Sr. Systems Engineer (Endpoint Detection & Response) Job at Themis Insight, Maryland

L3hMYVFpaVh4YzhHVW4vYzVaQjBlaTd0Vmc9PQ==
  • Themis Insight
  • Maryland

Job Description

Themis Insight solves difficult business, IT, and analytic problems by addressing the whole problem – not just the symptoms – using interdisciplinary approaches that are both practical and innovative. We provide fresh alternatives to ordinary, mainstream consulting firms through small, highly skilled, and hand-picked teams that can meet clients' needs in any industry. Our broad interdisciplinary understanding allows us to provide the right solution, even if it is from outside the industry or traditionally defined problem space. We bring Public and Private, Civilian and Military expertise to every case.

We are hiring a Sr. Systems Engineer (Endpoint Detection & Response) to work in Fort Meade, MD . Position location is subject to change based on central MD client's needs.

Required: TS/SCI with a Polygraph

Description:

The Senior Systems Engineer (Level 3) serves as a principal technical leader and subject matter expert within the National Security Agency's Enterprise Endpoint Detection and Response (EDR) Program. Operating in a highly classified, multi-domain infrastructure, the successful candidate will drive the strategic architectural design, end-to-end integration, deployment, and optimization of premier endpoint security platforms, specifically Microsoft Defender for Endpoint (MDE) and Trellix HX. This critical role bridges high-level systems architecture with operational defense capabilities, ensuring total endpoint visibility, robust threat containment, and resilient configuration management across all enterprise and mission-critical assets to defend national security infrastructure against sophisticated cyber threats.

Essential Duties and Responsibilities:

The Systems Engineer 3 is responsible for leading the lifecycle engineering and scale-out architecture of MDE and Trellix HX across hybrid environments, including on-premises, cloud, and virtual desktop infrastructures (VDI). This includes authoring complex system engineering and implementation plans, tuning agent configurations and exclusion policies to eliminate mission friction, and monitoring overall endpoint health at scale. The engineer will collaborate closely with threat hunting and intelligence analysts to translate actionable threat intelligence into custom technical indicators of compromise (IOCs), utilizing Kusto Query Language (KQL) and YARA rules. Additionally, the individual will act as a primary technical advisor to Government stakeholders on system risks and engineering considerations, provide advanced forensic support to the SOC during critical high-priority incidents, and actively mentor junior and mid-level engineering personnel within the program.

Individual Capabilities/Experience Required:

  • Twenty (20) years experience as a SE in programs and contracts of similar scope, type and complexity is required. Demonstrated experience in planning and leading Systems Engineering efforts is required. Bachelor's degree in System Engineering, Computer Science, Information Systems, Engineering Science, Engineering Management, or related discipline from an accredited college or university is required. Five (5) years of additional SE experience may be substituted for a bachelor's degree.
  • Microsoft Defender for Endpoint (MDE) Expertise: Proven engineering experience with MDE architecture, deployment strategies via MECM/SCCM or Intune, policy ring management, and advanced hunting using Kusto Query Language (KQL).
  • Trellix HX Expertise: Demonstrated experience engineering, deploying, and managing Trellix HX (formerly FireEye) controllers and agents within airgapped or highly restricted networks, including the creation of OpenIOC and YARA rules.
  • Operating System & Forensic Knowledge: In-depth technical understanding of Windows, Linux, and macOS internals, including file systems, registry structures, and process execution mechanics.
  • Professional Standards: Compliance with DoD 8570/8140 IAM Level II or III baseline certifications.

Individual Capabilities/Experience Desired:

  • Vendor Certifications: Microsoft Certified: Security Operations Analyst Associate (SC-200), Azure Security Engineer Associate (AZ-500), or Trellix Certified Engineering credentials.
  • Methodologies & Toolsets: Experience with Model-Based Systems Engineering (MBSE), Cameo, and workflow management within the Atlassian Suite (Jira, Confluence).
  • Technical Frameworks: Familiarity with NSA Technical Manual Standards (e.g., NSA DS-89) and defense-in-depth engineering principles.
  • Core Competencies: Strong record of team collaboration, exceptional transparency in managing high-consequence infrastructure, and an aptitude for developing technical leadership pipelines.

Themis Insight has all the PERKS!

You are our most valuable resource — your ambition, your knowledge, your creativity. We offer an industry-leading set of benefits to supplement your normal salary compensation. Themis Insight has you covered with flexible ways to balance work and home life, full health benefit premium coverage, and generous contributions toward your retirement.

  • Competitive health, dental, and vision plans with 100% paid premiums.
  • 401k: We contribute 6% even if you don't!
  • Time Off: 11 standard holidays, and 25 days of PTO
  • Career Development: Get career counseling and individualized career development plans, including education and training.
  • Employee referral bonuses for successful hires

Themis Insight is an Equal Opportunity/Affirmative Action employer.

Themis Insight provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

Job Tags

Full time, Local area, Work from home, Flexible hours

Similar Jobs

Waffle House - Lehigh Valley Waffles

Server / Waitstaff Job at Waffle House - Lehigh Valley Waffles

 ...what you might earn as a Server at other similar restaurants. Flexible schedules Full time or Part time, Day or Night shift /...  ...experience required Must have a positive and friendly attitude Teens welcome but must be 16 years old + We are a strong, growing... 

Grace Federal Solutions LLC

Van Services Driver - Flexible Job at Grace Federal Solutions LLC

 ...Van Services Driver Flexible Location: Durham, NC Employer: Grace Federal Solutions Schedule: Full-Time | Day Shifts We Need Professionals Who Take Safety Seriously. Grace Federal Solutions is hiring a dependable Van Services Drivers to provide safe... 

University of Pennsylvania

Clinical Research Project Manager C Job at University of Pennsylvania

 ...employer in Philadelphia, is a world-renowned leader in education, research, and innovation. This historic, Ivy League school consistently...  ...programs and resources, and much more. Posted Job Title Clinical Research Project Manager C Job Profile Title Clinical... 

Nielsen Automotive Group

Bodyshop Technician Job at Nielsen Automotive Group

Nielsen Dodge is looking for a Body shop Tech to join the team!This position is responsible for performing vehicle repair as assigned in accordance with dealer and factory standards.What We Offer:* FREE COLLEGE OPPORTUNITY! Online or in-person with Strayer University... 

Wellpath

Psychiatric Nurse Practitioner (PMHNP) - FT Day Job at Wellpath

 ...in class clinical resources for training, education, and point of care support. How you make a difference The Psychiatric Nurse Practitioner provides a full range of psychiatric services to incarcerated patients in accordance with state scope of practice, collaborative...