Sr Endpoint Security Engineer

Stefanini GroupNew York, NY
Remote

About The Position

Stefanini Group is looking for a Sr Endpoint Security Engineer for a globally recognized company! We're looking for a Senior Endpoint Security Engineer to own and evolve our endpoint security and identity ecosystem across a modern, cloud-first environment. This is a high-impact role where you'll lead strategy and hands-on execution across: macOS endpoint management (Jamf Pro), Apple Business Manager, Identity platforms (Entra ID, Okta, Google Workspace), and EDR/XDR (CrowdStrike or similar, including managed SOC integrations). You'll help drive Zero Trust architecture, automate device lifecycle management, and improve enterprise security posture at scale.

Requirements

  • 5+ years in endpoint security or endpoint engineering
  • Strong hands-on experience with: Jamf Pro (macOS management is a must)
  • Apple Business Manager
  • CrowdStrike or similar EDR/XDR
  • Identity platform experience: Entra ID (Azure AD)
  • Okta
  • Experience in Google Workspace environments
  • Solid understanding of Zero Trust and endpoint security frameworks
  • Scripting: Python, Bash, or PowerShell

Nice To Haves

  • Jamf / CrowdStrike / Okta certifications
  • Experience with MDR/MSSP environments
  • SIEM tools (Splunk, Sentinel)
  • Experience in SOX-compliant environments
  • API integrations across security platforms

Responsibilities

  • Own and manage Jamf Pro for macOS fleet (configuration, compliance, patching)
  • Lead Apple Business Manager integration for automated device enrollment & lifecycle
  • Implement endpoint hardening (CIS benchmarks, encryption, policy enforcement)
  • Deploy & optimize CrowdStrike (or equivalent EDR/XDR)
  • Partner with MDR/MSSP providers for 24/7 threat coverage
  • Investigate alerts, tune detections, and improve response playbooks
  • Integrate and manage: Microsoft Entra ID (Azure AD), Okta (SSO, MFA, lifecycle), Google Workspace (existing identity layer)
  • Build conditional access policies tied to device posture
  • Enable seamless SSO and identity federation
  • Automate provisioning/deprovisioning across Jamf, Okta, Entra ID, Google Workspace
  • Build scripts (Python/Bash) and API integrations
  • Integrate with SIEM/SOAR platforms (e.g., Sentinel, Splunk)
  • Support SOX / SOC 2 / ISO audit readiness
  • Maintain endpoint and identity security documentation
  • Deliver reporting on device compliance, vulnerabilities, and incidents
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service