be considered without regard to race, creed, color, ancestry, religion, sex, national origin, citizenship, age, sexual orientation, gender identity, disability, marital status, family medical leave status, or protected veteran status.
Job Title: Cloud Security Engineer Location: Offshore, India Experience: 8-10 years Role Overview We are seeking a highly skilled Cloud Security Engineer to design, implement, and maintain robust security controls for AWS cloud environments. This role is critical in securing the migration of banking infrastructure from on-premises data centers to AWS, ensuring compliance with financial regulations, data protection standards, and industry best practices. The candidate must have deep expertise in AWS security services, cloud security posture management, and data protection strategies within highly regulated environments such as banking or financial services. Key Responsibilities Cloud Security Architecture & Migration - Implement and secure AWS architectures for migrating on-premises banking workloads. - Perform threat modeling and risk assessments for migration strategies (rehost, replatform, refactor). - Define secure landing zones using AWS best practices (multi-account strategy, segmentation). - Ensure secure connectivity (VPN, Direct Connect) between on-prem and AWS environments. - Collaborate with infrastructure and DevOps teams to embed security into migration pipelines. AWS Cloud Security Controls - Implement and manage AWS-native security services, including: - Identity & Access Management (IAM) with least privilege access - AWS Organizations and Service Control Policies (SCPs) - AWS Key Management Service (KMS) for encryption - AWS CloudTrail, CloudWatch, GuardDuty, Security Hub - Establish strong access control mechanisms (RBAC/ABAC, MFA enforcement). - Harden compute, storage, and network layers (EC2, S3, RDS, VPC). - Experience in banking/financial services or other regulated industries. - Strong understanding of: - Data protection and privacy regulations - Secure migration strategies and risks - Ensure adherence to banking and financial regulatory requirements. - Work closely with GRC teams to align cloud security with enterprise policies Data Security & Protection - Design and enforce data protection strategies for sensitive banking data: - Encryption at rest and in transit - Tokenization, masking, and anonymization - Implement secure key lifecycle management and HSM integration if required. - Define data classification and data loss prevention (DLP) controls. Cloud Security Posture Management (CSPM) - Implement and manage CSPM tools (e.g., AWS Security Hub, Prisma Cloud, Wiz, Orca). - Continuously monitor for misconfigurations, vulnerabilities, and compliance gaps. - Automate remediation using Infrastructure as Code (IaC) and security tooling. Automation - Integrate security into CI/CD pipelines (SAST, DAST, dependency scanning). - Define guardrails using Infrastructure as Code (Terraform, CloudFormation). - Automate security checks and policy enforcement (e.g., using AWS Config rules). - Enable secure secrets management (AWS Secrets Manager, Parameter Store). Required Skills & Experience - Strong hands-on experience with AWS cloud security services. - Deep understanding of: - IAM, VPC security, encryption, network segmentation - Cloud-native logging and monitoring - Experience with CSPM and vulnerability management tools. - Familiarity with hybrid cloud environments (on-prem + AWS). - Proficiency in scripting (Python, Bash) and IaC (Terraform/CloudFormation). - Strong analytical and problem-solving skills. - Ability to work cross-functionally with infrastructure, DevOps, and compliance teams. - Excellent communication skills for technical and non-technical stakeholders. Preferred Qualifications - AWS Certifications (e.g., AWS Certified Security – Specialty). - Experience with zero trust architecture and micro-segmentation. - Exposure to container and Kubernetes security (EKS). - Knowledge of SIEM/SOAR platforms. At Zensar, we’re “experience-led everything”. We are committed to conceptualizing, designing, engineering, marketing, and managing digital solutions and experiences for over 130 leading enterprises. We are a company driven by a bold purpose: Together, we shape experiences for better futures. Whether for our clients, our people, or the world around us, this belief powers everything we do. At the heart of our culture is ONE with Client - a set of four core values that reflect who we are and how we work: One Zensar, Nurturing, Empowering, and Client Focus. Part of the $4.8 billion RPG Group, we’re a community of 10,000+ innovators across 30+ global locations, including Milpitas, Seattle, Princeton, Cape Town, London, Zurich, Singapore, and Mexico City. Explore Life at Zensar and join us to Grow. Own. Achieve. Learn. to be the best version of yourself. We believe the best work happens when individuality is celebrated, growth is encouraged, and well-being is prioritized. We are an equal employment opportunity (EEO) and affirmative action employer, committed to creating an inclusive workplace. All qualified applicants will be considered without regard to race, creed, color, ancestry, religion, sex, national origin, citizenship, age, sexual orientation, gender identity, disability, marital status, family medical leave status, or protected veteran status.

