Chargepoint Staff Endpoint Security Engineer at ChargePoint responsible for owning and advancing the endpoint security program. Focus on protecting corporate assets through EDR, DLP, and insider threat detection and response.
Responsibilities
Lead insider threat detection and response efforts - build and maintain detection logic, investigate anomalous user behaviour, and drive incident response for insider threat cases.
Manage and mature the enterprise Data Loss Prevention (DLP) programme: define and refine DLP policies, monitor alerts, investigate violations, and coordinate remediation with stakeholders.
Own the end-to-end management of the enterprise EDR platform - deployment, policy configuration, tuning, and ongoing optimisation across Windows, macOS, and Linux endpoints.
Develop new detection use cases, monitoring strategies and automation workflows for endpoint-based threats, leveraging telemetry from EDR, DLP, UEBA, and other endpoint security tools.
Triage, investigate, and respond to endpoint security alerts; perform root cause analysis and recommend containment and remediation actions.
Conduct proactive threat hunting across endpoint telemetry to identify advanced threats and attacker techniques that evade signature-based detection.
Collaborate with the SOC, threat intelligence, and incident response teams to correlate endpoint findings with broader security events.
Evaluate, recommend, and integrate new endpoint security technologies and capabilities as the threat landscape evolves.
Develop and maintain runbooks, standard operating procedures, and documentation for endpoint security operations and incident response workflows.
Produce metrics, dashboards, and executive-level reports on endpoint security posture, alert trends, and insider threat programme maturity.
Partner with IT and infrastructure teams to provide security guidance on endpoint hardening, configuration baselines, and secure deployment practices.
7+ years of experience in information security, with at least 5 years focused on endpoint security engineering.
Qualification
Excellent analyticalBachelor's degree in Computer Science
Required
Demonstrated experience in insider threat detection and response, including familiarity with UEBA tools and behavioural analytics.
Proven ability to develop custom detection rules, use cases, and correlation logic for endpoint-based threats.
Experience with SOAR platforms and security automation for endpoint alert triage and response.
Solid understanding of endpoint hardening, OS internals (Windows, macOS, Linux), and attack surface reduction techniques.
Experience with MITRE ATT&CK framework and its application to endpoint threat detection and threat hunting.
Strong scripting and automation skills (Python, PowerShell, Bash) to build tooling, automate workflows, and parse telemetry.
Excellent analytical, investigative, and problem-solving skills with the ability to work under pressure during active incidents.
Strong written and verbal communication skills; ability to present technical findings to both security peers and executive leadership.
Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field or equivalent practical experience.
Knowledge of user onboarding and offboarding processes and the security controls that should be embedded in those workflows - ability to guide IT teams on automation policies for access provisioning and de-provisioning.
Experience with SOAR platforms and security automation for endpoint alert triage and response.
Familiarity with Zero Trust architecture principles and their application to endpoint security.