All Jobs Vacancy

End-Point Security Architect

Posted 2 days ago by Stellent IT LLC

The Endpoint Security Architect serves as the technical authority for enterprise endpoint security strategy, architecture, and modernization initiatives across a highly regulated critical infrastructure environment. This role is responsible for developing endpoint security standards, defining future-state architectures, and leading endpoint security initiatives supporting corporate IT, remote workforce, cloud, and operational business environments.

The architect will partner closely with Cybersecurity, Infrastructure, Identity & Access Management, Network Security, Cloud Engineering, and Operations teams to design secure endpoint solutions that align with Zero Trust principles, regulatory requirements, and enterprise security objectives.

Endpoint Security Architecture

  • Develop, maintain, and govern enterprise endpoint security architectures and roadmaps.
  • Define security standards, reference architectures, design patterns, and implementation guidance for endpoint technologies.
  • Lead architecture reviews and ensure endpoint solutions align with enterprise security standards.
  • Design endpoint security controls supporting Windows, macOS, mobile devices, and remote users.
  • Support Zero Trust security initiatives and endpoint access strategies.

Endpoint Protection & Detection

  • Design and govern endpoint protection platforms including:
  • Microsoft Defender for Endpoint
  • CrowdStrike Falcon
  • SentinelOne
  • Tanium
  • Carbon Black
  • Similar EDR/XDR solutions
  • Define endpoint telemetry, logging, threat detection, and response requirements.
  • Collaborate with Security Operations teams to improve endpoint visibility and threat detection coverage.

Endpoint Management & Modern Workplace

  • Architect modern endpoint management solutions utilizing:
  • Microsoft Intune
  • Microsoft Autopilot
  • Microsoft Configuration Manager (MECM/SCCM)
  • Workspace ONE
  • Jamf
  • Develop endpoint compliance, configuration baseline, and device lifecycle management strategies.
  • Support BYOD, mobile device management (MDM), and unified endpoint management (UEM) initiatives.

Identity & Zero Trust

  • Partner with IAM teams to implement:
  • Conditional Access
  • Device Trust
  • Multi-Factor Authentication (MFA)
  • Least Privilege Access
  • Privileged Access Management
  • Align endpoint security architecture with NIST 800-207 Zero Trust principles.

Risk, Governance & Compliance

  • Conduct endpoint security architecture reviews and risk assessments.
  • Participate in architecture governance processes and technical design reviews.
  • Develop security standards, configuration baselines, and hardening requirements.
  • Support compliance initiatives aligned to:
  • NERC-CIP
  • NIST Cybersecurity Framework
  • NIST 800-53
  • CIS Controls
  • Regulatory and audit requirements.

Technical Leadership

  • Provide technical leadership and mentorship to engineers and architects.
  • Evaluate emerging endpoint security technologies and recommend future-state solutions.
  • Influence architecture decisions across multiple technology teams and business units.

Required Qualifications

  • 8+ years of experience in Endpoint Security, Security Architecture, Endpoint Engineering, or related disciplines.
  • Experience designing and securing large enterprise endpoint environments.
  • Deep knowledge of endpoint security concepts including:
  • EDR/XDR
  • Endpoint hardening
  • Device compliance
  • Privileged access controls
  • Endpoint telemetry
  • Experience with Microsoft Intune and Microsoft Defender for Endpoint.
  • Experience with endpoint management and deployment platforms.
  • Experience implementing Zero Trust security controls.
  • Strong understanding of Windows endpoint security architecture.
  • Experience developing enterprise security standards and technical documentation.
  • Knowledge of NIST 800-53, NIST 800-207, CIS Controls, and defense-in-depth principles.

Preferred Qualifications

  • Experience supporting highly regulated environments, critical infrastructure, energy, utility, nuclear, or government organizations.
  • Experience with:
  • CrowdStrike Falcon
  • Tanium
  • SentinelOne
  • Jamf
  • Workspace ONE
  • ServiceNow
  • Experience with cloud security integration across Microsoft 365, Azure, and AWS.
  • Experience conducting threat modeling and endpoint risk assessments.
  • Experience leading enterprise endpoint modernization initiatives.

Preferred Certifications

  • CISSP
  • Microsoft Certified: Endpoint Administrator Associate
  • Microsoft Certified: Azure Security Engineer Associate
  • Microsoft Certified: Security Operations Analyst Associate
  • CrowdStrike Certified Falcon Administrator
  • Tanium Certified Professional
  • GIAC (GSEC, GCIH, GCED, GCIA)
  • Microsoft Defender for Endpoint Certifications.
Rate:
Not specified
Location:
Remote
IR35 Status:
Outside
Remote Status:
Remote
Industry:
Cybersecurity
Seniority Level:
Senior

Take-Home Pay

Not Available

Visit calculators for additional details

Share job