Endpoint Security Engineer

VailexaBoise, ID

About The Position

At Vailexa, we’re not just hiring — we’re building thinkers, creators, and future leaders. We believe in giving people the space to grow, the freedom to think, and the opportunity to create real impact from day one. If you’re someone who wants to learn fast, take ownership, and grow beyond limits, you’ll feel right at home here.

Requirements

  • 5+ years of hands-on experience in endpoint security, security engineering, or a closely related IT security role.
  • Working proficiency with at least one major EDR/EPP platform, including policy configuration and detection investigation.
  • Practical experience with Beyond Trust privilege management (or a comparable PAM/endpoint privilege solution) and least-privilege enforcement.
  • Solid understanding of PKI concepts and operational experience with certificate lifecycle management.
  • Experience managing endpoints and mobile devices with Microsoft Intune (compliance, configuration, app protection).
  • Demonstrated experience applying endpoint hardening frameworks such as CIS Benchmarks or DISA STIGs.
  • Strong knowledge of Windows endpoint internals; familiarity with macOS and mobile (iOS/Android) management.
  • Comfortable scripting for automation and reporting (PowerShell preferred; Python a plus).

Nice To Haves

  • Experience with Microsoft Entra ID (Azure AD) and Conditional Access.
  • Familiarity with SIEM/log analysis and integrating endpoint telemetry into detection workflows.
  • Exposure to Group Policy, Configuration Manager (SCCM), or other configuration management tooling.
  • Relevant certifications: Security+, GCED, GCWN, Microsoft SC-200 / MD-102, CrowdStrike CCFA, or Beyond Trust certifications.
  • Understanding of compliance and regulatory frameworks (NIST 800-53, ISO 27001) as they apply to endpoints.

Responsibilities

  • Administer and tune EDR/EPP platforms (e.g., CrowdStrike, Microsoft Defender for Endpoint, SentinelOne) — manage policies, investigate detections, and support response.
  • Operate and maintain privileged access controls using BeyondTrust (Privilege Management / Endpoint Privilege Management), enforcing least-privilege and managing application elevation policies.
  • Support PKI operations — certificate issuance, renewal, revocation, and troubleshooting for endpoint authentication, code signing, and encryption use cases.
  • Manage mobile and modern device security through Microsoft Intune — compliance policies, configuration profiles, app protection, and conditional access integration.
  • Build, apply, and validate endpoint hardening baselines (CIS Benchmarks, DISA STIGs, vendor best practices) across Windows, macOS, and mobile platforms.
  • Monitor for vulnerabilities and misconfigurations, coordinate remediation, and verify patch and configuration compliance.
  • Document standards, runbooks, and operational procedures; partner with SOC, IT, and infrastructure teams on incidents and escalations.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service