Job Description – Manager, Security Engineering (Systems & Endpoint Security)
Role Summary
The Manager, Security Engineering (Systems & Endpoint Security) is responsible for leading and overseeing enterprise-scale security engineering functions across endpoint, identity, and systems security platforms. This role owns the design, engineering, deployment, and lifecycle management of critical security controls including Microsoft Exchange Online Protection (EOP), SCCM-based agent deployment, IAM solution agents, and SentinelOne endpoint protection.
The role provides technical leadership, operational governance, and delivery accountability to ensure secure, scalable, and compliant rollout of security agents and controls across the enterprise, aligned with Zero Trust principles and regulatory requirements.
Key Responsibilities
Security Engineering Leadership
- Lead and manage systems and endpoint security engineering teams, providing technical direction, mentoring, and performance oversight.
- Drive people management activities including hiring, performance management, coaching, and team development.
- Own engineering standards, deployment models, and operational readiness for systems security platforms.
- Act as the primary escalation point for endpoint and identity security initiatives.
Endpoint & Systems Security Platforms
- Oversee enterprise engineering and rollout of SentinelOne endpoint protection agents, ensuring coverage, health, policy compliance, and performance optimization.
- Lead Microsoft SCCM / Endpoint Configuration Manager-based deployment of security agents, endpoint patching, and system hardening controls.
- Drive enterprise-level endpoint patch management strategy, ensuring timely remediation of vulnerabilities and compliance with security standards.
- Manage Microsoft Exchange Online Protection (EOP) for advanced email threat protection.
- Ensure seamless deployment and integration of IAM solution agents including PAM and IGA tools.
Identity, Directory & Infrastructure Security
- Administer and secure Active Directory environments including domain controller management, replication, and hardening.
- Design and enforce Group Policy Objects (GPOs) for secure configuration and endpoint compliance.
- Manage and secure Azure Active Directory (Microsoft Entra ID), including identity governance and conditional access policies.
- Ensure alignment of identity and endpoint controls with Zero Trust and least privilege principles.
Architecture, Design & Standards
- Define and enforce secure engineering architectures, deployment patterns, and configuration baselines.
- Partner with Security Architecture, IAM, Cloud, and Infrastructure teams to align security solutions.
- Develop and maintain SOPs, runbooks, engineering standards, and design documentation.
Operational Excellence & Risk Management
- Ensure availability, reliability, and scalability of systems security platforms.
- Identify and remediate agent deployment gaps, vulnerabilities, and configuration drift.
- Support security incidents, endpoint investigations, and forensic activities.
- Drive automation initiatives using scripting and APIs to improve operational efficiency.
Required Skills & Experience
- 12–18 years of experience in security engineering, systems security, or endpoint security.
- 5+ years of experience in engineering leadership or people management roles.
- Hands-on and architectural expertise in:
- SentinelOne Endpoint Protection
- Microsoft SCCM / Endpoint Configuration Manager
- Microsoft Exchange Online Protection (EOP)
- IAM agent integrations (PAM, IGA)
- Strong expertise in:
- Active Directory (AD) administration and security
- Group Policy Object (GPO) design and enforcement
- Domain Controller management and hardening
- Azure Active Directory (Microsoft Entra ID)
- Enterprise endpoint patch management
- Strong knowledge of Windows environments and endpoint hardening practices.
- Experience with scripting and automation using PowerShell or APIs.
Preferred Qualifications
- Experience working in healthcare or other highly regulated environments.
- Exposure to Zero Trust architecture and endpoint security transformation programs.
- Relevant certifications such as CISSP, Microsoft Security, Azure Security, or endpoint security certifications.
Leadership & Behavioral Competencies
- Strong engineering judgment with the ability to balance security, stability, and scalability.
- Ability to translate business and risk requirements into actionable engineering solutions.
- Excellent communication skills with both technical and executive stakeholders.
- Ownership mindset with a strong focus on execution, resilience, and accountability.