The role involves deploying and maintaining endpoint security controls like EDR/XDR agents across Windows, Linux, and macOS environments. You will also automate administrative tasks, monitor telemetry health, and collaborate with IT and security teams to harden systems and respond to incidents.
We are looking for a hands-on Endpoint & Security Platforms Engineer to build and operate the controls that protect our employee devices and server workloads, working across the full lifecycle from deployment and hardening to troubleshooting, automation, and authorized containment.
This is a chance to influence technical decisions that improve protection without disrupting critical services, and to broaden your engineering skills through hands-on work with security platforms and automation. You will work closely with IT, Infrastructure, Cyber Defense, and data security colleagues to make protection reliable and effective without creating unnecessary friction for users or critical systems.
Responsibilities
Deploy and maintain EDR/XDR agents and endpoint protection policies across Windows, Linux, and macOS workstations and production servers, managing the full agent lifecycle: upgrades, policy tuning, exclusions, and controlled rollback
Resolve agent failures, telemetry gaps, policy conflicts, and performance issues. Coordinate deployments with IT, which provides first-line support, and take ownership of complex security cases
Implement risk-based OS hardening baselines together with application and infrastructure owners: test compatibility, prepare rollback steps, and deploy changes safely across production systems
Operate endpoint DLP controls: maintain agents, implement policies agreed with data security colleagues, and reduce unnecessary blocking without weakening protection
Maintain assigned security platforms (e.g. SIEM), including service health, access configuration, updates, storage, backups, and recovery
Monitor telemetry and control health, investigating stale agents, coverage gaps, and unmanaged systems, and drive fixes through automation and improved runbooks
Support Cyber Defense investigations with endpoint expertise and execute approved containment actions, escalating anything that could disrupt production
Automate recurring administration, validation, and reporting tasks using scripts and APIs, and maintain clear documentation for configurations and procedures
Requirements
4+ years of hands-on experience in endpoint security, infrastructure security, system security, or a related security engineering role
Practical experience deploying and operating an enterprise EDR/XDR or endpoint protection platform across a mixed workstation and server environment
Strong Linux administration skills, plus the ability to support and troubleshoot protection on Windows workstations and servers using logs, services, permissions, network connections, and resource usage
Experience introducing security controls into production, including testing, controlled deployment, and rollback
Experience implementing OS hardening and working with native security controls
Understanding of access-control models, least privilege, endpoint telemetry, file-integrity monitoring, and host-isolation techniques
Ability to automate operational work using at least one scripting language such as Python, Bash, or PowerShell
Clear communication with technical colleagues and system owners, reliable documentation, and the ability to follow issues through to a verified result
Upper-Intermediate English
Fluent Ukrainian
Will be a plus
Experience administering a self-managed Elastic or another SIEM platform
Experience with endpoint DLP solutions or Microsoft Defender
macOS security and device-management tools such as Mosyle, ManageEngine, Ansible, or Puppet
Experience with CIS Benchmarks, DISA STIG, or native OS security controls (SELinux, AppArmor, FileVault, BitLocker, etc.)
Experience supporting a large, distributed fleet of endpoints or servers, ideally in fintech, trading, or another performance-critical environment
Technical education in Information Security, Computer Science, or a related field
We offer
20 paid vacation days per year
10 paid sick leave days per year
Public holidays according to the company’s approved holiday calendar
Medical budget
Remote work
Professional education budget
Language-learning budget
Wellness budget covering gym membership, sports equipment, and related expenses
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”