Haystack
← Back to Jobs
Technology
TE

Endpoint Security Engineer

TekDallasNew York, NY🇺🇸United StatesPosted 10 Sept 2026

Why This Role Stands Out

Elevate enterprise security by implementing robust hardening standards and automation in a hybrid environment with TekDallas, a company recognized for its commitment to innovation. You'll thrive here if you possess expertise in Active Directory security, endpoint protection, and vulnerability remediation, contributing to a resilient and secure infrastructure. This is an excellent opportunity to leverage and expand your skills in a dynamic technology setting.

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
New York, NY, United States
Posted
17 hours ago
EncryptionMFAAzurePowerShell

Job Description

Endpoint Security Engineer / Endpoint & Identity Security Engineer

Location: NYC, NY – need candidates from Tristate (NY/NJ/CT)

 

AIMust have to be LOCAL to Tristate

Mandatory: Hardening, AD security, endpoint protection, vulnerability remediation, 

and automation

 We need someone who can strengthen enterprise security by implementing hardening standards, securing Active Directory, and managing endpoint protection across Windows and Linux environments. Maintain CIS‑aligned baselines, enforce GPO‑driven security controls, and support vulnerability remediation using industry‑leading tools. Ensure endpoints, servers, and identities remain compliant, resilient, and securely configured.

Key Focus Areas:

  • CIS Benchmark hardening (Windows/Linux)
  • Active Directory & GPO security governance
  • Endpoint protection (Defender, CrowdStrike, SentinelOne, Trellix)
  • Vulnerability management (Tenable/Qualys/Rapid7)
  • PAM, MFA, encryption, listing & device control
  • PowerShell automation for security configuration

 Required Skills:

  • Windows Server & Active Directory Administration
  • CIS Benchmark Hardening (Windows, Linux, endpoints)
  • Group Policy (GPO) Security & Governance
  • Endpoint Security Platforms: Microsoft Defender, CrowdStrike, SentinelOne, Trellix, Symantec
  • Core Security Controls: PAM, MFA, Encryption, Application listing, Device Control
  • Vulnerability Management Tools: Tenable, Qualys, or Rapid7
  • Security Frameworks: CIS, NIST, ISO 27001
  • PowerShell Automation

Certifications related to work: (any or as many is okay—as these are plus)

  1. CIS Secure Suite Certified Practitioner (CIS‑CP)
  2. SC‑300 (Identity & Access Administrator)
  3. AZ‑500 (Azure Security Engineer)
  4. SC‑200 (Security Operations Analyst)
  5. CrowdStrike CCFA or Sentinel One SIREN
  6. Qualys / Tenable / Rapid7 VM Certification

Similar jobs