ForgeApply
Try it free

ForgeApply · Job listing

EndPoint Security Engineer

Aresmgmt

New York, NY | Los Angeles, US$240k – $270konsite

Tailor your resume for this Aresmgmt job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Aresmgmt's site. Free trial, no card required.

About this role

Over the last 20 years, Ares’ success has been driven by our people and our culture. Today, our team is guided by our core values – Collaborative, Responsible, Entrepreneurial, Self-Aware, Trustworthy – and our purpose to be a catalyst for shared prosperity and a better future. Through our recruitment, career development and employee-focused programming, we are committed to fostering a welcoming and inclusive work environment where high-performance talent of diverse backgrounds, experiences, and perspectives can build careers within this exciting and growing industry.

Job Description Cybersecurity Engineer –   Infrastructure &   Endpoint Security Engineer   (Tech Lead)  

Job Family: Cybersecurity Engineering   Direct Reports:   None  

Position Summary:

We are seeking a n   experienced   Cybersecurity   Engineer to   serve as the technical   lead   for enterprise   endpoint defense,   Microsoft 365 collaboration security,   secure browsing,   endpoint   privilege management , and measurable   security   control maturity. This role will lead the design, deployment, tuning, lifecycle management, and continuous improvement of   security platforms that protect corporate endpoints, servers,   Microsoft 365 collaboration services, SaaS platforms,   and cloud-connected assets from advanced threats while enabling reliable and frictionless business workflows.  

T his role will   work   closely with Security Operations, Infrastructure,   Desktop Engineering,   Collaboration Services,   Platform Engineering, Identity, Cloud Security, Network Security,   GRC,   Legal, Compliance,   and other cross-functional teams to ensure endpoint , Microsoft 365, SaaS,   an d   infrastructure   security controls are   secure by design, consistently deployed, operationally resilient, auditable , measurable,   and aligned with enterprise security standards.  

Detailed Responsibilities / Duties:

• EDR/XDR Platforms : Lead the engineering, deployment, tuning, and scaling of CrowdStrike Falcon and /or   Microsoft Defender for Endpoint platforms, including EDR, host   firewall , identity protection, policy management, detection tuning, and exception handling , partner ing   with SOC CrowdStrike operation al leadership  

• Lifecycle Management :   Own   endpoint security platform lifecycle management, including sensor deployment strategy, upgrade planning, health monitoring, coverage gap remediation, rollback procedures, and change management coordination ,   partnering with SOC   and Works tation   operational leadership    

• Secure Browsing Architecture : Architect, engineer, and enforce enterprise-wide security policies for secure enterprise browser technologies, including solutions such as Palo Alto Prisma Access Browser ,   partnering   network   operational   leadership  

• Microsoft 365 Collaboration Security : Engineer and mature security controls across Exchange Online, SharePoint Online, OneDrive, Microsoft Teams, and related Microsoft 365 workloads, including external sharing governance, guest access, link-sharing controls, tenant configuration baselines, collaboration risk reduction, and secure productivity enablement.  

• Privilege Management : Engineer and   maintain   global Endpoint Privilege Management solutions using CyberArk and/or   BeyondTrust   to reduce or   eliminate   standing local administrator rights while preserving operational continuity.  

• Security Automation : Build robust automation workflows and playbooks using PowerShell, Python, APIs, or workflow platforms to streamline deployment validation, threat containment, reporting, exception review, and control compliance.  

• Engineering Escalation : Act as the engineering escalation point for complex endpoint incidents, security tooling issues, agent conflicts, detection gaps, and root-cause investigations in partnership with Security Operations and Infrastructure teams.  

• Posture Hardening : Develop and   review   baseline security configurations aligned with CIS Benchmarks, NIST guidance, and enterprise standards for Windows, macOS, and Linux endpoints.   Partner with   vulnerability threat management (VTM) team as they report and manage compliance in this space .  

• Ecosystem Integration : Integrate endpoint telemetry with SIEM, SOAR, XDR, vulnerability management, and reporting platforms to improve   detection   fidelity, response readiness, and measurable control effectiveness.  

• Microsoft Security & Compliance Integration : Partner on Microsoft Defender for Office 365, Microsoft Purview, audit logging, sensitivity labeling, DLP, retention, eDiscovery support, and Microsoft 365 Secure Score improvements to strengthen collaboration security and data protection outcomes.  

• Documentation & Audit : Create and   maintain   technical documentation, runbooks, dashboards, operational procedures, and audit evidence for endpoint security controls.  

Stakeholder Collaboration and Governance  

• Cross-Functional Alignment : Collaborate with   Security Operations, Infrastructure, Desktop Engineering,   Collaboration Services,   Identity, Cloud Security, Platform Engineering, Network Security, GRC,   Legal, Compliance,   and other cross-functional   partners to implement endpoint , Microsoft 365, SaaS, and infrastructure   security improvements.  

• Risk Translation : Translate complex endpoint security risks, platform limitations, compliance needs, and technical issues into clear, actionable recommendations for both technical and non-technical stakeholders.  

• Vendor Governance : Support vendor governance activities, including technology evaluation, roadmap alignment, service provider coordination, issue escalation, operational performance reviews, and contract or capability assessments.  

• Change Management : Partner with change management, audit, and compliance teams to ensure endpoint security changes are   properly assessed , documented, approved, implemented,   validated , and   evidenced .  

• Collaboration Go

Salary insight

The midpoint of this range ($255k) is about 54% above the median disclosed salary for New York roles listed on ForgeApply ($166k across 6,609 jobs).

See full Security Engineer salary data for New York

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this Aresmgmt role before you apply.

Tailor my resume for this job

Similar jobs

More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in New York · More jobs at Aresmgmt · Browse all jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)