Base Career helps you apply smarter for this job.
Key skills for this role
This position will support the United States Postal Service (USPS).
GDIT is seeking an experienced Endpoint Security Engineer (Hybrid Multi-Cloud) to join our dynamic team.
Clearance Level Must Currently Possess:
Clearance Level Must Be Able to Obtain:
Job Family:
Job Description:
This position will support the United States Postal Service (USPS). GDIT is seeking an experienced Endpoint Security Engineer (Hybrid Multi-Cloud) to join our dynamic team.
As an Endpoint Security Engineer, you will design, deploy, and operationalize active, behavior-based endpoint detection and response (EDR/XDR) capabilities across one of the largest private operational fleets in North America. Protecting an enterprise comprising 600,000+ employees and 30,000+ physical sites, you will maintain rigorous security posture across traditional end-user computing (EUC) devices (laptop, desktop, mobile devices & retail terminals), on-premises physical & virtual servers & containerized workloads, and dynamic multi-cloud workloads (AWS, Azure, GCP).
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
, USA
, USA
, USA
, USA
, USA
, USA
, USA
, USA
Bachelor's Degree in Computer Science or related technical discipline, preferred but not required.
NOTE: If resources do not have a relevant college degree, an additional 4 years of relevant work experience is required.
8+ years of progressive experience in technical cybersecurity engineering or infrastructure security roles.
3–5 years of experience directly engineering and administering enterprise-grade EDR/XDR platforms across 50,000+ endpoints in a distributed hybrid environment.
Demonstrated track record supporting active SOC investigations and collaborating cross-functionally with system owners in large-scale enterprise environments.
EDR/XDR Engineering: Expert-level proficiency administering enterprise-scale endpoint platforms across Windows, macOS, Linux distributions, and container runtime environments.
Behavioral Analysis & Threat Hunting: Deep mastery of process lineage, behavioral IOAs (Indicators of Attack), Sysmon telemetry, and detection authoring using query languages such as SQL, KQL (Kusto Query Language) , Splunk SPL , or YARA .
Hybrid Infrastructure & OS Internals: Deep understanding of Windows/Linux kernel architectures, API hooking, hypervisor isolation, and multi-cloud workload identity integrations.
Automation & Scripting: Strong programming/scripting abilities in PowerShell , Python , or Bash to orchestrate fleet-wide remediations and automate policy compliance at scale.
Artificial Intelligence & Machine Learning : Fluency applying appropriate AI/ML technologies and analytics platforms (Splunk, Databricks, Elastic) to streamline and/or automate activities including but not limited to research, developing documentation, and supporting development of executive communications. Fluency applying appropriate AI/ML technologies to automate security activities to improve timeliness or full automation of event response activities.
Abilities & Core Competencies
Stakeholder Empathy & Impact Analysis: Proven ability to balance stringent security controls with business operational velocity, ensuring minimal disruption to end-user productivity and mission-critical COTS/proprietary software.
Crisis Leadership & Composure: Capable of methodically triaging active enterprise threats under pressure and articulating complex host-based attacks to executive leadership.
Operational Scale Management: Mindset geared toward "Infrastructure-as-Code" and policy automation rather than manual device-by-device intervention.
GIAC Certified Enterprise Defender (GCED) , GIAC Certified Incident Handler (GCIH) , or GCFA (Forensic Analyst) .
CISSP (Certified Information Systems Security Professional).
Specialized Vendor Engineering Credentials (e.g., CrowdStrike Certified Falcon Administrator/Hunter , Microsoft Certified: Security Operations Analyst Associate / SC-200 ).
Ability to obtain and maintain a Public Trust clearance and successfully pass a thorough Government background screening process requiring the completion of detailed forms and fingerprinting.
This position has a U.S. residency requirement. The USPS security clearance process requires the selected candidate to have resided in the U.S. (including U.S. Territories) for the last five years as follows: U.S. Citizens cannot have left the U.S. (including U.S. Territories) for longer than 6 months consecutively in the last 3 years (unless they meet certain exceptions). Non-U.S. Citizens cannot have left the U.S. (including U.S. Territories) for longer than 90 days consecutively in the last 3 years.
401K with company match
Comprehensive health and wellness packages
Internal mobility team dedicated to helping you own your career
Professional growth opportunities including paid education and certifications
Cutting-edge technology you can learn from
Rest and recharge with paid vacation and holidays
#zxc726
Scheduled Weekly Hours:
Work Location:
Additional Work Locations:
gdit.com/tc .
Verified company details for this employer are not available yet.
USD 96569-130651 yearly / year
Full-time
Senior · 8+ years experience
Remote
Apply faster on company sites with our extension.