Principal EDR Engineer

3 days ago

Annapolis Junction, MD, United States Quevera LLC Full-time
Job Description
Job Description

Job Description:

Quevera is seeking a Principal EDR Engineer with an active TS/SCI clearance with Polygraph to support the National Security Agency’s Enterprise Endpoint Detection and Response (EDR) Program in Fort Meade, Maryland. Operating within a highly classified, multi-domain infrastructure, you will serve as a principal technical leader and subject matter expert responsible for strengthening endpoint visibility, threat containment, and configuration resilience across enterprise and mission-critical assets.

In this role, you will lead the architecture, integration, deployment, optimization, and lifecycle engineering of Microsoft Defender for Endpoint (MDE) and Trellix HX across on-premises, cloud, virtual desktop infrastructure, air-gapped, and other highly restricted environments. You will bridge enterprise systems architecture with operational cyber defense capabilities to protect national security infrastructure against sophisticated cyber threats.

As a Principal EDR Engineer, you will advise Government stakeholders on system risks and engineering decisions, collaborate with threat-hunting and intelligence teams, provide advanced support during critical incidents, and mentor junior and mid-level engineering personnel across the program.


Job Responsibilities:

  • Lead the lifecycle engineering, architecture, integration, deployment, and optimization of enterprise EDR capabilities.
  • Design and implement scalable Microsoft Defender for Endpoint and Trellix HX architectures across hybrid enterprise environments.
  • Develop complex systems-engineering, architecture, deployment, and implementation plans.
  • Engineer and manage MDE deployments using Microsoft Endpoint Configuration Manager (MECM/SCCM) or Microsoft Intune.
  • Develop and maintain MDE policy rings, agent configurations, exclusion policies, and endpoint-health monitoring capabilities.
  • Engineer, deploy, and manage Trellix HX controllers and agents within air-gapped and highly restricted networks.
  • Monitor endpoint health, agent performance, policy compliance, and platform coverage at enterprise scale.
  • Tune endpoint-security configurations and exclusions to reduce operational friction while maintaining effective security controls.
  • Collaborate with threat-hunting and intelligence analysts to translate actionable threat intelligence into technical detection capabilities.
  • Develop custom indicators of compromise using Kusto Query Language (KQL), OpenIOC, and YARA rules.
  • Provide advanced endpoint forensic and engineering support to Security Operations Center personnel during critical, high-priority incidents.
  • Analyze endpoint behavior across Windows, Linux, and macOS operating systems.
  • Advise Government stakeholders on system risks, architecture decisions, implementation strategies, and engineering considerations.
  • Apply defense-in-depth principles to endpoint-security architecture and configuration management.
  • Develop and maintain systems-engineering documentation, implementation plans, technical standards, and architecture artifacts.
  • Mentor junior and mid-level engineers and contribute to the development of technical leadership across the program.


Minimum Requirements:

  • Active TS/SCI clearance with Polygraph required.
  • Twenty (20) years of experience as a Systems Engineer supporting programs and contracts of similar scope, type, and complexity.
  • Demonstrated experience planning and leading systems-engineering efforts.
  • Proven engineering experience with Microsoft Defender for Endpoint architecture and enterprise deployment.
  • Experience deploying MDE through MECM/SCCM or Microsoft Intune.
  • Experience managing MDE policies, deployment rings, endpoint configurations, exclusions, and advanced hunting capabilities.
  • Experience developing advanced hunting queries using Kusto Query Language.
  • Experience engineering, deploying, and managing Trellix HX controllers and agents.
  • Experience supporting Trellix HX within air-gapped or highly restricted network environments.
  • Experience c