Overview
In this role you will strengthen the firm’s security posture by owning Windows security engineering, endpoint protection, and automation at scale. You’ll work across Windows platforms, AD/Entra ID, PKI, and core infrastructure to implement robust controls and threat mitigation. The position combines hands-on engineering with advisory work to support global IT teams in a fast-moving environment. You’ll drive vulnerability management and platform hardening, influencing technical decisions and security best practices.
Responsibilities
- Design and implement security controls across Windows platforms
- Drive vulnerability management initiatives and remediation at scale
- Automate configuration, monitoring, and incident response
- Improve endpoint security (EDR, AV, patching, OS hardening)
- Collaborate with core infrastructure (AD / Entra ID, PKI, networking)
- Investigate threats and advise on technical risk
- Support global IT teams across a distributed environment
Key requirements
- Strong Windows security engineering experience
- Solid understanding of host-based controls (application control, firewalling, logging, encryption)
- Hands-on with endpoint protection, EDR, scanning and patching tools
- Experience with OS hardening, privileged access concepts, identity and security best practices
- Knowledge of common attack techniques and countermeasures
- Good grasp of Active Directory/Entra ID and PKI
- High level PowerShell programming skills
- Clear communicator, reliable, collaborative, able to influence technical decisions
- Clear communicator
- Collaborative
- Influential
- Windows security engineering
- Endpoint protection (EDR, AV)
- Vulnerability management
…
