This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Our direct client is Endpoint Security Engineer who will be embedded within the endpoint engineering team (3 Windows engineers, 2 macOS engineers) to enhance security operations and strengthen the security posture of client workstations. You will work closely with endpoint engineering and cybersecurity teams to identify vulnerabilities, automate remediation, and strengthen endpoint security baselines in a large enterprise environment. Will assist in improving our endpoint cyber hygiene and vulnerability management program in collaboration with the CSPO.
Job Responsibility:
Identify, analyze, and prioritize endpoint vulnerabilities using tools such as Tenable, Axonius, Jamf Pro, SCCM, Intune, Active Directory, and Entra
Assess environmental and operational factors that may impact remediation feasibility and timelines
Provide risk-based recommendations to improve the vulnerability management program
Develop, test, and deploy remediation scripts and configurations for Windows and macOS endpoints using tools such as Jamf, ConfigMgr/SCCM, Intune, and Group Policy
Write clear, maintainable scripts and automation (e.g., modular logic, meaningful naming, basic error handling and logging) that can be reused by the team
Document scripts and configurations with purpose, parameters, usage instructions, and any security considerations to support troubleshooting and cross-team adoption
Maintain an organized library of remediation artifacts
if applicable, help establish and use a version-controlled repository (e.g., Git) to track changes and support basic peer review
Contribute to secure baseline configurations aligned with Argonne CSPP, NIST 800-53 Rev 5, CIS Benchmarks, Microsoft Security Baselines, DISA STIGs, and/or macOS Security Compliance Project
Assist in development, testing, implementation, documentation of baseline configurations
Monitor baseline implementation for coverage, effectiveness, unapproved deviations, and required changes
Participate in regular team meetings to provide status updates, propose improvements, and discuss implementation strategies
Monitor endpoint compliance and provide reports on remediation effectiveness and baseline configurations to leadership and stakeholders
Requirements:
Endpoint engineering expertise
Strong cyber security skills
Modern, secure coding practices
3–5 years of experience in complex large enterprise environments
Hands-on expertise with SCCM, Jamf Pro, and/or Microsoft Intune for Windows and macOS endpoints
Experience packaging and deploying applications, security updates, and scripts across enterprise platforms
Familiarity with Group Policy and Intune for configuration management
Proficiency in automation scripting (PowerShell, Bash, Python) with emphasis on modular, reusable, and secure code
Experience with version control systems (Git) and collaborative development workflows (branching, pull requests, peer review)
Knowledge of CVE program, NIST Vulnerability Database, CISA Known Exploited Vulnerability Database, and overall vulnerability management processes
Experience implementing NIST 800-53 Rev 5, CIS Benchmarks, DISA STIGs, Microsoft Security Baselines, and macOS Security Compliance Project
Strong problem-solving skills with a focus on reducing organizational risk
Effective communication skills to convey technical concepts to both technical and non-technical stakeholders
Collaborative mindset for working within a mixed Windows/macOS engineering team