Device Security Engineer
Endava View all jobs
- Dublin
- Permanent
- Full-time
- Define and maintain device security standards, policies, and architectural patterns for endpoints, servers, and mobile devices.
- Develop and govern device hardening baselines and configuration standards aligned with enterprise security policies and compliance frameworks.
- Improve device compliance posture by implementing consistent security policies, reporting, and remediation processes.
- Partner with Infrastructure and End User Computing teams to manage device lifecycle security including provisioning, patching, compliance enforcement, and decommissioning.
- Engineer and maintain device protection platforms such as EDR, antivirus, and device management solutions.
- Ensure device protection controls are configured correctly and provide effective coverage across the enterprise environment.
- Define and enforce device identity and access security requirements, including conditional access readiness, device compliance policies, and privileged access controls.
- Support remediation of device security risks, high-risk configurations, and compliance gaps based on business impact and threat intelligence.
- Act as a device security subject matter expert during cyber incidents involving endpoints or managed devices.
- Maintain device security documentation including baseline builds, configuration standards, and secure device deployment patterns.
- Collaborate with SOC and Cyber Defence teams to ensure endpoint telemetry supports effective monitoring, detection, and response workflows.
- Support automation and continuous improvement initiatives for device compliance enforcement, configuration management, and reporting.
- 8-10+ years of experience in IT infrastructure or cybersecurity, with at least 5 years in endpoint or device security engineering roles.
- Hands-on experience implementing and managing enterprise device security controls and endpoint protection platforms.
- Experience with endpoint and mobile device management technologies such as Microsoft Intune, JAMF, Tanium, or equivalent platforms.
- Experience with endpoint security platforms such as CrowdStrike or Microsoft Defender for Endpoint.
- Proven experience collaborating with infrastructure, cloud, and endpoint operations teams to manage device security controls and compliance.
- Experience working with managed service providers or outsourced operations models for security tooling management.
- Experience supporting incident response, device remediation activities, and security investigations involving endpoints.
- Relevant security certifications such as CISSP, endpoint security certifications, or vendor-specific certifications are desirable.
- Strong knowledge of endpoint and device security architecture including:
- Device hardening and secure configuration management
- Endpoint protection and EDR technologies
- Device compliance enforcement and policy management
- Endpoint encryption and secure storage controls
- Hands-on experience with enterprise device security tooling including:
- Microsoft Intune / Endpoint Manager
- JAMF
- Tanium
- CrowdStrike
- Microsoft Defender security suite
- Understanding of device identity and access security including conditional access, device compliance gates, and privileged access controls.
- Experience integrating endpoint telemetry into security monitoring platforms such as SIEM or XDR.
- Strong troubleshooting and problem-solving skills related to endpoint security controls and device management platforms.
- Understanding of modern endpoint attack techniques including ransomware, lateral movement, and credential theft.
- Familiarity with Zero Trust security principles and secure device posture models.
- Finance: Competitive salary package, share plan, company performance bonuses, value-based recognition awards, referral bonus;
- Career Development: Career coaching, global career opportunities, non-linear career paths, internal development programmes for management and technical leadership;
- Learning Opportunities: Complex projects, rotations, internal tech communities, training, certifications, coaching, online learning platforms subscriptions, pass-it-on sessions, workshops, conferences;
- Work-Life Balance: Hybrid work and flexible working hours, employee assistance programme;
- Health: Global internal wellbeing programme, access to wellbeing apps;
- Community: Global internal tech communities, hobby clubs and interest groups, inclusion and diversity programmes, events and celebrations.