Endpoint Security Engineer
- Dragonfli Group
- Washington, United States
- $10,000
Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.
As an Endpoint Security Engineer, you'll design, deploy, and operationalize behavior-based endpoint detection and response (EDR/XDR) capabilities protecting one of the largest private operational fleets in North America — spanning hundreds of thousands of end-user devices, on-premise and virtual servers, and multi-cloud workloads across AWS, Azure, and GCP. You'll partner directly with application owners to tune policies and eliminate friction, while providing tier-3/tier-4 technical escalation support to SOC analysts and IT Operations during active investigations. This is a high-visibility engineering role for someone who thinks in terms of infrastructure-as-code and policy automation rather than device-by-device intervention.
This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.
Responsibilities:
- Engineer, deploy, and maintain Next-Gen Antivirus (NGAV) and EDR/XDR agents across hundreds of thousands of heterogeneous endpoints
- Implement active behavioral protections against zero-day malware, living-off-the-land binaries, fileless execution, and credential dumping
- Serve as primary technical partner to application owners and business units, establishing baseline behavior profiles to minimize false positives and operational disruption
- Manage allowlisting, exception workflows, and phased ring deployments (canary/pilot/production)
- Act as endpoint security escalation lead for SOC analysts and IT administrators during high-severity events
- Perform advanced host forensics, process-tree reconstruction, memory analysis, and script-based live remediation
- Extend endpoint security standards across private data center virtualization (VMware/Nutanix) and multi-cloud infrastructure
- Continuously validate control efficacy using automated attack simulation (BAS) tools and Purple Team exercises
- Track and report on agent health, tamper-resistance, telemetry integrity, and coverage metrics
Requirements
Must-Have:
- 7+ years of progressive experience in technical cybersecurity engineering or infrastructure security roles
- 3–5 years directly engineering and administering enterprise-grade EDR/XDR platforms across 50,000+ endpoints in a distributed hybrid environment
- Expert-level proficiency administering EDR/XDR platforms across Windows, macOS, Linux, and container runtime environments
- Deep understanding of behavioral IOAs, Sysmon telemetry, and detection authoring (SQL, KQL, Splunk SPL, or YARA)
- Strong scripting ability in PowerShell, Python, or Bash for fleet-wide remediation and automation
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or equivalent practical experience
- U.S. Citizenship or Permanent Residency; ability to work within the continental United States
Preferred / Nice-to-Have:
- GIAC Certified Enterprise Defender (GCED), GIAC Certified Incident Handler (GCIH), or GCFA
- CISSP
- Vendor credentials such as CrowdStrike Certified Falcon Administrator/Hunter or Microsoft SC-200
- Prior experience supporting active SOC investigations in large-scale enterprise environments
- Fluency applying AI/ML tooling (Splunk, Databricks, Elastic) to streamline security operations
Skill(s)
Technical Skills:
EDR/XDR engineering (CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne) · Behavioral threat hunting and detection authoring · Windows/Linux kernel internals and API hooking · Multi-cloud workload security (AWS, Azure, GCP) · PowerShell/Python/Bash automation · Host forensics and memory analysis · Attack simulation (BAS) and Purple Team exercises
Soft Skills:
Stakeholder empathy and business-impact analysis · Crisis leadership and composure under pressure · Cross-functional collaboration with SOC and IT Operations · Executive-level communication of technical risk
Benefits
Medical — Multiple POS health plan options including an HSA-compatible plan
Dental — PPO coverage for preventive, basic, and major services
Vision — Annual exam, frames, lenses, and contact lens allowance
401(k) — Employer match up to 5% of eligible compensation
Long-Term Disability — 100% employer-paid coverage at 50% of pre-disability earnings
Life Insurance & AD&D — 100% employer-paid coverage valued at $10,000 each
PTO — 15–25 days annually based on tenure
Paid Federal Holidays — All 11 federal holidays observed
Skills
- EDR/XDR
- Endpoint Security
- AWS
- Azure
- GCP
- Infrastructure as Code
- Policy Automation
