Principal EDR Engineer
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
Job Description:
Quevera is seeking a Principal EDR Engineer with an active TS/SCI clearance with Polygraph to support the National Security Agency’s Enterprise Endpoint Detection and Response (EDR) Program in Fort Meade, Maryland. Operating within a highly classified, multi-domain infrastructure, you will serve as a principal technical leader and subject matter expert responsible for strengthening endpoint visibility, threat containment, and configuration resilience across enterprise and mission-critical assets.
In this role, you will lead the architecture, integration, deployment, optimization, and lifecycle engineering of Microsoft Defender for Endpoint (MDE) and Trellix HX across on-premises, cloud, virtual desktop infrastructure, air-gapped, and other highly restricted environments. You will bridge enterprise systems architecture with operational cyber defense capabilities to protect national security infrastructure against sophisticated cyber threats.
As a Principal EDR Engineer, you will advise Government stakeholders on system risks and engineering decisions, collaborate with threat-hunting and intelligence teams, provide advanced support during critical incidents, and mentor junior and mid-level engineering personnel across the program.
Job Responsibilities:
- Lead the lifecycle engineering, architecture, integration, deployment, and optimization of enterprise EDR capabilities.
- Design and implement scalable Microsoft Defender for Endpoint and Trellix HX architectures across hybrid enterprise environments.
- Develop complex systems-engineering, architecture, deployment, and implementation plans.
- Engineer and manage MDE deployments using Microsoft Endpoint Configuration Manager (MECM/SCCM) or Microsoft Intune.
- Develop and maintain MDE policy rings, agent configurations, exclusion policies, and endpoint-health monitoring capabilities.
- Engineer, deploy, and manage Trellix HX controllers and agents within air-gapped and highly restricted networks.
- Monitor endpoint health, agent performance, policy compliance, and platform coverage at enterprise scale.
- Tune endpoint-security configurations and exclusions to reduce operational friction while maintaining effective security controls.
- Collaborate with threat-hunting and intelligence analysts to translate actionable threat intelligence into technical detection capabilities.
- Develop custom indicators of compromise using Kusto Query Language (KQL), OpenIOC, and YARA rules.
- Provide advanced endpoint forensic and engineering support to Security Operations Center personnel during critical, high-priority incidents.
- Analyze endpoint behavior across Windows, Linux, and macOS operating systems.
- Advise Government stakeholders on system risks, architecture decisions, implementation strategies, and engineering considerations.
- Apply defense-in-depth principles to endpoint-security architecture and configuration management.
- Develop and maintain systems-engineering documentation, implementation plans, technical standards, and architecture artifacts.
- Mentor junior and mid-level engineers and contribute to the development of technical leadership across the program.
Minimum Requirements:
- Active TS/SCI clearance with Polygraph required.
- Twenty (20) years of experience as a Systems Engineer supporting programs and contracts of similar scope, type, and complexity.
- Demonstrated experience planning and leading systems-engineering efforts.
- Proven engineering experience with Microsoft Defender for Endpoint architecture and enterprise deployment.
- Experience deploying MDE through MECM/SCCM or Microsoft Intune.
- Experience managing MDE policies, deployment rings, endpoint configurations, exclusions, and advanced hunting capabilities.
- Experience developing advanced hunting queries using Kusto Query Language.
- Experience engineering, deploying, and managing Trellix HX controllers and agents.
- Experience supporting Trellix HX within air-gapped or highly restricted network environments.
- Experience c