SOFTSWISS logo
SOFTSWISS

Winning combination of software products for iGaming

Endpoint Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 1,001-5,000H1B No SponsorCompany SiteLinkedIn

Location

Poland

Posted

26 days ago

Salary

0

Seniority

Senior

High School5 yrs expEnglishCloudJamfMacOSPythonSplunkGo

Job Description

Endpoint Security Engineer

SOFTSWISS

• Deploy, configure, and maintain(as L3) endpoint security solutions • Own the end-to-end vulnerability management process for endpoints • Develop and enforce endpoint hardening standards • Collaborate with the SOC and other security teams to correlate endpoint telemetry with network and cloud events for threat detection and response • Participate in the resolution of endpoint-related security incidents • Support and administer the existing Splunk deployment - ensuring stability, data source coverage, and platform reliability; drive its evolution as a Security BI platform through advanced dashboards, metrics, and reporting tailored to endpoint security and management needs

Job Requirements

  • 5+ years of hands-on experience in endpoint security engineering, with a focus on Windows and macOS environments
  • Deep expertise with modern EDR/XDR - deployment, policy configuration, agent management, and L3-level troubleshooting
  • Proven experience with vulnerability management processes end-to-end: asset discovery, prioritization, remediation tracking, and reporting
  • Experience administering Splunk including onboarding endpoint data sources, building searches and dashboards, and supporting SOC detection use cases
  • Hands-on experience with MDM solutions (Jamf, Intune, or equivalent) - including defining and enforcing security configuration requirements, compliance baselines, and policy rollout
  • Strong knowledge of endpoint hardening standards for Windows (CIS Benchmarks, STIG) and macOS (CIS macOS Benchmark, NIST guidelines)
  • Experience developing and maintaining hardening baselines, including scripted or policy-driven enforcement at scale
  • Ability to formalise security requirements into policies, standards, and control frameworks
  • Hands-on participation in incident response for endpoint-related security events: containment, investigation, root cause analysis
  • Solid understanding of attacker TTPs (MITRE ATT&CK framework) as applied to endpoint threat scenarios
  • Experience in development and automation (Python/Go)
  • Structured written and oral communication to ensure clarity
  • Upper Intermediate or higher English level
  • Nice to have: Experience with threat hunting on endpoint telemetry - proactively identifying anomalies beyond alert-driven workflows
  • Familiarity with compliance frameworks relevant to endpoint controls: PCI DSS, ISO 27001, or SOC 2 - particularly mapping hardening standards to control requirements
  • Exposure to SIEM/SOAR integration forwarding endpoint events, building detection rules, or contributing to automated response playbooks
  • Understanding of PKI and certificate management as applied to endpoints (device certificates, mTLS, MDM enrollment)
  • Experience with privileged access controls on endpoints - local admin management, PAM integration, or application allowlisting
  • Familiarity with DLP solutions and data protection policies at the endpoint level

Benefits

  • Full-time remote work opportunities and flexible working hours
  • Private insurance
  • Additional 1 Day Off per calendar year
  • Sports program compensation
  • Comprehensive Mental Health Programme
  • Free online English lessons with a native speaker
  • Generous referral program
  • Training, internal workshops, and participation in international professional conferences and corporate events

Related Categories

Related Job Pages

More Security Engineer Jobs

Cisco logo

Security Engineering Technical Leader – Control Plane, Hypershield

Cisco

We securely connect everything to make anything possible.

Full TimeRemoteTeam 10,001+Since 1984H1B Sponsor

• design and develop control plane software for security features used in smart switching platforms and distributed firewall systems • contribute to core feature development from design through implementation, with a focus on APIs, policy orchestration, and secure service integration • work closely with engineers across control plane, data plane, and platform teams to deliver scalable capabilities that support deployment, observability, and policy enforcement across distributed environments • build and maintain APIs used for policy configuration, deployment workflows, logging, and operational visibility • integrate third-party components and internal services into Cisco security platforms • contribute to architecture discussions, feature design, and technical execution for new security capabilities

California + 4 moreAll locations: California | Maine | Montana | North Dakota | Ohio
$183.8K - $263.6K / year
Job Closed
Booz Allen Hamilton logo

Data Security Engineer

Booz Allen Hamilton

Booz Allen Hamilton is an award-winning provider of strategic innovation, management consulting, technology, and engineering services. Founded in 1914, the comp

Data Security Engineer Location: Ford Island United States Job Description: Data Security Engineer The Opportunity: Architect, deploy, and configure data security solutions across various clients for DoD, IC, and civilian federal clients. Create new architectures to meet client requirements adhering to Zero Trust best practices and IC data header guidelines. Interface with key stakeholders, including agency personnel and internal delivery and engineering teams. Assist in building custom policy to ensure positive control of data across hybrid cloud environments. You Have: - 3+ years of experience designing, deploying, and configuring data security solutions - Experience with Data Security Posture Management (DSPM) tools such as Varonis or BigID - Experience with Data Loss Prevention (DLP) tools such as Forcepoint, Trellix, or Symantec - Experience with data labeling and tagging solutions such as Purview, Fortra, or Titus - Experience documenting and diagraming technical architectures - Secret clearance - HS diploma or GED Nice If You Have: - Experience working in federal, DoD, or IC agency environments - Experience managing and maintaining containerization solutions - Knowledge of federal information security policies, standards, procedures, directives, frameworks, federal security authorizations, assessment, and risk management processes for enterprise systems - Knowledge of Trusted Data Format (TDF) and Attribute Based Access Control (ABAC) - Knowledge of Virtru Data Security Platform (DSP) and Keycloak - Top Secret clearance - Bachelor's degree in an IT, Cybersecurity, or Engineering field Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Secret clearance is required. Compensation At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $86,900.00 to $198,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date. Identity Statement As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Candidate AI Usage Policy AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided. Work Model Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings. - Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility. - Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility. - Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

Hawaii
$86.9K - $198K / year
Booz Allen Hamilton logo

Information Systems Security Manager

Booz Allen Hamilton

Booz Allen Hamilton is an award-winning provider of strategic innovation, management consulting, technology, and engineering services. Founded in 1914, the comp

Administer US government security policies, create assessment packages using Risk Management Framework, manage system administrators for software updates, and conduct security self-reviews to ensure compliance with security protocols and procedures.

North Carolina
NRG Energy logo

Cybersecurity Risk Analyst

NRG Energy

NRG Energy is a Fortune 300 and S&P 500 company, based in Princeton, New Jersey, owns and operates a diverse portfolio of energy companies. Established in 1989,

Title: Cybersecurity Risk Analyst Location: Houston, TX, US, 77010 Company: NRG As an NRG employee, we encourage you to take charge of your career and development journey. We invite you to explore exciting opportunities across our businesses. You’ll find that our dynamic work environment provides variety and challenge. Your growth is key to our ongoing success—take the lead in shaping your career development, goals and future! JOB SUMMARY: The Cybersecurity Risk Analyst supports the organization's cyber risk management program by identifying, assessing, documenting, and communicating cyber risk across systems, applications, technologies, and business initiatives. This role partners with Technology, Business, Enterprise Risk and other stakeholders to enable risk-informed decisions and practical risk treatment outcomes. The role is focused on internal cybersecurity risk assessments evaluating threats, vulnerabilities, control gaps, and business impact while helping stakeholders align on risk acceptance decisions consistent with organizational risk tolerance. Work is guided by the NIST CSF 2.0, with expected familiarity with FAIR and professional AI tools, as well as awareness of emerging technology risks and evolving cyber threats. This role is distinct from team responsibilities centered on third-party risk, vendor contracts, security surveys, or regulatory compliance. Essential Duties and Responsibilities: Cybersecurity Risk Assessment - Conduct cybersecurity risk assessments for systems, applications, infrastructure, technologies, projects, and business initiatives. - Identify, assess, analyze, and document cybersecurity threats, vulnerabilities, control gaps, exploitability considerations, and potential business impacts. - Evaluate inherent and residual cyber risk and develop clear, supportable risk statements, ratings, and recommendations. - Apply established cybersecurity risk assessment methodologies, frameworks, and reference materials, including FAIR and other relevant cyber risk analysis approaches. - Support practical and well-informed cyber risk treatment recommendations, including mitigation, remediation, transfer, avoidance, and acceptance. - Assist in identifying and documenting reasonable cyber risk acceptance positions aligned with business objectives, governance expectations, and organizational risk tolerance. Stakeholder Engagement and Risk Facilitation - Partner with stakeholders across Technology, Cybersecurity, Business, and Enterprise Risk to gather information and support effective cyber risk assessments. - Facilitate meetings, workshops, and working sessions to bring the right stakeholders together for risk identification, analysis, treatment, and acceptance discussions. - Build alignment across teams and help translate technical cybersecurity issues into clear business risk implications and decision points. - Coordinate with team members responsible for adjacent activities, including third-party risk management, compliance support, contract review, security surveys, and regulatory matters, while maintaining primary focus on internal cyber risk assessment and analysis. Vulnerability and Threat-Informed Risk Analysis - Work closely with vulnerability management and other cybersecurity teams to understand vulnerability exposure, remediation priorities, compensating controls, and the impact of technical findings on cyber risk. - Analyze vulnerability data, remediation status, exploitability, and exposure trends to inform cyber risk assessments and recommendations. - Maintain awareness of emerging cyber threats, attack techniques, threat actor activity, and technology developments that may affect the organization’s risk posture. Metrics, Reporting, and Program Support - Collect, organize, analyze, and report cybersecurity risk metrics, trends, and themes to support leadership reporting and program oversight. - Prepare clear and concise risk assessment documentation, reports, summaries, and presentations for technical and non-technical stakeholders. - Support the continuous improvement of cybersecurity risk assessment processes, templates, standards, and reporting practices. - Use approved AI-enabled tools responsibly to support cyber risk research, analysis, documentation, and operational efficiency in accordance with company requirements. - Incorporate considerations related to artificial intelligence, generative AI, and other emerging technology risks into cybersecurity risk assessments, as applicable. Working Conditions: - Hybrid. - Travel minimally. Minimum Requirements: - A bachelor’s degree in Cybersecurity, Information Technology, Information Systems, Risk Management, Business, or a related field is preferred but not required. - A minimum of five years of experience in cybersecurity, information security, cyber risk, technology risk, vulnerability management, IT audit, or a related discipline is essential. - Demonstrated experience performing cybersecurity or technology risk assessments is required. - Familiarity with the NIST Cybersecurity Framework (CSF) 2.0 is required. - Familiarity with FAIR and other recognized cybersecurity risk assessment methodologies, models, or reference resources are required. - Experience with vulnerability management concepts, processes, and reporting, including the ability to interpret vulnerability data in a risk context, is required. - Proficiency in Microsoft Office products, including Word, Excel, PowerPoint, and SharePoint, is expected. - Ability to effectively apply approved AI technologies such as CoPilot in a professional environment is expected. Additional Knowledge, Skills and Abilities: Technical & Domain Expertise: - Strong understanding of cybersecurity risk principles, threats, vulnerabilities, control environments, and risk treatment concepts. - Working knowledge of cybersecurity frameworks and references, including NIST CSF 2.0, and familiarity with related standards such as NIST 800-53, CIS Controls, ISO 27001, or COBIT. - Familiarity with cyber risk analysis methods such as FAIR; familiarity with quantitative risk analysis concepts, including Monte Carlo simulation, is preferred but not required. - Knowledge of vulnerability management practices and the ability to connect technical findings to broader business and cyber risk considerations. - Awareness of artificial intelligence, generative AI, and emerging technology risks, and the ability to incorporate those considerations into cyber risk assessments. - Experience in energy, utilities, critical infrastructure, or other highly regulated industries is preferred. - Knowledge of operational technology, industrial control systems, or energy generation and retail environments is preferred. Skills & Competencies: - Strong analytical, critical thinking, and problem-solving capabilities. - Effective stakeholder engagement and facilitation skills, with the ability to bring teams together and drive productive risk discussions. - Ability to gather, interpret, and present risk metrics and related data in a meaningful and actionable manner. - Strong written and verbal communication skills, including the ability to prepare professional documentation and communicate effectively with both technical and non-technical audiences. - Ability to translate complex cybersecurity issues into clear, concise, and business-relevant risk information. - Strong organizational skills and the ability to manage multiple priorities while delivering high-quality work within established deadlines. - Demonstrated ability to work collaboratively across Cybersecurity, Technology, Business, and Enterprise Risk teams. Physical Requirements: - From time to it may be required to move light computer equipment such as laptops. NRG Energy is committed to a drug and alcohol-free workplace. To the extent permitted by law and any applicable collective bargaining agreement, employees are subject to periodic random drug testing, and post-accident and reasonable suspicion drug and alcohol testing. EOE AA M/F/Vet/Disability. Level, Title and/or Salary may be adjusted based on the applicant's experience or skills.

Texas