ForgeApply · Job listing
EndPoint Security Engineer
Aresmgmt
Tailor your resume for this Aresmgmt job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Aresmgmt's site. Free trial, no card required.
About this role
Over the last 20 years, Ares’ success has been driven by our people and our culture. Today, our team is guided by our core values – Collaborative, Responsible, Entrepreneurial, Self-Aware, Trustworthy – and our purpose to be a catalyst for shared prosperity and a better future. Through our recruitment, career development and employee-focused programming, we are committed to fostering a welcoming and inclusive work environment where high-performance talent of diverse backgrounds, experiences, and perspectives can build careers within this exciting and growing industry.
Job Description Cybersecurity Engineer – Infrastructure & Endpoint Security Engineer (Tech Lead)
Job Family: Cybersecurity Engineering Direct Reports: None
Position Summary:
We are seeking a n experienced Cybersecurity Engineer to serve as the technical lead for enterprise endpoint defense, Microsoft 365 collaboration security, secure browsing, endpoint privilege management , and measurable security control maturity. This role will lead the design, deployment, tuning, lifecycle management, and continuous improvement of security platforms that protect corporate endpoints, servers, Microsoft 365 collaboration services, SaaS platforms, and cloud-connected assets from advanced threats while enabling reliable and frictionless business workflows.
T his role will work closely with Security Operations, Infrastructure, Desktop Engineering, Collaboration Services, Platform Engineering, Identity, Cloud Security, Network Security, GRC, Legal, Compliance, and other cross-functional teams to ensure endpoint , Microsoft 365, SaaS, an d infrastructure security controls are secure by design, consistently deployed, operationally resilient, auditable , measurable, and aligned with enterprise security standards.
Detailed Responsibilities / Duties:
• EDR/XDR Platforms : Lead the engineering, deployment, tuning, and scaling of CrowdStrike Falcon and /or Microsoft Defender for Endpoint platforms, including EDR, host firewall , identity protection, policy management, detection tuning, and exception handling , partner ing with SOC CrowdStrike operation al leadership
• Lifecycle Management : Own endpoint security platform lifecycle management, including sensor deployment strategy, upgrade planning, health monitoring, coverage gap remediation, rollback procedures, and change management coordination , partnering with SOC and Works tation operational leadership
• Secure Browsing Architecture : Architect, engineer, and enforce enterprise-wide security policies for secure enterprise browser technologies, including solutions such as Palo Alto Prisma Access Browser , partnering network operational leadership
• Microsoft 365 Collaboration Security : Engineer and mature security controls across Exchange Online, SharePoint Online, OneDrive, Microsoft Teams, and related Microsoft 365 workloads, including external sharing governance, guest access, link-sharing controls, tenant configuration baselines, collaboration risk reduction, and secure productivity enablement.
• Privilege Management : Engineer and maintain global Endpoint Privilege Management solutions using CyberArk and/or BeyondTrust to reduce or eliminate standing local administrator rights while preserving operational continuity.
• Security Automation : Build robust automation workflows and playbooks using PowerShell, Python, APIs, or workflow platforms to streamline deployment validation, threat containment, reporting, exception review, and control compliance.
• Engineering Escalation : Act as the engineering escalation point for complex endpoint incidents, security tooling issues, agent conflicts, detection gaps, and root-cause investigations in partnership with Security Operations and Infrastructure teams.
• Posture Hardening : Develop and review baseline security configurations aligned with CIS Benchmarks, NIST guidance, and enterprise standards for Windows, macOS, and Linux endpoints. Partner with vulnerability threat management (VTM) team as they report and manage compliance in this space .
• Ecosystem Integration : Integrate endpoint telemetry with SIEM, SOAR, XDR, vulnerability management, and reporting platforms to improve detection fidelity, response readiness, and measurable control effectiveness.
• Microsoft Security & Compliance Integration : Partner on Microsoft Defender for Office 365, Microsoft Purview, audit logging, sensitivity labeling, DLP, retention, eDiscovery support, and Microsoft 365 Secure Score improvements to strengthen collaboration security and data protection outcomes.
• Documentation & Audit : Create and maintain technical documentation, runbooks, dashboards, operational procedures, and audit evidence for endpoint security controls.
Stakeholder Collaboration and Governance
• Cross-Functional Alignment : Collaborate with Security Operations, Infrastructure, Desktop Engineering, Collaboration Services, Identity, Cloud Security, Platform Engineering, Network Security, GRC, Legal, Compliance, and other cross-functional partners to implement endpoint , Microsoft 365, SaaS, and infrastructure security improvements.
• Risk Translation : Translate complex endpoint security risks, platform limitations, compliance needs, and technical issues into clear, actionable recommendations for both technical and non-technical stakeholders.
• Vendor Governance : Support vendor governance activities, including technology evaluation, roadmap alignment, service provider coordination, issue escalation, operational performance reviews, and contract or capability assessments.
• Change Management : Partner with change management, audit, and compliance teams to ensure endpoint security changes are properly assessed , documented, approved, implemented, validated , and evidenced .
• Collaboration Go
Salary insight
The midpoint of this range ($255k) is about 54% above the median disclosed salary for New York roles listed on ForgeApply ($166k across 6,609 jobs).
See full Security Engineer salary data for New York →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Aresmgmt role before you apply.
Tailor my resume for this jobSimilar jobs
- Enterprise Security Engineer — Paveakatroveinformationtechnologies · San Francisco, CA
- Enterprise Security Engineer — Gecko-robotics · Pittsburgh
- Enterprise Security Engineer — Benchling · San Francisco, CA
- Enterprise Security Engineer — Sendbird · San Mateo, California, United States
- Identity Security Engineer — Little Caesars · Detroit, MI
- Lead Security Engineer — Hinge-health · New York
- Lead Security Engineer — Alembic · San Francisco HQ
- Lead Security Engineer — Duettoresearch · United States
More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in New York · More jobs at Aresmgmt · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)