The Endpoint Security Architect serves as the technical authority for enterprise endpoint security strategy, architecture, and modernization initiatives across a highly regulated critical infrastructure environment. This role is responsible for developing endpoint security standards, defining future-state architectures, and leading endpoint security initiatives supporting corporate IT, remote workforce, cloud, and operational business environments.
The architect will partner closely with Cybersecurity, Infrastructure, Identity & Access Management, Network Security, Cloud Engineering, and Operations teams to design secure endpoint solutions that align with Zero Trust principles, regulatory requirements, and enterprise security objectives.
Endpoint Security Architecture
- Develop, maintain, and govern enterprise endpoint security architectures and roadmaps.
- Define security standards, reference architectures, design patterns, and implementation guidance for endpoint technologies.
- Lead architecture reviews and ensure endpoint solutions align with enterprise security standards.
- Design endpoint security controls supporting Windows, macOS, mobile devices, and remote users.
- Support Zero Trust security initiatives and endpoint access strategies.
Endpoint Protection & Detection
- Design and govern endpoint protection platforms including:
- Microsoft Defender for Endpoint
- CrowdStrike Falcon
- SentinelOne
- Tanium
- Carbon Black
- Similar EDR/XDR solutions
- Define endpoint telemetry, logging, threat detection, and response requirements.
- Collaborate with Security Operations teams to improve endpoint visibility and threat detection coverage.
Endpoint Management & Modern Workplace
- Architect modern endpoint management solutions utilizing:
- Microsoft Intune
- Microsoft Autopilot
- Microsoft Configuration Manager (MECM/SCCM)
- Workspace ONE
- Jamf
- Develop endpoint compliance, configuration baseline, and device lifecycle management strategies.
- Support BYOD, mobile device management (MDM), and unified endpoint management (UEM) initiatives.
Identity & Zero Trust
- Partner with IAM teams to implement:
- Conditional Access
- Device Trust
- Multi-Factor Authentication (MFA)
- Least Privilege Access
- Privileged Access Management
- Align endpoint security architecture with NIST 800-207 Zero Trust principles.
Risk, Governance & Compliance
- Conduct endpoint security architecture reviews and risk assessments.
- Participate in architecture governance processes and technical design reviews.
- Develop security standards, configuration baselines, and hardening requirements.
- Support compliance initiatives aligned to:
- NERC-CIP
- NIST Cybersecurity Framework
- NIST 800-53
- CIS Controls
- Regulatory and audit requirements.
Technical Leadership
- Provide technical leadership and mentorship to engineers and architects.
- Evaluate emerging endpoint security technologies and recommend future-state solutions.
- Influence architecture decisions across multiple technology teams and business units.
Required Qualifications
- 8+ years of experience in Endpoint Security, Security Architecture, Endpoint Engineering, or related disciplines.
- Experience designing and securing large enterprise endpoint environments.
- Deep knowledge of endpoint security concepts including:
- EDR/XDR
- Endpoint hardening
- Device compliance
- Privileged access controls
- Endpoint telemetry
- Experience with Microsoft Intune and Microsoft Defender for Endpoint.
- Experience with endpoint management and deployment platforms.
- Experience implementing Zero Trust security controls.
- Strong understanding of Windows endpoint security architecture.
- Experience developing enterprise security standards and technical documentation.
- Knowledge of NIST 800-53, NIST 800-207, CIS Controls, and defense-in-depth principles.
Preferred Qualifications
- Experience supporting highly regulated environments, critical infrastructure, energy, utility, nuclear, or government organizations.
- Experience with:
- CrowdStrike Falcon
- Tanium
- SentinelOne
- Jamf
- Workspace ONE
- ServiceNow
- Experience with cloud security integration across Microsoft 365, Azure, and AWS.
- Experience conducting threat modeling and endpoint risk assessments.
- Experience leading enterprise endpoint modernization initiatives.
Preferred Certifications
- CISSP
- Microsoft Certified: Endpoint Administrator Associate
- Microsoft Certified: Azure Security Engineer Associate
- Microsoft Certified: Security Operations Analyst Associate
- CrowdStrike Certified Falcon Administrator
- Tanium Certified Professional
- GIAC (GSEC, GCIH, GCED, GCIA)
- Microsoft Defender for Endpoint Certifications.