Job Description
Cybersecurity Engineer –Infrastructure &Endpoint Security Engineer(Tech Lead)
Job Family: Cybersecurity EngineeringDirect Reports:None
Position Summary:
We are seeking anexperiencedCybersecurityEngineer toserve as the technicalleadfor enterpriseendpoint defense,Microsoft 365 collaboration security,secure browsing,endpointprivilege management, and measurablesecuritycontrol maturity. This role will lead the design, deployment, tuning, lifecycle management, and continuous improvement ofsecurity platforms that protect corporate endpoints, servers,Microsoft 365 collaboration services, SaaS platforms,and cloud-connected assets from advanced threats while enabling reliable and frictionless business workflows.
This role willworkclosely with Security Operations, Infrastructure,Desktop Engineering,Collaboration Services,Platform Engineering, Identity, Cloud Security, Network Security,GRC,Legal, Compliance,and other cross-functional teams to ensure endpoint, Microsoft 365, SaaS,andinfrastructuresecurity controls aresecure by design, consistently deployed, operationally resilient, auditable, measurable,and aligned with enterprise security standards.
Detailed Responsibilities / Duties:
EDR/XDR Platforms: Lead the engineering, deployment, tuning, and scaling of CrowdStrike Falcon and/orMicrosoft Defender for Endpoint platforms, including EDR, hostfirewall, identity protection, policy management, detection tuning, and exception handling, partneringwith SOC CrowdStrike operational leadership
Lifecycle Management:Ownendpoint security platform lifecycle management, including sensor deployment strategy, upgrade planning, health monitoring, coverage gap remediation, rollback procedures, and change management coordination,partnering with SOCand Workstationoperational leadership
Secure Browsing Architecture: Architect, engineer, and enforce enterprise-wide security policies for secure enterprise browser technologies, including solutions such as Palo Alto Prisma Access Browser,partneringnetworkoperationalleadership
Microsoft 365 Collaboration Security: Engineer and mature security controls across Exchange Online, SharePoint Online, OneDrive, Microsoft Teams, and related Microsoft 365 workloads, including external sharing governance, guest access, link-sharing controls, tenant configuration baselines, collaboration risk reduction, and secure productivity enablement.
Privilege Management: Engineer andmaintainglobal Endpoint Privilege Management solutions using CyberArk and/orBeyondTrustto reduce oreliminatestanding local administrator rights while preserving operational continuity.
Security Automation: Build robust automation workflows and playbooks using PowerShell, Python, APIs, or workflow platforms to streamline deployment validation, threat containment, reporting, exception review, and control compliance.
Engineering Escalation: Act as the engineering escalation point for complex endpoint incidents, security tooling issues, agent conflicts, detection gaps, and root-cause investigations in partnership with Security Operations and Infrastructure teams.
Posture Hardening: Develop andreviewbaseline security configurations aligned with CIS Benchmarks, NIST guidance, and enterprise standards for Windows, macOS, and Linux endpoints.Partner withvulnerability threat management (VTM) team as they report and manage compliance in this space.
Ecosystem Integration: Integrate endpoint telemetry with SIEM, SOAR, XDR, vulnerability management, and reporting platforms to improvedetectionfidelity, response readiness, and measurable control effectiveness.
Microsoft Security & Compliance Integration: Partner on Microsoft Defender for Office 365, Microsoft Purview, audit logging, sensitivity labeling, DLP, retention, eDiscovery support, and Microsoft 365 Secure Score improvements to strengthen collaboration security and data protection outcomes.
Documentation & Audit: Create andmaintaintechnical documentation, runbooks, dashboards, operational procedures, and audit evidence for endpoint security controls.
Stakeholder Collaboration and Governance
Cross-Functional Alignment: Collaborate withSecurity Operations, Infrastructure, Desktop Engineering,Collaboration Services,Identity, Cloud Security, Platform Engineering, Network Security, GRC,Legal, Compliance,and other cross-functionalpartners to implement endpoint, Microsoft 365, SaaS, and infrastructuresecurity improvements.
Risk Translation: Translate complex endpoint security risks, platform limitations, compliance needs, and technical issues into clear, actionable recommendations for both technical and non-technical stakeholders.
Vendor Governance: Support vendor governance activities, including technology evaluation, roadmap alignment, service provider coordination, issue escalation, operational performance reviews, and contract or capability assessments.
Change Management: Partner with change management, audit, and compliance teams to ensure endpoint security changes areproperly assessed, documented, approved, implemented,validated, andevidenced.
Collaboration Governance: Partner with collaboration platform owners, business stakeholders, Legal, and Compliance to define and operationalize secure collaboration standards, including external sharing, guest access, sensitivity labeling, retention, and data loss prevention requirements.
Mentorship:Contribute toknowledge sharing across the team and mentor others on endpoint security architecture, troubleshooting practices, control validation, automation, and operational standards.
Supervisory Responsibilities:
None.
This is an individual contributor role with strong expectations for technical ownership, cross-functional leadership, and mentoring through influence.
Required Qualifications
8+ years of cybersecurity, endpoint security engineering, endpoint infrastructure, or related enterprise security experience.
Strong hands-onexpertisewith endpoint securityand Microsoft securityplatforms such as CrowdStrike Falcon,Microsoft Defender for Endpoint, Microsoft Defender for Office 365,Palo Alto secure access or secure browser technologies, CyberArk,and/orBeyondTrust.
Strong knowledge of Windows, macOS, and Linux operating systems, including endpoint hardening, troubleshooting, agent behavior, security baselines, and enterprise-scale deployment considerations.
Strong understanding of endpoint networking, TLS traffic flows, proxy behavior, hostfirewallbehavior, and how endpoint security controls interact across endpoint, network, cloud, identity, and SaaS environments.
Experience with enterprise endpoint management and deployment tools such as Microsoft Intune, MECM/SCCM, Group Policy,Jamf, or equivalent platforms.
Familiarity with cybersecurity controls forMicrosoft 365 collaboration services,SaaS platforms, Microsoft Entra ID, Azure environments, conditional access, device posture, and Zero Trust concepts.
Experience securing or governing Microsoft 365 collaboration workloads such as Exchange Online, SharePoint Online, OneDrive, and Microsoft Teams, including external sharing, guest access, permissions, audit logs, and data protection controls.
Experience with endpointfirewallproducts, vulnerability management processes, patch coordination, and basic network security principles.
Deep critical-thinking skills with the ability to analyze detections, diagnose complex endpoint issues, distinguish true threats from false positives, and drive root-cause resolution under pressure.
Demonstrated ability toidentifyrepeatable operational work and implement automation using scripting, APIs, workflows, or infrastructure-as-code concepts.
Experience developing endpoint security metrics, dashboards, compliance reports, exception tracking, or control effectiveness reporting.
Effective communication and collaboration skills with the ability to work across technical and non-technical stakeholder groups.
Preferred Qualifications
Relevant certifications such as CrowdStrike Certified Falcon Administrator, GIAC, CISSP, Microsoft Security certifications, Azure Security Engineer Associate, or CyberArk/BeyondTrustplatform certifications.
Experience with PowerShell, Python, REST APIs, Microsoft Graph API, workflow automation, or configuration-as-code approaches.
Experience with Microsoft Graph API, SharePoint Online Management Shell, Exchange Online PowerShell, Teams administration, or Microsoft 365 security and compliance automation.
Experience integrating endpoint security telemetry with corporate SIEM, SOAR, XDR, case management, vulnerability management, or data analytics ecosystems.
Experience implementing or supporting Microsoft 365 data protection capabilities such as sensitivity labels, DLP, retention policies, eDiscovery workflows, audit logging, Safe Links, Safe Attachments, and collaboration security reporting.
Experience supporting endpoint security controls in regulated, audit-driven, or financial-servicesenvironments.
Familiarity with Zero Trust security principles, identity-based access control, device posture, conditional access, and secure access service edge concepts.
LeadershipQualifications
Strong senseof ownership, accountability, and attention to detail.
Ability to lead through influence,establishtechnical direction, and drive execution across cross-functional teams without direct reporting authority.
Proven ability to develop structured processes that improve consistency, scalability, auditability, measurability, and operational efficiency.
Ability to manage competing priorities and deliver reliable outcomes in a dynamic enterprise environment.
Strong technical judgment and ability to balance security risk, operational stability, user experience, and business impact.
Strong communicationskills for bridging technical and business perspectives, including the ability to present risks, tradeoffs, and recommendations to leadership.
Curiosity and growth mindset, with the ability to adapt to evolvingendpoint,cloud, identity, AI, and threat landscapes.
Education
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field preferred.
Equivalent hands-on technical experience, relevant cybersecurity training, or nontraditional educational paths will also be considered.
Reporting Relationships
Compensation
The anticipated base salary range for this position is listed below. Total compensation may also include a discretionary performance-based bonus. Note, the range takes into account a broad spectrum of qualifications, including, but not limited to, years of relevant work experience, education, and other relevant qualifications specific to the role.
$240,000 - $270,000
The firm also offers robust Benefits offerings. Ares U.S. Core Benefits include Comprehensive Medical/Rx, Dental and Vision plans; 401(k) program with company match; Flexible Savings Accounts (FSA); Healthcare Savings Accounts (HSA) with company contribution; Basic and Voluntary Life Insurance; Long-Term Disability (LTD) and Short-Term Disability (STD) insurance; Employee Assistance Program (EAP), and Commuter Benefits plan for parking and transit.
Ares offers a number of additional benefits including access to a world-class medical advisory team, a mental health app that includes coaching, therapy and psychiatry, a mindfulness and wellbeing app, financial wellness benefit that includes access to a financial advisor, new parent leave, reproductive and adoption assistance, emergency backup care, matching gift program, education sponsorship program, and much more.
There is no set deadline to apply for this job opportunity. Applications will be accepted on an ongoing basis until the search is no longer active.