Posted 7 days ago

EndPoint Security Engineer

0200 Ares Operations LLC United States of America, New York, NY - PARK
Onsite Full Time

Job description

Over the last 20 years, Ares’ success has been driven by our people and our culture. Today, our team is guided by our core values – Collaborative, Responsible, Entrepreneurial, Self-Aware, Trustworthy – and our purpose to be a catalyst for shared prosperity and a better future. Through our recruitment, career development and employee-focused programming, we are committed to fostering a welcoming and inclusive work environment where high-performance talent of diverse backgrounds, experiences, and perspectives can build careers within this exciting and growing industry. Job Description Cybersecurity Engineer – Infrastructure & Endpoint Security Engineer (Tech Lead) Job Family: Cybersecurity Engineering Direct Reports: None Position Summary: We are seeking an experienced Cybersecurity Engineer to serve as the technical lead for enterprise endpoint defense, Microsoft 365 collaboration security, secure browsing, endpoint privilege management, and measurable security control maturity. This role will lead the design, deployment, tuning, lifecycle management, and continuous improvement of security platforms that protect corporate endpoints, servers, Microsoft 365 collaboration services, SaaS platforms, and cloud-connected assets from advanced threats while enabling reliable and frictionless business workflows. This role will work closely with Security Operations, Infrastructure, Desktop Engineering, Collaboration Services, Platform Engineering, Identity, Cloud Security, Network Security, GRC, Legal, Compliance, and other cross-functional teams to ensure endpoint, Microsoft 365, SaaS, and infrastructure security controls are secure by design, consistently deployed, operationally resilient, auditable, measurable, and aligned with enterprise security standards. Detailed

Responsibilities

/

Duties

EDR/XDR Platforms: Lead the engineering, deployment, tuning, and scaling of CrowdStrike Falcon and/or Microsoft Defender for Endpoint platforms, including EDR, host firewall, identity protection, policy management, detection tuning, and exception handling, partnering with SOC CrowdStrike operational leadership Lifecycle Management: Own endpoint security platform lifecycle management, including sensor deployment strategy, upgrade planning, health monitoring, coverage gap remediation, rollback procedures, and change management coordination, partnering with SOC and Workstation operational leadership Secure Browsing Architecture: Architect, engineer, and enforce enterprise-wide security policies for secure enterprise browser technologies, including solutions such as Palo Alto Prisma Access Browser, partnering network operational leadership Microsoft 365 Collaboration Security: Engineer and mature security controls across Exchange Online, SharePoint Online, OneDrive, Microsoft Teams, and related Microsoft 365 workloads, including external sharing governance, guest access, link-sharing controls, tenant configuration baselines, collaboration risk reduction, and secure productivity enablement. Privilege Management: Engineer and maintain global Endpoint Privilege Management solutions using CyberArk and/or BeyondTrust to reduce or eliminate standing local administrator rights while preserving operational continuity. Security Automation: Build robust automation workflows and playbooks using PowerShell, Python, APIs, or workflow platforms to streamline deployment validation, threat containment, reporting, exception review, and control compliance. Engineering Escalation: Act as the engineering escalation point for complex endpoint incidents, security tooling issues, agent conflicts, detection gaps, and root-cause investigations in partnership with Security Operations and Infrastructure teams. Posture Hardening: Develop and review baseline security configurations aligned with CIS Benchmarks, NIST guidance, and enterprise standards for Windows, macOS, and Linux endpoints. Partner with vulnerability threat management (VTM) team as they report and manage compliance in this space. Ecosystem Integration: Integrate endpoint telemetry with SIEM, SOAR, XDR, vulnerability management, and reporting platforms to improve detection fidelity, response readiness, and measurable control effectiveness. Microsoft Security & Compliance Integration: Partner on Microsoft Defender for Office 365, Microsoft Purview, audit logging, sensitivity labeling, DLP, retention, eDiscovery support, and Microsoft 365 Secure Score improvements to strengthen collaboration security and data protection outcomes. Documentation & Audit: Create and maintain technical documentation, runbooks, dashboards, operational procedures, and audit evidence for endpoint security controls. Stakeholder Collaboration and Governance Cross-Functional Alignment: Collaborate with Security Operations, Infrastructure, Desktop Engineering, Collaboration Services, Identity, Cloud Security, Platform Engineering, Network Security, GRC, Legal, Compliance, and other cross-functional partners to implement endpoint, Microsoft 365, SaaS, and infrastructure security improvements. Risk Translation: Translate complex endpoint security risks, platform limitations, compliance needs, and technical issues into clear, actionable recommendations for both technical and non-technical stakeholders. Vendor Governance: Support vendor governance activities, including technology evaluation, roadmap alignment, service provider coordination, issue escalation, operational performance reviews, and contract or capability assessments. Change Management: Partner with change management, audit, and compliance teams to ensure endpoint security changes are properly assessed, documented, approved, implemented, validated, and evidenced. Collaboration Governance: Partner with collaboration platform owners, business stakeholders, Legal, and Compliance to define and operationalize secure collaboration standards, including external sharing, guest access, sensitivity labeling, retention, and data loss prevention requirements. Mentorship: Contribute to knowledge sharing across the team and mentor others on endpoint security architecture, troubleshooting practices, control validation, automation, and operational standards. Supervisory

Responsibilities

None. This is an individual contributor role with strong expectations for technical ownership, cross-functional leadership, and mentoring through influence. Required

Qualifications

8+ years of cybersecurity, endpoint security engineering, endpoint infrastructure, or related enterprise security experience. Strong hands-on expertise with endpoint security and Microsoft security platforms such as CrowdStrike Falcon, Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Palo Alto secure access or secure browser technologies, CyberArk, and/or BeyondTrust. Strong knowledge of Windows, macOS, and Linux operating systems, including endpoint hardening, troubleshooting, agent behavior, security baselines, and enterprise-scale deployment considerations. Strong understanding of endpoint networking, TLS traffic flows, proxy behavior, host firewall behavior, and how endpoint security controls interact across endpoint, network, cloud, identity, and SaaS environments.

Experience

with enterprise endpoint management and deployment tools such as Microsoft Intune, MECM/SCCM, Group Policy, Jamf, or equivalent platforms. Familiarity with cybersecurity controls for Microsoft 365 collaboration services, SaaS platforms, Microsoft Entra ID, Azure environments, conditional access, device posture, and Zero Trust concepts.

Experience

securing or governing Microsoft 365 collaboration workloads such as Exchange Online, SharePoint Online, OneDrive, and Microsoft Teams, including external sharing, guest access, permissions, audit logs, and data protection controls.

Experience

with endpoint firewall products, vulnerability management processes, patch coordination, and basic network security principles. Deep critical-thinking skills with the ability to analyze detections, diagnose complex endpoint issues, distinguish true threats from false positives, and drive root-cause resolution under pressure. Demonstrated ability to identify repeatable operational work and implement automation using scripting, APIs, workflows, or infrastructure-as-code concepts.

Experience

developing endpoint security metrics, dashboards, compliance reports, exception tracking, or control effectiveness reporting. Effective communication and collaboration skills with the ability to work across technical and non-technical stakeholder groups.

Preferred Qualifications

Relevant certifications such as CrowdStrike Certified Falcon Administrator, GIAC, CISSP, Microsoft Security certifications, Azure Security Engineer Associate, or CyberArk/BeyondTrust platform certifications.

Experience

with PowerShell, Python, REST APIs, Microsoft Graph API, workflow automation, or configuration-as-code approaches.

Experience

with Microsoft Graph API, SharePoint Online Management Shell, Exchange Online PowerShell, Teams administration, or Microsoft 365 security and compliance automation.

Experience

integrating endpoint security telemetry with corporate SIEM, SOAR, XDR, case management, vulnerability management, or data analytics ecosystems.

Experience

implementing or supporting Microsoft 365 data protection capabilities such as sensitivity labels, DLP, retention policies, eDiscovery workflows, audit logging, Safe Links, Safe Attachments, and collaboration security reporting.

Experience

supporting endpoint security controls in regulated, audit-driven, or financial-services environments. Familiarity with Zero Trust security principles, identity-based access control, device posture, conditional access, and secure access service edge concepts. Leadership

Qualifications

Strong sense of ownership, accountability, and attention to detail. Ability to lead through influence, establish technical direction, and drive execution across cross-functional teams without direct reporting authority. Proven ability to develop structured processes that improve consistency, scalability, auditability, measurability, and operational efficiency. Ability to manage competing priorities and deliver reliable outcomes in a dynamic enterprise environment. Strong technical judgment and ability to balance security risk, operational stability, user experience, and business impact. Strong communication skills for bridging technical and business perspectives, including the ability to present risks, tradeoffs, and recommendations to leadership. Curiosity and growth mindset, with the ability to adapt to evolving endpoint, cloud, identity, AI, and threat landscapes.

Education

Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field preferred. Equivalent hands-on technical experience, relevant cybersecurity training, or nontraditional educational paths will also be considered. Reporting Relationships Compensation The anticipated base salary range for this position is listed below. Total compensation may also include a discretionary performance-based bonus. Note, the range takes into account a broad spectrum of qualifications, including, but not limited to, years of relevant work experience, education, and other relevant qualifications specific to the role. $240,000 - $270,000 The firm also offers robust

Benefits

offerings. Ares U.S. Core

Benefits

include Comprehensive Medical/Rx, Dental and Vision plans; 401(k) program with company match; Flexible Savings Accounts (FSA); Healthcare Savings Accounts (HSA) with company contribution; Basic and Voluntary Life Insurance; Long-Term Disability (LTD) and Short-Term Disability (STD) insurance; Employee Assistance Program (EAP), and Commuter

Benefits

plan for parking and transit. Ares offers a number of additional benefits including access to a world-class medical advisory team, a mental health app that includes coaching, therapy and psychiatry, a mindfulness and wellbeing app, financial wellness benefit that includes access to a financial advisor, new parent leave, reproductive and adoption assistance, emergency backup care, matching gift program, education sponsorship program, and much more. There is no set deadline to apply for this job opportunity. Applications will be accepted on an ongoing basis until the search is no longer active. Ares Management Corporation (NYSE: ARES) is a leading global alternative investment manager offering clients complementary primary and secondary investment solutions across the credit, real estate, private equity and infrastructure asset classes. We seek to provide flexible capital to support businesses and create value for our stakeholders and within our communities. By collaborating across our investment groups, we aim to generate consistent and attractive investment returns throughout market cycles. As of March 31, 2026, Ares Management's global platform had approximately $644 billion of assets under management(1) with more than 4,400 employees operating across North America, South America, Europe, Asia Pacific and the Middle East. For more information, please visit www.aresmgmt.com. Ares Management LLC (together with its related operating and administrative subsidiaries, “Ares Management”) is an Equal Employment Opportunity employer and considers all applicants for employment without regard to race, color, religion, ethnicity, creed, sex, age, national origin, alienage or citizenship status, disability, medical condition, pregnancy, marital status, partnership status, sexual orientation, status regarding public assistance, military or veteran status, domestic violence victim status, gender identity and expression, transgender status, genetic information, status as unemployed, political affiliation or any other characteristic protected by federal, state or local law. Ares Management will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the Fair Chance Initiative for Hiring Ordinance. (1) As of March 31, 2026. AUM amounts include funds managed by Ivy Hill Asset Management, LP., a wholly owned portfolio company of Ares Capital Corporation and registered investment adviser.

Skills and functions

  • Azure
  • Data Analytics
  • Python