Remote job
Endpoint & Security Platforms Engineer
Job details
About this role
Role overview A hands-on engineering role responsible for building and operating the controls that protect employee devices and server workloads across a mixed estate. The position covers the full lifecycle of endpoint and security platforms, from deployment and hardening through troubleshooting, automation, and authorized containment, working closely with IT, infrastructure, cyber defense, and data security colleagues.
Responsibilities - Deploy and maintain EDR/XDR agents and endpoint protection policies across Windows, Linux, and macOS workstations and production servers, covering the full agent lifecycle. - Resolve agent failures, telemetry gaps, policy conflicts, and performance issues, taking ownership of complex security cases. - Implement risk-based OS hardening baselines alongside application and infrastructure owners, including testing, rollback preparation, and safe production deployment. - Operate endpoint DLP controls, maintaining agents and tuning policies to reduce friction without weakening protection. - Maintain assigned security platforms such as SIEM, including service health, access configuration, updates, storage, backups, and recovery. - Monitor telemetry and control health, investigating stale agents, coverage gaps, and unmanaged systems, and drive fixes through automation and runbook improvements. - Support cyber defense investigations with endpoint expertise and execute approved containment actions. - Automate recurring administration, validation, and reporting using scripts and APIs, and maintain clear configuration documentation.
Requirements - 4+ years of hands-on experience in endpoint security, infrastructure security, system security, or a related security engineering discipline. - Practical experience deploying and operating an enterprise EDR/XDR or endpoint protection platform across mixed workstation and server environments. - Strong Linux administration skills, plus the ability to support and troubleshoot protection on Windows using logs, services, permissions, network connections, and resource usage. - Experience introducing security controls into production, including testing, controlled deployment, and rollback. - Background implementing OS hardening and working with native security controls. - Understanding of access-control models, least privilege, endpoint telemetry, file-integrity monitoring, and host-isolation techniques. - Ability to automate operational work using Python, Bash, PowerShell, or similar scripting languages. - Clear communication with technical colleagues, reliable documentation habits, and a focus on following issues through to verified resolution. - Upper-Intermediate English and fluent Ukrainian.
Nice to have - Experience administering a self-managed Elastic or other SIEM platform. - Background with endpoint DLP solutions or Microsoft Defender. - Familiarity with macOS security and device-management tools such as Mosyle, ManageEngine, Ansible, or Puppet. - Experience with CIS Benchmarks, DISA STIG, or native OS security controls like SELinux, AppArmor, FileVault, or BitLocker. - Experience supporting a large, distributed fleet of endpoints or servers, ideally in fintech, trading, or another performance-critical environment. - Technical education in Information Security, Computer Science, or a related field.
Benefits and work setup - 20 paid vacation days per year plus 10 paid sick leave days. - Public holidays aligned with the company's approved calendar. - Medical budget, professional education budget, and language-learning budget. - Wellness budget covering gym membership, sports equipment, and related expenses. - Remote work setup.