Grant Thornton (US)

Endpoint Security Stack Manager

Grant Thornton (US)  •  Dublin, IE (Onsite)  •  2 months ago
Apply
AI can make mistakes so check important info. Chat history is never stored.
55
AI Success™

Job Description

Endpoint Security Stack Manager

Own the operations, health, and continual improvement of the enterprise endpoint security stack—delivering high coverage, fast detection/containment, tight compliance, and great engineer/operator experience. Tools in scope include CrowdStrike Falcon EDR/XDR, Microsoft Intune (MEM) for Windows/macOS/iOS/Android MDM/MAM, Qualys VMDR (incl. PC/SCA), Absolute for asset assurance, and device compliance gating (Intune + Entra Conditional Access). This role collaborates closely with the SOC/MXDR provider and infra/client-engineering to maintain a defensible, auditable endpoint posture at scale.

Scope & Tooling (authoritative systems)

  • EDR/XDR: CrowdStrike Falcon (sensors, prevention policies, RTR, identity protection, device control).
  • MDM/MEM: Microsoft Intune/MEM (enrollment, configuration profiles, compliance policies, app protection, update rings).
  • Vulnerability & Config: Qualys VMDR + Policy Compliance + Secure Configuration Assessment (agents, scanners, appliances).
  • Asset Assurance: Absolute (agent health, tamper detection, device location/lock/wipe).
  • Device Compliance/Zero Trust: Intune + Entra Conditional Access device posture gates, aligned to GT endpoint standards.
  • Adjacencies: Endpoint Privilege Mgmt (e.g., CyberArk EPM), encryption (BitLocker/FileVault), SIEM/SOAR and SOC integrations—per GT’s defense‑in‑depth architecture.

Key Responsibilities

Platform Operations & Maintenance

  • Own day‑to‑day operations of EDR/MDM/VM/Asset Assurance platforms: console administration, policy lifecycle, agent currency, tuning, and change control (CAB) aligned to GT standards.
  • Maintain sensor/agent health & coverage across all supported OSes; drive auto‑healing and deployment automation (Intune, scripts) to keep coverage above target SLAs.
  • Run Qualys scans at scale (agents/appliances), fix coverage gaps, and partner with patching teams on remediation SLAs.
  • Administer device compliance policies and Conditional Access posture gates for Zero Trust access; minimize user friction while enforcing baseline.
  • Oversee Absolute for asset assurance (visibility, investigation support, and recovery workflows).

Detection, Response & SOC Collaboration

  • Ensure high‑fidelity EDR detections and rapid containment (isolation, RTR, IOCs), with playbooks aligned to the SOC/MXDR provider; continuously tune to reduce false positives.
  • Serve as tier‑3/engineering escalation for endpoint incidents; contribute to incident post‑mortems, root cause fixes, and lessons‑learned hardening.

Governance, Risk & Compliance

  • Align all tooling and controls with GT Endpoint Security Standard and defense‑in‑depth architecture; maintain audit‑ready evidence, runbooks, and metrics.
  • Own tool control mappings to CIS/NIST/ISO; partner with GRC for control attestations and external audits.

Engineering & Automation

  • Drive policy-as-code and automation for agent deployment, compliance enforcement, and reporting (PowerShell, KQL, Python, Graph, APIs).
  • Rationalize integrations with SIEM/SOAR, CMDB/asset systems, ticketing, and collaboration tools—consistent with the enterprise architecture.

Lifecycle & Vendor Management

  • Manage licensing, renewals, roadmaps, and vendor/MSP/MSSP relationships; evaluate new capabilities (e.g., identity threat protection, device control enhancements).

M&A / New Environment Onboarding

  • Lead EDR and Qualys roll‑in for acquisitions per the InfoSec M&A Playbook: uninstall legacy agents, deploy GT standard agents, integrate to SOC, and hit day‑1 protection/visibility.

Required Experience & Qualifications

  • 8+ years in endpoint security/operations; 3+ years leading EDR/MDM/Vulnerability platforms at enterprise scale.
  • Hands‑on with CrowdStrike Falcon, Intune/MEM (Windows/macOS/iOS/Android), Qualys VMDR/PC/SCA, Absolute, and device compliance/Conditional Access; familiarity with CyberArk EPM, BitLocker/FileVault helpful in GT context.
  • Strong OS internals (Windows/macOS/Linux), scripting (PowerShell, KQL, Python), packaging/deployment, API integrations.
  • Knowledge of NIST CSF, CIS benchmarks, ISO 27001; ITIL change/problem.
  • Certifications a plus: CrowdStrike (CCFR/CCFA/CCFH), Microsoft (SC‑200/AZ‑500/MS‑101), Qualys, GIAC (GCIA/GCED/GCFA), ITIL.

#LI-KS1

We are Grant Thornton
Grant Thornton Ireland is rapidly approaching 3,000 people, in 9 offices across Ireland, Isle of Man, Gibraltar and Bermuda. With a presence in over 149 countries around the world and a global network of 73,000 people, we bring our clients the local knowledge, national expertise and global presence to help them succeed – wherever they’re located.

At GT, we work as trusted advisors, bringing local knowledge and national expertise, with a global presence, to help businesses succeed – wherever they are located. We make business more personal by investing in building relationships and empowering our clients to make the right decisions for their organisation now and for the future. Whether that is working with the public sector to build thriving communities, with regulators and financial institutions to build trust, or with a diverse range of businesses to help them achieve their goals, Grant Thornton Ireland work hard to support clients to act on the issues that matter.

At GT Ireland we don’t just predict your future, we build it
A Career at GT
Looking for a more fulfilling role in professional services? One where fresh thinking, collaboration and diversity are valued? At Grant Thornton we do things differently.

What does this mean for you?
A career in a more inclusive working environment, a more collaborative work culture, a more supported, flexible working role, more possibilities to grow and more opportunities to help shape the future for your clients. We respect and value your experience. And we want you to bring your authentic self to work and be at your best. It is how it should be.

Grow with us
At Grant Thornton, we care about our people and work hard to make you feel valued. If you are looking to deepen and develop your skills, knowledge, and experience throughout your career, then that is what you will get, and more.
Our Benefits
Please follow this link for information on our generous benefits package.

Grant Thornton (US)

About Grant Thornton (US)

Forget what you think you know about professional services. We go beyond what’s expected and help others do the same.

Grant Thornton is the brand name for Grant Thornton LLP and Grant Thornton Advisors LLC the U.S. member firms of Grant Thornton International Ltd, one of the world’s leading independent audit & assurance, tax and advisory firms. That means our network has more than 73,000 professionals in more than 146 countries who are ready to help public and private organizations of all sizes take on today’s challenges. But what sets us apart isn’t just what we do – it’s how we do it. Here, we believe in making business more personal and building trust into every result. We’re collaborators – obsessed with quality and ready for anything – who understand the value of strong relationships. It’s how we challenge the expectations of business and empower our people and clients to do it, too.

One thing we won’t do? Grant Thornton will never request money or any form of payment for services via social media. Please report any concerns at 1-800-810-3503.

Grant Thornton International Limited (GTIL) and the member firms, including Grant Thornton LLP and Grant Thornton Advisors LLC, are not a worldwide partnership. Services are delivered by the member firms. GTIL and its member firms are not agents of, and do not obligate, one another and are not liable for one another’s acts or omissions. Please see www.grantthornton.com for further details.​

Industry
Accounting & Tax
Company Size
10,000+ employees
Headquarters
Chicago, IL
Year Founded
1924
Social Media