Head of Endpoint Defense

KyndrylRye Brook, WA
$115,080 - $218,520

About The Position

Leads Kyndryl's endpoint defense function, owning the operation, tuning, and coverage of the endpoint detection and response estate across Palo Alto Cortex XDR, Microsoft Defender for Endpoint, Trend Micro, and additional endpoint tooling. Ensures consistent prevention, detection, and telemetry quality across a heterogeneous, multi-vendor fleet, and that endpoint signal feeds the detection pipeline cleanly. Runs the function as a platform service to Cyber Defense, not as an independent detection authority.

Requirements

  • Mastery of security tools and technologies, such as firewalls, intrusion detection/prevention systems, endpoint security, , and SIEM solutions
  • Deep understanding of operating systems (e.g., Windows, Linux) and their security mechanisms
  • Knowledge of security standards and compliance requirements (e.g., ISO 27001, NIST, GDPR)
  • Experience with key market leading technologies in the relevant area
  • Ability to assess and follow best practices in technology deployment and configuration
  • Experience with the design and implementation of security architectures, segmentation and zero trust frameworks

Nice To Haves

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or other related fields
  • Experience with workload, server, network architectures and associated security controls

Responsibilities

  • Own operations, policy, and health for the endpoint defense estate: Cortex XDR, Microsoft Defender for Endpoint, Trend Micro, and other endpoint tooling.
  • Drive agent coverage, deployment, and configuration integrity across the managed fleet, closing gaps in visibility.
  • Tune prevention and detection policy to balance efficacy against operational disruption, in partnership with Cyber Defense and SIEM/SOAR.
  • Rationalize the multi-vendor endpoint stack toward consistent coverage and reduced overlap, with a defensible consolidation or coexistence posture.
  • Ensure endpoint telemetry is complete, timely, and correctly integrated into XSIAM and the detection pipeline.
  • Support incident response with endpoint containment, isolation, and forensic data on demand from the Incident Commander.
  • Drive automation for agent deployment, health monitoring, policy management, remediation actions, and telemetry quality to reduce operational overhead and improve response times.
  • Establish and report on endpoint security KPIs, including coverage, agent health, prevention efficacy, telemetry quality, containment performance, and remediation outcomes.
  • Lead and develop the endpoint defense team.

Benefits

  • medical and dental coverage
  • disability
  • retirement benefits
  • paid leave
  • paid time off
  • Kyndryl’s discretionary annual bonus program
  • comprehensive benefits package
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service