Why This Role Stands Out
Elevate enterprise security by implementing robust hardening standards and automation in a hybrid environment with TekDallas, a company recognized for its commitment to innovation. You'll thrive here if you possess expertise in Active Directory security, endpoint protection, and vulnerability remediation, contributing to a resilient and secure infrastructure. This is an excellent opportunity to leverage and expand your skills in a dynamic technology setting.
Quick Overview
Job Description
Endpoint Security Engineer / Endpoint & Identity Security Engineer
Location: NYC, NY – need candidates from Tristate (NY/NJ/CT)
AIMust have to be LOCAL to Tristate
Mandatory: Hardening, AD security, endpoint protection, vulnerability remediation,
and automation
We need someone who can strengthen enterprise security by implementing hardening standards, securing Active Directory, and managing endpoint protection across Windows and Linux environments. Maintain CIS‑aligned baselines, enforce GPO‑driven security controls, and support vulnerability remediation using industry‑leading tools. Ensure endpoints, servers, and identities remain compliant, resilient, and securely configured.
Key Focus Areas:
- CIS Benchmark hardening (Windows/Linux)
- Active Directory & GPO security governance
- Endpoint protection (Defender, CrowdStrike, SentinelOne, Trellix)
- Vulnerability management (Tenable/Qualys/Rapid7)
- PAM, MFA, encryption, listing & device control
- PowerShell automation for security configuration
Required Skills:
- Windows Server & Active Directory Administration
- CIS Benchmark Hardening (Windows, Linux, endpoints)
- Group Policy (GPO) Security & Governance
- Endpoint Security Platforms: Microsoft Defender, CrowdStrike, SentinelOne, Trellix, Symantec
- Core Security Controls: PAM, MFA, Encryption, Application listing, Device Control
- Vulnerability Management Tools: Tenable, Qualys, or Rapid7
- Security Frameworks: CIS, NIST, ISO 27001
- PowerShell Automation
Certifications related to work: (any or as many is okay—as these are plus)
- CIS Secure Suite Certified Practitioner (CIS‑CP)
- SC‑300 (Identity & Access Administrator)
- AZ‑500 (Azure Security Engineer)
- SC‑200 (Security Operations Analyst)
- CrowdStrike CCFA or Sentinel One SIREN
- Qualys / Tenable / Rapid7 VM Certification
Similar jobs
- JM
Product Security Architect
NewJ.P. Morgan
Plano, Texas🇺🇸On-site47 minutes agoPythonJavaC#+4Technology - VA
Lead Sr. Network Operations Engineer (Network Security - Palo Alto/Zscaler) Engineer
NewVanguard
Charlotte, North Carolina🇺🇸Hybrid47 minutes agoAWSZero TrustTechnology - MA
Cyber Systems Engineer
NewMANTECH
United States🇺🇸Hybrid47 minutes agoTechnology - VA
Cloud Security Specialist (IAM & Cloud Controls)
NewVanguard
Malvern, Pennsylvania🇺🇸Hybrid47 minutes agoGCPSQLAWS+6Technology - VA
College to Corporate IT Internship - Risk & Security - Analyst (PA)
NewVanguard
Malvern, Pennsylvania🇺🇸Hybrid47 minutes agoAgileAdministrative - TE
Information Security Analyst
NewTechNix LLC
United States🇺🇸Remote17 hours agoAWSPenetration TestingTechnology