Security Engineer (Endpoint and Infrastructure Protection)

$$$
Product

We are looking for a hands-on Security Engineer to build and operate the controls that protect our employee devices and server workloads.

This role sits at the intersection of endpoint security, server protection, and security platform engineering. You will not be limited to monitoring alerts: you will work across the full lifecycle of security controls - from deployment and policy tuning to coverage monitoring, hardening, troubleshooting, automation, and authorized containment.
 

You will work closely with IT, Infrastructure, Cyber Defense, IAM, and Compliance teams to make protection reliable, measurable, and effective without creating unnecessary friction for users or critical systems

Responsibilities

  • Operate and continuously improve EDR/XDR and endpoint protection controls across macOS and Windows workstations and Linux and Windows server workloads
  • Administer device-security controls through MDM/UEM and related management platforms where applicable
  • Manage the security-control lifecycle, including agent deployment, upgrades, policy configuration, exclusions, health monitoring, coverage-gap remediation, and controlled rollback
  • Build and maintain risk-based operating-system hardening baselines using CIS Benchmarks or equivalent security standards
  • Monitor telemetry and control health, and investigate stale agents, deployment failures, unmanaged systems, policy conflicts, and coverage gaps
  • Troubleshoot false positives, performance issues, security-agent conflicts, and control failures, driving them through root-cause analysis and remediation
  • Partner with IT and infrastructure teams on vulnerability remediation, patching, and security configuration improvements
  • Support endpoint- and server-related investigations and execute containment actions when authorized through approved procedures
  • Maintain file-integrity monitoring and isolation readiness for critical systems where required
  • Automate recurring administration, validation, and reporting tasks using scripts, APIs, or platform workflows
  • Maintain clear runbooks, configuration records, deployment documentation, and remediation tracking

     

Requirements

  • 4+ years of hands-on experience in endpoint security, infrastructure security, system security, or a related security engineering role
  • Practical experience administering an enterprise EDR/XDR or endpoint protection platform across a mixed workstation and server environment
  • Strong knowledge of Linux and desktop operating system - macOS, Windows - with the ability to troubleshoot security controls across the remaining platform
  • Experience with endpoint management, MDM/UEM, or equivalent configuration-management workflows
  • Ability to deploy, tune, and troubleshoot security agents, policies, exclusions, telemetry, and containment workflows
  • Experience implementing operating-system hardening and working with native security controls
  • Understanding of access-control models, least privilege, endpoint telemetry, file-integrity monitoring, and host-isolation techniques.
  • Ability to automate operational work using at least one scripting language such as Python, Bash, or PowerShell
  • English at Intermediate level or higher
     

Will be a plus

  • Experience working with CIS Benchmarks or comparable hardening standards
  • Experience securing both macOS workstations and Linux production servers
  • Experience supporting a large, distributed fleet of managed endpoints or servers
  • Familiarity with native controls such as SELinux, AppArmor, Gatekeeper, System Integrity Protection, FileVault, Microsoft Defender, Attack Surface Reduction, or BitLocker
  • Experience integrating endpoint telemetry or response workflows with other security platforms
  • Experience in fintech, banking, trading, or another regulated environment
  • Relevant technical education, professional training, or equivalent practical experience


We offer

  • 20 paid vacation days per year
  • 10 paid sick leave days per year
  • Public holidays according to the company’s approved holiday calendar
  • Medical budget
  • Remote work
  • Professional education budget
  • Language-learning budget
  • Wellness budget covering gym membership, sports equipment, and related expenses

Required skills experience

EDR 4 years
XDR 4 years
Linux 4 years
MacOS 4 years
JAMF 4 years
Microsoft Intune 4 years

Required languages

English B1 - Intermediate
Ukrainian Native
Published 25 August
6 views
Β·
0 applications
To apply for this and other jobs on Djinni login or signup.
Loading...