Endpoint Security Engineer

Vailexa

Boise, ID

JOB DETAILS
SKILLS
Access Control, Analysis Skills, Android, Applications Security, Authentication, Benchmarking, Best Practices, Certificate Issuance, CompTIA Security+, Computer Security, Configuration Management, Cryptography, Defense Information Systems Agency (DISA), Digital Certificates, Documentation Standards, Endpoint Security, GCWN - GIAC Certified Windows Security Administrator, ISO (International Organization for Standardization), Identify Issues, Mac Operating System, Machine Tool, Microsoft Access Database, Microsoft Product Family, Microsoft Windows Azure, Microsoft Windows Operating System, Microsoft Windows System Internals/Programming, Mobile Devices, Operational Support, Operations Processes, Public Key Infrastructure (PKI), Python Programming/Scripting Language, Regulatory Compliance, Scripting (Scripting Languages), Security Information and Event Management (SIEM), System Center Configuration Manager (SCCM), Telemetry, U.S. National Institute of Standards and Technology (NIST), Use Cases, Windows PowerShell, iOS
LOCATION
Boise, ID
POSTED
Today
Build More Than Just a Career. Build Your Future.

At Vailexa, we're not just hiring — we're building thinkers, creators, and future leaders.

We believe in giving people the space to grow, the freedom to think, and the opportunity to create real impact from day one. If you're someone who wants to learn fast, take ownership, and grow beyond limits, you'll feel right at home here.

KEY RESPONSIBILITIES

  • Endpoint Detection & Response: Administer and tune EDR/EPP platforms (e.g., CrowdStrike, Microsoft Defender for Endpoint, SentinelOne) — manage policies, investigate detections, and support response.
  • Privilege & PAM: Operate and maintain privileged access controls using BeyondTrust (Privilege Management / Endpoint Privilege Management), enforcing least-privilege and managing application elevation policies.
  • PKI & Certificates: Support PKI operations — certificate issuance, renewal, revocation, and troubleshooting for endpoint authentication, code signing, and encryption use cases.
  • Mobile / Intune: Manage mobile and modern device security through Microsoft Intune — compliance policies, configuration profiles, app protection, and conditional access integration.
  • Hardening: Build, apply, and validate endpoint hardening baselines (CIS Benchmarks, DISA STIGs, vendor best practices) across Windows, macOS, and mobile platforms.
  • Vulnerability & Compliance: Monitor for vulnerabilities and misconfigurations, coordinate remediation, and verify patch and configuration compliance.
  • Collaboration & Documentation: Document standards, runbooks, and operational procedures; partner with SOC, IT, and infrastructure teams on incidents and escalations.

 

REQUIRED SKILLS & EXPERIENCE

  • 5+ years of hands-on experience in endpoint security, security engineering, or a closely related IT security role.
  • Working proficiency with at least one major EDR/EPP platform, including policy configuration and detection investigation.
  • Practical experience with Beyond Trust privilege management (or a comparable PAM/endpoint privilege solution) and least-privilege enforcement.
  • Solid understanding of PKI concepts and operational experience with certificate lifecycle management.
  • Experience managing endpoints and mobile devices with Microsoft Intune (compliance, configuration, app protection).
  • Demonstrated experience applying endpoint hardening frameworks such as CIS Benchmarks or DISA STIGs.
  • Strong knowledge of Windows endpoint internals; familiarity with macOS and mobile (iOS/Android) management.
  • Comfortable scripting for automation and reporting (PowerShell preferred; Python a plus).

 

PREFERRED / NICE TO HAVE

  • Experience with Microsoft Entra ID (Azure AD) and Conditional Access.
  • Familiarity with SIEM/log analysis and integrating endpoint telemetry into detection workflows.
  • Exposure to Group Policy, Configuration Manager (SCCM), or other configuration management tooling.
  • Relevant certifications: Security+, GCED, GCWN, Microsoft SC-200 / MD-102, CrowdStrike CCFA, or Beyond Trust certifications.
  • Understanding of compliance and regulatory frameworks (NIST 800-53, ISO 27001) as they apply to endpoints.

Ready to take the next step?

If you're excited about this role and ready to grow with a team that values ambition, ideas, and impact — we'd love to hear from you.

 Apply now and start building your journey with Vailexa.

About the Company

V

Vailexa