Koniag Government Services

Senior Endpoint Protection Analyst

Koniag Government Services  •  $140k - $180k/yr  •  Washington, DC (Onsite)  •  2 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

This position may be filled prior to the posted deadline. Interested candidates are encouraged to apply as soon as possible.

Koniag Operation Services, a Koniag Government Services company, is seeking an experienced Senior Endpoint Protection Analyst to join a cybersecurity team dedicated to protecting critical IT infrastructure and ensuring the security and integrity of enterprise endpoint environments. This position requires the ability to obtain a Public Trust Clearance to support our government customer.

Benefits include medical, dental, and vision insurance, 401(k) retirement plan, paid time off, paid parental leave, life and disability insurance, flexible spending accounts, commuter benefits, and tuition reimbursement.

The ideal candidate is a highly skilled, proactive cybersecurity professional who is passionate about endpoint security, threat detection, and incident response, and possesses the technical depth and analytical expertise to identify, investigate, and mitigate complex endpoint threats in a fast-paced, mission-driven environment.

The Senior Endpoint Protection Analyst will serve as a senior-level subject matter expert responsible for the administration, monitoring, analysis, and continuous improvement of enterprise endpoint protection solutions. This individual will play a critical role in defending the organization's endpoint infrastructure against cyber threats, leading incident response activities, and ensuring endpoint security tools and configurations remain current, effective, and compliant with applicable federal security standards and policies.

Principal responsibilities will include but are not limited to:

  • Serve as a senior technical authority for enterprise endpoint protection platforms, including endpoint detection and response (EDR), antivirus, anti-malware, host-based intrusion detection, and data loss prevention (DLP) solutions.
  • Monitor, analyze, and respond to endpoint security alerts, events, and incidents, conducting thorough investigations to determine scope, impact, and root cause.
  • Lead and support incident response activities related to endpoint threats, including malware infections, ransomware, unauthorized access, lateral movement, and data exfiltration attempts.
  • Perform in-depth forensic analysis of compromised endpoints to identify indicators of compromise (IOCs), threat actor techniques, tactics, and procedures (TTPs), and recommend remediation actions.
  • Develop, tune, and maintain endpoint detection rules, policies, and configurations to reduce false positives, improve detection fidelity, and ensure comprehensive coverage across the enterprise endpoint environment.
  • Conduct regular vulnerability assessments and endpoint compliance reviews, identifying gaps in endpoint security posture and recommending corrective actions.
  • Collaborate with the Security Operations Center (SOC), network security, and IT operations teams to correlate endpoint telemetry with broader threat intelligence and network security data.
  • Manage and administer endpoint protection platforms, ensuring agents are deployed, updated, and functioning correctly across all managed endpoints.
  • Develop and maintain endpoint security policies, standards, baselines, and hardening guidelines in alignment with federal security frameworks such as NIST, FISMA, and agency-specific requirements.
  • Research and analyze emerging cyber threats, vulnerabilities, and attack techniques relevant to endpoint environments, providing actionable intelligence and recommendations to leadership and stakeholders.
  • Support the development and continuous improvement of endpoint security playbooks, standard operating procedures (SOPs), and incident response runbooks.
  • Prepare and deliver clear, accurate, and timely security reports, briefings, and documentation for technical teams and non-technical stakeholders including government leadership.
  • Mentor and provide technical guidance to junior analysts, sharing knowledge and best practices to strengthen the overall capabilities of the cybersecurity team.
  • Participate in security audits, assessments, and Authorization to Operate (ATO) activities by providing endpoint security documentation, evidence, and subject matter expertise.
  • Evaluate and recommend new endpoint security technologies, tools, and capabilities to enhance the organization's overall security posture.
  • Support patch management and vulnerability remediation efforts by validating endpoint compliance and coordinating with IT operations teams.
  • Actively contribute to threat hunting activities, proactively searching for hidden threats and anomalous behaviors within the endpoint environment.

Education and Experience

Required:

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related field from an accredited college or university.
  • 5+ years of experience in cybersecurity, with a focus on endpoint security, endpoint protection, or incident response.
  • Demonstrated experience administering and operating enterprise endpoint protection and EDR platforms such as CrowdStrike Falcon, Microsoft Defender for Endpoint, Carbon Black, SentinelOne, or similar solutions.
  • Experience conducting endpoint security incident investigations, forensic analysis, and malware analysis.

Preferred:

  • 7+ years of experience in cybersecurity with a specialization in endpoint protection or security operations.
  • Experience supporting endpoint security operations in a federal government IT environment.

Required Skills and Competencies:

  • Deep technical expertise in endpoint protection technologies including EDR, antivirus, anti-malware, host-based intrusion detection systems (HIDS), and data loss prevention (DLP) solutions.
  • Proficiency in administering and operating at least one enterprise EDR platform such as CrowdStrike Falcon, Microsoft Defender for Endpoint, Carbon Black, SentinelOne, or equivalent.
  • Strong experience conducting security incident investigations, root cause analysis, and digital forensic analysis of compromised endpoints.
  • Solid understanding of malware analysis techniques, including static and dynamic analysis, and the ability to identify and document indicators of compromise (IOCs).
  • Familiarity with threat intelligence frameworks such as MITRE ATT&CK and the ability to map observed adversary behaviors to known TTPs.
  • Experience developing and tuning endpoint detection rules, alerts, and security policies to improve detection accuracy and reduce alert fatigue.
  • Knowledge of federal cybersecurity frameworks, standards, and regulations including NIST SP 800-53, FISMA, and FIPS, and the ability to align endpoint security practices with these requirements.
  • Experience supporting vulnerability management and patch compliance activities within enterprise endpoint environments.
  • Proficiency with security information and event management (SIEM) platforms for correlating endpoint telemetry with broader security event data.
  • Strong analytical, critical thinking, and problem-solving skills with the ability to assess complex security situations and make timely, informed decisions.
  • Excellent written and verbal communication skills in English, with the ability to produce clear and accurate security reports, documentation, and briefings for both technical and executive audiences.
  • Ability to mentor junior team members and contribute to the professional development of the broader cybersecurity team.
  • Ability to work effectively both independently and collaboratively within a cross-functional cybersecurity team environment.
  • Ability to obtain and maintain a Public Trust Clearance.

Desired Skills and Competencies:

  • Experience working in a federal government cybersecurity environment, preferably supporting a civilian or defense agency.
  • One or more industry-recognized cybersecurity certifications such as:
  • CompTIA Security+, CySA+, or CASP+
  • Certified Ethical Hacker (CEH)
  • GIAC Certified Enterprise Defender (GCED)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Forensic Analyst (GCFA)
  • Certified Information Systems Security Professional (CISSP)
  • CrowdStrike Certified Falcon Responder (CCFR) or equivalent vendor certification
  • Experience with threat hunting methodologies and tools, including proactive identification of advanced persistent threats (APTs) within endpoint environments.
  • Familiarity with cloud endpoint security concepts and experience securing endpoints within Microsoft Azure, AWS, or hybrid cloud environments.
  • Experience with scripting languages such as Python, PowerShell, or Bash for automating security tasks and enhancing endpoint monitoring capabilities.
  • Knowledge of network security concepts including firewalls, proxies, and intrusion detection/prevention systems and how they correlate with endpoint security telemetry.
  • Experience participating in or supporting Authorization to Operate (ATO) processes and security control assessments.
  • Familiarity with zero trust architecture principles and their application to endpoint security strategies.
  • Experience supporting or contributing to Security Operations Center (SOC) operations, including shift-based monitoring and escalation procedures.

Our Equal Employment Opportunity Policy:

The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.

The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or to apply to a position on our website, please contact Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.

Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.

Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352

Koniag Government Services

About Koniag Government Services

Koniag Government Services (KGS) is an Alaska Native Corporation comprised of multiple wholly owned subsidiary companies that deliver Enterprise Solutions, Professional Services, and Operations Management to Federal Government agencies. With an agile employee and corporate culture, KGS applies its proven technical, professional, and operational expertise to enable successful mission outcomes for Defense and Civilian agencies through forward-leaning, solution-oriented business partnerships and a commitment to exceptional service delivery.

Our commitment to quality delivery is demonstrated by our independently accredited CMMI/Dev Level3, CMMI/Svc Level3, ISO 9001:2015 Quality Management System, and ISO 20001:2011 Service Management System. KGS is headquartered in Chantilly, VA with offices all over the country.

KGS is seeking qualified candidates for our open positions, but we will only extend an offer of employment after a candidate applies through the link in our job posting. If you receive a job offer via email only and have not been interviewed by the KGS hiring manager, feel free to contact KGSrecruiting@koniag-gs.com to verify its validity.

Industry
IT & Software
Company Size
1,001-5,000 employees
Headquarters
Chantilly, Virginia
Year Founded
1975
Social Media