Level

Dyson

Lead Engineer – Endpoint Security

Dyson is hiring a Lead Engineer – Endpoint Security in Kuala Lumpur, Malaysia. Level rates it ; you can apply on Level.

AI in this role

Lead endpoint security engineer responsible for defining hardening standards, managing EDR/XDR controls, and securing multi-OS device fleets.

microsoft-defenderintunejamfpowershell
endpoint-securityos-hardeningedrvulnerability-managementincident-response

Role Purpose
As the Endpoint Security Engineer, you are accountable for defining endpoint hardening standards and engineering baseline security controls across all Windows, macOS, and Linux device estates.

Operating as a hands-on technical lead, you will drive endpoint risk reduction across the enterprise. By configuring advanced EDR/XDR controls, managing device compliance frameworks, and supporting incident response teams, you will ensure end-user devices are continuously defended against modern compromise techniques.

In this role, you will lead and manage the following domains:

Endpoint Hardening & Baselines: Defining, implementing, and enforcing security baselines across Windows, macOS, and Linux fleets.

EDR/XDR Control Engineering: Managing and tuning Microsoft Defender endpoints and security capabilities.

Device Compliance Frameworks: Designing compliance policies that enforce endpoint health prior to granting corporate resource access.

Vulnerability & Posture Reduction: Leading targeted initiatives to mitigate system vulnerabilities, OS flaws, and configuration drift.

Security Reviews & Incident Support: Conducting technical endpoint security reviews and assisting incident response teams during major investigations.

Key Skills & Qualifications

- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent practical experience).

- A minimum of 5–7 years' technical experience in endpoint security engineering, OS hardening, and endpoint management at scale.

- Deep engineering knowledge of multi-OS security architectures (Windows, macOS, Linux) and cross-platform EDR deployment.

- Relevant certifications such as Microsoft Certified: Security Operations Analyst Associate (SC-200), GIAC Endpoint Asset Protection (GCED), or CISSP are highly desirable.

Security Expertise & Architecture
Deep understanding of OS internal security structures (Windows Defender, macOS Security Frameworks, Linux PAM/AppArmor/SELinux) and local attack mitigation controls.

Tooling & Technical Proficiency
Proficiency in Microsoft Defender for Endpoint, Intune, JAMF, Microsoft Security Baselines, CIS Benchmarks, and endpoint management systems.

Risk Management & Prioritisation
Ability to prioritize OS-level misconfigurations and endpoint vulnerabilities based on active exploit availability and local device access rights.

Governance, Process & Control Design
Experience designing automated device compliance policies, device health attestation checks, and local privilege management controls.

Service Delivery & Operational Management
Proven ability to manage endpoint security agent coverage, maintain health telemetry across global device estates, and minimize agent conflicts.

Data Analysis, Reporting & Insight
Skilled in analyzing endpoint telemetry, KQL querying, and generating clear health dashboards for device compliance and security posture.

Stakeholder Management & Influence
Ability to partner with workplace platform engineering teams to push security updates and baseline policy changes without disrupting end-user productivity.

Threat Intelligence Integration
Ability to translate threat intelligence indicators (IoCs) and adversary techniques (MITRE ATT&CK) into tailored endpoint detection and block rules.

Leadership & Collaboration
Proven ability to lead technical endpoint security workstreams, provide clear remediation directions, and mentor junior operational staff.

Continuous Improvement & Automation
Experience driving security automation through script-based remediation (PowerShell, Bash, Python) and unified endpoint management integrations.

Key Accountabilities & Success Measures
Endpoint Hardening & Security Baselines
Accountability: Architect, deploy, and maintain standardized security baselines for all Windows, macOS, and Linux endpoints.
Success Measures: Greater than 98% compliance rate with established OS security baselines across the entire enterprise estate; 100% of managed devices bound by strict compliance and attestation requirements.

Defender Suite Engineering & Telemetry
Accountability: Engineer Microsoft Defender capabilities, optimize detection engine rules, and ensure full agent health across all OS platforms.
Success Measures: >99% agent deployment health and active reporting across all connected devices; Dynamic detection policy coverage mapped directly against top MITRE ATT&CK techniques.

Vulnerability & Risk Reduction Initiatives
Accountability: Drive endpoint risk reduction programs aimed at mitigating configuration flaws, unpatched software, and high-risk local permissions.
Success Measures: Measurable structural reduction in high and critical endpoint security posture gaps; MTTR for critical endpoint configuration drift kept within defined SLA targets.


Dyson is an equal opportunity employer. We know that great minds don’t think alike, and it takes all kinds of minds to make our technology so unique. We welcome applications from all backgrounds and employment decisions are made without regard to race, colour, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other any other dimension of diversity.

How we rate this

Lead Engineer – Endpoint Security at Dyson rates 0 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.

Classification

Little AI. AI is not part of the work.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Prepare for this job

A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.

Skills and AI tools this role asks for

Endpoint SecurityOs HardeningEdrVulnerability ManagementIncident ResponseMicrosoft DefenderIntuneJamf

Questions you could be asked

  1. Tell me about a project where endpoint security was part of your work. What did you do?
  2. Tell me about a project where os hardening was part of your work. What did you do?
  3. Tell me about a project where edr was part of your work. What did you do?
  4. Tell me about a project where vulnerability management was part of your work. What did you do?
  5. Tell me about a project where incident response was part of your work. What did you do?

Adapt your resume

  • List these exact terms on your resume: Endpoint Security, Os Hardening, Edr, Vulnerability Management, and Incident Response. An applicant tracking system matches the wording, not the idea.
  • Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.

Want an expert to read your CV for this job?

Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.

Get a free CV review

Get new software engineering jobs by email

One email a week with the new software engineering jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

Similar roles

Software Engineering roles that involve little AI, at other companies.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at Dyson

Related searches

Same AI level

Jobs by city