Driving A Better Way®
Staff Endpoint Security Engineer
Location
India
Posted
6 days ago
Salary
0
Seniority
Lead
Job Description
Staff Endpoint Security Engineer
ChargePoint
Role Description We are looking for a Staff Endpoint Security Engineer with deep expertise across Windows, macOS, and Linux environments to lead and mature our endpoint security programme. You will be responsible for the design, deployment, and continuous improvement of our endpoint protection, detection, and response capabilities, as well as our Mobile Device Management (MDM) infrastructure. Working closely with IT, security operations, and compliance teams, you will ensure that every managed device across the organisation meets the highest security standards — from first enrolment to decommission. What You Will Bring to ChargePoint - Endpoint Protection & Hardening - Define, implement, and enforce endpoint security baselines and hardening standards across Windows, macOS, and Linux platforms in alignment with CIS Benchmarks, NIST guidelines, and organisational policy. - Deploy, manage, and tune Endpoint Detection and Response (EDR) solutions (e.g., CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, or equivalent) across all device types. - Implement and maintain antivirus, anti-malware, host-based firewall, application allowlisting/blocklisting, and data loss prevention (DLP) controls. - Conduct regular endpoint vulnerability assessments and drive timely remediation in coordination with IT and asset owners. - Manage full-disk encryption across platforms — BitLocker (Windows), FileVault (macOS), and LUKS/dm-crypt (Linux). - Mobile Device Management (MDM) - Architect, deploy, and manage enterprise MDM solutions — including Jamf Pro (macOS/iOS), Microsoft Intune, VMware Workspace ONE, or equivalent platforms — across the organisation's full device fleet. - Design and enforce MDM enrolment workflows, device compliance policies, configuration profiles, and conditional access rules. - Manage application lifecycle through MDM — packaging, deployment, patching, and removal across managed endpoints. - Manage certificate lifecycle and PKI integration for device authentication and Wi-Fi/VPN access. - Windows Endpoint Security - Manage and harden Windows endpoints using Group Policy (GPO), Microsoft Endpoint Configuration Manager (MECM/SCCM), and Microsoft Intune. - Implement and maintain Windows Defender suite — Defender Antivirus, Defender for Endpoint, Defender Firewall, and Attack Surface Reduction (ASR) rules. - Oversee Windows patch management processes ensuring timely deployment of OS and application updates. - Configure and monitor Windows Event Logging, Sysmon, and audit policies for comprehensive endpoint telemetry. - macOS Endpoint Security - Manage macOS fleet security using Jamf Pro — configuration profiles, extension attributes, smart groups, policies, and patch management. - Implement macOS security controls including system integrity protection (SIP), Gatekeeper, TCC (Transparency, Consent & Control), and secure boot settings. - Develop and maintain custom Jamf scripts (Bash, Python, Swift) for automation, remediation, and compliance reporting. - Manage macOS MDM enrolment via Apple Business Manager (ABM) / Apple School Manager (ASM) and DEP/ADE workflows. - Linux Endpoint Security - Harden Linux endpoints (Ubuntu, RHEL, CentOS, Debian, or equivalent) using industry-standard security frameworks and configuration management tools (Ansible, Chef, Puppet, or similar). - Implement and manage SELinux / AppArmor policies, auditd configurations, and host-based intrusion detection (OSSEC, Wazuh, or equivalent). - Manage Linux patch management and software inventory using tools such as Landscape, Ansible, or Satellite. - Monitor and respond to Linux endpoint security events using EDR agents and SIEM integrations. - Threat Detection & Incident Response - Triage and respond to endpoint security alerts and incidents — containment, investigation, eradication, and recovery. - Perform endpoint forensic analysis including memory forensics, disk imaging, and log analysis during security incidents. - Develop and maintain endpoint-specific detection rules, threat hunting queries, and playbooks. - Collaborate with the SOC/SIEM team to enrich endpoint telemetry and improve detection coverage. - Compliance & Governance - Ensure endpoint security posture meets compliance requirements for relevant frameworks (SOC 2, ISO 27001, CIS Controls, NIST CSF, PCI-DSS, HIPAA where applicable). - Maintain endpoint asset inventory and configuration management database (CMDB) accuracy. - Produce regular endpoint compliance and health reports for security leadership and audit purposes. - Develop and enforce acceptable use, BYOD, and device security policies. - Leadership & Collaboration - Mentor junior and mid-level endpoint security engineers and IT operations staff. - Define endpoint security roadmap and drive continuous improvement initiatives. - Evaluate and onboard new endpoint security tooling; manage vendor relationships. - Collaborate with HR and IT on joiners/movers/leavers processes to ensure secure device provisioning and deprovisioning. Qualifications - 7–9 years of hands-on experience in endpoint security, systems administration, or a closely related field. - Expert-level knowledge of Windows endpoint security — Group Policy, Intune, SCCM/MECM, Defender for Endpoint, and Windows hardening. - Expert-level knowledge of macOS endpoint security — Jamf Pro, Apple Business Manager, configuration profiles, and macOS security controls. - Solid experience with Linux endpoint security — hardening, SELinux/AppArmor, auditd, and Linux-based EDR/HIDS solutions. - Deep, proven experience with enterprise MDM platforms (Jamf Pro, Microsoft Intune, Workspace ONE, or equivalent) in a large-scale environment. - Hands-on experience with EDR/EPP platforms (CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, or equivalent). - Strong scripting skills for automation and endpoint management — Bash, PowerShell, Python, and/or Swift. - Solid understanding of PKI, certificate management, and secure authentication (SAML, OAuth, SCIM, conditional access). - Familiarity with SIEM platforms and endpoint telemetry integration (Splunk, Microsoft Sentinel, Elastic, or equivalent). - Strong knowledge of endpoint security frameworks: CIS Benchmarks, NIST SP 800-70, DISA STIGs. Nice to Have - Experience with Zero Trust Network Access (ZTNA) and integration of MDM compliance with identity providers (Okta, Azure AD, Ping Identity). - Familiarity with privileged access management (PAM) tools (CyberArk, BeyondTrust, or similar). - Exposure to mobile security (iOS, Android) within an MDM context. - Experience with vulnerability management platforms (Tenable, Qualys, Rapid7). - Knowledge of macOS and Linux forensics tooling (osquery, Velociraptor, or similar). - Relevant certifications: CISSP, CISM, CompTIA Security+, CEH, Microsoft SC-300/MD-102, Jamf Certified Admin/Expert, CrowdStrike CCFA/CCFR, or equivalent. - Experience in regulated industries (FinTech, Healthcare, Legal, or Enterprise SaaS). Location Gurgaon/Remote Company Description We are committed to an inclusive and diverse team. ChargePoint is an equal opportunity employer. We do not discriminate based on race, color, ethnicity, ancestry, national origin, religion, sex, gender, gender identity, gender expression, sexual orientation, age, disability, veteran status, genetic information, marital status or any legally protected status. If there is a match between your experiences/skills and the Company needs, we will contact you directly. ChargePoint is committed to fostering an inclusive workplace that welcomes and supports all qualified individuals. In alignment with this commitment, we ensure that persons with disabilities are provided with reasonable accommodations throughout the employment process. If you need a reasonable accommodation to participate in the application or interview process, to perform essential job functions, or to access any other benefits and privileges of employment, please contact us at accommodations@chargepoint.com. ChargePoint is an equal opportunity employer. Applicants only - Recruiting agencies do not contact.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Develops and executes a comprehensive IT roadmap covering applications, infrastructure, and cybersecurity • Aligns IT strategy with business priorities to support growth, scalability, and operational excellence • Serves as a key advisor to executive leadership on technology investments, risks, and opportunities • Oversees IT governance, budgeting, vendor management, and resource allocation across all domains • Builds and maintains a robust and aligned Disaster Recovery Plan to assure business continuity • Leads strategy, development, and optimization of ERP and enterprise applications • Partners with business leaders to identify opportunities for process automation and system enhancements • Ensures strong change management practices and risk-based systems validation process for all system implementations and upgrades • Oversees design, implementation, and maintenance of enterprise IT infrastructure, including networks, servers, cloud environments, and data centers • Ensures high availability, performance, and scalability of all IT systems and services • Establishes and monitors service level agreements (SLAs) and ensure excellent end-user support experience • Manages network architecture, telecommunications, and enterprise hardware/software lifecycle • Leads disaster recovery, business continuity, and resilience strategies • Owns enterprise cybersecurity strategy, including threat prevention, detection, and response • Ensures implementation and effectiveness of security controls • Maintains compliance with regulatory standards and internal controls • Conducts risk assessments and ensure mitigation strategies are implemented across systems and infrastructure • Leads IT service delivery including help desk, technical support, and end-user services • Drives continuous improvement in IT operations, service quality, and user satisfaction • Establishes and maintains strong partnerships with vendors, consultants, and hosting providers • Builds and leads high-performing teams across applications, infrastructure, and security • Develops team capabilities, succession plans, and organizational structure to support growth • Fosters a culture of accountability, collaboration, and innovation • Provides leadership, coaching, and performance management for IT staff
Manager, Application Security
Guild MortgageIn neighborhoods and communities everywhere, we deliver the promise of home.
• Develop and execute application security strategy, including threat modeling, secure code review practices, and vulnerability management • Establish and maintain secure software development lifecycle practices and standards across all engineering teams • Oversee vulnerability management programs including triage, remediation tracking, and executive reporting • Manage the application security tool portfolio including SAST, DAST, and software composition analysis platforms • Lead threat modeling and architectural security reviews for critical systems and new initiatives • Coordinate third-party security assessments, penetration testing, and code reviews • Drive security awareness and training programs tailored to developer and architect audiences • Establish KPIs and executive dashboards to communicate application security posture and risk trends • Partner with Engineering, DevOps, and Product leadership to embed security into CI/CD pipelines and release processes • Define and enforce application security policies, standards, and control frameworks • Evaluate and respond to emerging threats, CVEs, and industry developments relevant to application security • Lead, mentor, and grow a team of application security engineers
• As a Senior Account Manager here at Honeywell, you will be responsible for managing and growing key customer accounts, ensuring customer satisfaction, and driving revenue growth. • You will act as the primary point of contact for clients, developing strong relationships and understanding their business needs to provide tailored solutions. • In this role, you will impact Honeywell’s market presence and revenue by fostering long-term partnerships with clients and delivering exceptional account management and business development strategies. • Note that this role requires travel up to 50% domestically.
Senior AI Security Engineer
BackblazeBackblaze is the cloud storage innovator delivering a modern alternative to traditional cloud providers.
• Architect and implement guardrails for tool-using AI systems, including: • Tool access controls and allowlists • Context and memory isolation • Step-level validation of agent actions • Apply mitigations aligned to the OWASP Agentic AI Top 10 (e.g., prompt injection, unsafe tool use, data leakage, excessive autonomy) • Build enforcement mechanisms that govern AI behavior at execution time: • Interceptors, proxies, or middleware for tool/API calls • Policy decision and enforcement layers • Rate limits, execution bounds, and kill-switches • Design and implement identity and access controls for agents and automation, including: • Short-lived credentials and scoped permissions • Clear separation between human and non-human access • Strong binding of identity to task context and execution • Ensure all AI actions are attributable and auditable • Implement logging and tracing for AI activity: • Prompts, tool usage, and decision flows • Build detection capabilities using: • Behavioral baselining and anomaly detection techniques • Identify and alert on: • Abnormal tool usage • Suspicious prompt patterns • Unexpected data access • Perform agentic system threat modeling using MAESTRO, including: • Mapping agent capabilities, trust boundaries, and attack paths • Modeling misuse and adversarial scenarios • Translate findings into practical safeguards and detection logic • Protect developers using AI tools by: • Preventing sensitive data exposure • Validating AI-generated code and actions • Constraining unsafe automation




