Why This Role Stands Out
This role offers a fantastic opportunity to significantly enhance enterprise security and develop advanced skills in endpoint protection and identity management within a reputable tech company. You'll thrive here if you possess expertise in hardening, AD security, and vulnerability remediation, and are eager to contribute to a robust security posture. Apply now to join this dynamic team in NYC and make a real impact.
Quick Overview
Job Description
Endpoint Security Engineer / Endpoint & Identity Security Engineer
Location: NYC
Type: Onsite role at NYC client site
Must have: Hardening, AD security, endpoint protection, vulnerability remediation, and automation
We need someone who can strengthen enterprise security by implementing hardening standards, securing Active Directory, and managing endpoint protection across Windows and Linux environments. Maintain CIS‑aligned baselines, enforce GPO‑driven security controls, and support vulnerability remediation using industry‑leading tools. Ensure endpoints, servers, and identities remain compliant, resilient, and securely configured.
Key Focus Areas:
- CIS Benchmark hardening (Windows/Linux)
- Active Directory & GPO security governance
- Endpoint protection (Defender, CrowdStrike, SentinelOne, Trellix)
- Vulnerability management (Tenable/Qualys/Rapid7)
- PAM, MFA, encryption, listing & device control
- PowerShell automation for security configuration
Required Skills:
- Windows Server & Active Directory Administration
- CIS Benchmark Hardening (Windows, Linux, endpoints)
- Group Policy (GPO) Security & Governance
- Endpoint Security Platforms: Microsoft Defender, CrowdStrike, SentinelOne, Trellix, Symantec
- Core Security Controls: PAM, MFA, Encryption, Application listing, Device Control
- Vulnerability Management Tools: Tenable, Qualys, or Rapid7
- Security Frameworks: CIS, NIST, ISO 27001
- PowerShell Automation
Certifications related to work: (any or as many is okay—as these are plus)
- CIS Secure Suite Certified Practitioner (CIS‑CP)
- SC‑300 (Identity & Access Administrator)
- AZ‑500 (Azure Security Engineer)
- SC‑200 (Security Operations Analyst)
- CrowdStrike CCFA or Sentinel One SIREN
- Qualys / Tenable / Rapid7 VM Certification
Similar jobs
- DI
Security Control Assessor
NewDivIHN Integration Inc.
Oak Ridge, TN🇺🇸HybridYesterdayAdministrative - IN
Security Architect
NewInterSources Inc.
United States🇺🇸HybridYesterdaySQLSQL ServerAWS+2Technology - EG
IAM Analyst
NewEliassen Group
Almont, CO🇺🇸$70 - $80/hrHybridYesterday401kActive DirectoryRecruiting - BI
Information Systems Security Engineer
NewBigBear.ai
UT🇺🇸HybridYesterdayAWSMFAOAuth+6Technology - EG
Identity Engineer
NewEliassen Group
Dallas, TX🇺🇸$90 - $100/hrHybridYesterdayEngineering - DS
Zero Trust Cybersecurity Engineer with Security Clearance
NewDexian Signature Federal
Scott AFB, IL🇺🇸RemoteYesterdayGCPMicroservicesOracle+8Technology