Endpoint Management Engineer- Security Specialist
Job Summary
Manage and optimize Microsoft Defender for Endpoint and related security technologies
Monitor endpoint security posture and ensure adequate protection against malware ransomware phishing and advanced threats
Develop and implement endpoint security standards and hardening guidelines
Configure and maintain Attack Surface Reduction (ASR) rules and endpoint protection policies.
Manage local firewall configurations and security policies
Implement device control strategies including USB and peripheral restrictions
Enforce security compliance through Microsoft Intune Group Policy and configuration management platforms
Continuously assess and improve endpoint security posture
Implement and maintain local admin permission solutions such as Microsoft LAPS and Endpoint Privilege Management (EPM)
Review and optimize privileged access controls and ensure compliance with least-privilege principles
Coordinate periodic access reviews and governance processes
Manage endpoint vulnerability assessments and remediation activities.
Track security risks and remediation progress.
Develop reporting and KPI dashboards for compliance and security posture.
Recommend and implement changes upgrades and technology modernization projects to the Workplace service
Share knowledge within the IT department and Cyber Security Community proactively through knowledge sharing and the creation of knowledge base articles
Manage execute or support IT Projects when required
Support audits and certifications (TISAX ISO27001 etc.)
Defines and enforces department operating policies procedures and budget
Performs other duties as assigned.
Bachelors degree in Computer Science Information Technology Cyber Security or combined equivalent in education and experience
3-5 years experience as a Endpoint Security Engineer or in a similar role relating Cyber Security or Endpoint management
Hands-on experience managing enterprise endpoint security solutions.
Experience supporting large-scale Windows endpoint environments.
Security Platforms: Microsoft Defender for Endpoint Vulnerability Management Defender for Cloud Apps Sentinel
Endpoint Management: Microsoft Intune EntraID GPOs
Security Controls: Endpoint Privilege Management (EPM) Microsoft LAPS Device Control Local Firewall Management ASR Rule Configuration Security Baseline
Operating Systems: Windows 10/11 Windows Server macOS (preferred) Linux (optional)
Scripting: PowerShell Basic automation and reporting skills (e.g. PowerBI Ansible Terraform Python etc.)
Certificates: Microsoft Certified SC-200 MD-102 SC-300 SC-100 SC-900 or similar CISSP GSEC or equivalent (preferred)
Strong written and verbal communication up and down the organization.
Security-first mindset
Risk-based decision making
Able to effectively prioritize tasks in a high-pressure environment with strong customer service orientation.
Required Experience:
IC
About Company
KUKA is one of the world’s leading suppliers of intelligent robotics, plant and systems engineering and is driving digitization in industry.