Jr Endpoint Protection Analyst

Remote (Washington, DC, US)Remote (region-locked)Individual contributorFound yesterday
Apply to this job

Free credits included. Sign up to start applying with Jobfinder.

endpoint securitycybersecurity operationsit administrationsecurity monitoringcompliance

Koniag Data Solutions, a Koniag Government Services company, is seeking a motivated and technically developing Endpoint Protection Analyst (Junior) to support enterprise cybersecurity operations and IT administrative support services for a federal government client. This position requires the ability to obtain and maintain a government background investigation, PIV credentials, and all requisite IT access authorizations prior to performing work. Primary work will be performed at the client site in Washington, DC and approved remote/telework locations.

We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.

This role serves as an important technical support function responsible for assisting in the administration, monitoring, and maintenance of enterprise endpoint security controls and endpoint protection platforms across a complex, geographically distributed federal IT environment spanning on-premises infrastructure, cloud platforms, and enterprise applications.

The ideal candidate is an enthusiastic and detail-oriented early-career cybersecurity professional with foundational knowledge of endpoint security technologies, security operations practices, and Federal cybersecurity compliance requirements. This individual must possess a strong desire to learn and grow within a dynamic federal IT security environment, a collaborative mindset, and the technical foundation necessary to support the administration and monitoring of enterprise endpoint protection capabilities under the guidance of senior security personnel.

The Endpoint Protection Analyst (Junior) will serve as a supporting technical contributor within the program's cybersecurity team, assisting senior security engineers and analysts in the day-to-day administration, monitoring, and maintenance of enterprise endpoint security controls and endpoint protection platforms. This individual supports the protection of Government endpoints—including workstations, laptops, servers, and mobile devices—against malware, unauthorized access, policy violations, and other security threats, contributing to the program's broader mission of maintaining a strong and continuously improving enterprise security posture in alignment with Federal cybersecurity frameworks and client security requirements.

Principal responsibilities will include but are not limited to:

Endpoint Protection Platform Administration

  • Assist in the administration and maintenance of enterprise endpoint protection platforms, including Endpoint Detection and Response (EDR), antivirus, anti-malware, host-based intrusion detection, application control, and device management solutions under the guidance of senior security engineers.
  • Support the configuration, deployment, and management of endpoint security agents across managed endpoints, ensuring agent coverage is comprehensive, current, and accurately tracked.
  • Monitor endpoint protection platform dashboards and consoles, identifying endpoints with outdated agents, missing security policies, protection gaps, or active threats requiring investigation or remediation.
  • Assist in the development and maintenance of endpoint security policies, configurations, and deployment packages, ensuring policies are aligned with applicable security baselines, DISA STIGs, CIS Benchmarks, and client security requirements.
  • Support the management of endpoint protection platform exceptions, exclusions, and whitelists, ensuring all exceptions are properly documented, reviewed, and approved in accordance with defined governance procedures.
  • Assist in the administration and maintenance of Mobile Device Management (MDM) and Unified Endpoint Management (UEM) platforms, supporting the enrollment, configuration, monitoring, and compliance enforcement of managed mobile and remote devices.
  • Generate and distribute endpoint protection platform health and coverage reports, providing program leadership and Government stakeholders with accurate visibility into endpoint security posture and protection gaps.

Threat Detection & Alert Monitoring

  • Monitor endpoint protection platform alerts, EDR telemetry, and security event feeds, triaging security alerts and escalating confirmed or suspected security incidents to senior analysts and the incident response team in accordance with defined escalation procedures and SLA requirements.
  • Assist in the investigation of endpoint security alerts, gathering relevant event data, endpoint telemetry, and contextual information to support accurate triage and escalation decisions under the guidance of senior security personnel.
  • Support the development and maintenance of endpoint alert triage procedures, escalation playbooks, and response runbooks, contributing practical observations and lessons learned from daily monitoring activities.
  • Assist in identifying and documenting false positive alert patterns, supporting senior engineers in refining detection rules, alert thresholds, and EDR platform tuning to improve alert fidelity and reduce analyst fatigue.
  • Monitor endpoint protection platform health and availability, identifying and escalating platform performance issues, service disruptions, and coverage gaps that may impact the program's ability to detect and respond to endpoint threats.

Vulnerability & Patch Management Support

  • Assist in the execution of endpoint vulnerability scanning activities, supporting the scheduling, execution, and result collection of regular vulnerability scans across managed endpoints using enterprise vulnerability scanning platforms.
  • Support the analysis and triage of endpoint vulnerability scan results, assisting senior engineers in identifying, categorizing, and prioritizing vulnerabilities based on severity, exploitability, and asset criticality under defined risk-based prioritization criteria.
  • Assist in tracking and reporting on endpoint patch compliance status, monitoring patch deployment progress across managed endpoints and identifying systems with outstanding critical and high-severity patches requiring escalation.
  • Support coordination with system administrators and desktop support personnel to facilitate timely endpoint patch deployment, providing technical assistance and escalation support as needed.
  • Maintain accurate and current endpoint vulnerability and patch compliance records in the program's vulnerability management tracking system, supporting audit readiness and compliance reporting activities.

Endpoint Hardening & Compliance

  • Assist in the implementation and validation of endpoint hardening standards, supporting the application of DISA STIGs, CIS Benchmarks, and client-specific security baselines across managed Windows, Linux, and macOS endpoint environments.
  • Support configuration compliance scanning activities, assisting in the execution and analysis of Security Content Automation Protocol (SCAP) scans and configuration compliance assessments across managed endpoints.
  • Assist in tracking and reporting on endpoint configuration compliance status, identifying non-compliant endpoints and supporting remediation activities to bring endpoints into compliance with applicable security baselines.
  • Support the development and maintenance of endpoint hardening documentation, including hardening guides, configuration baseline specifications, and compliance reporting templates.

Incident Response Support

  • Support cybersecurity incident response activities involving endpoint security events, assisting senior analysts and engineers in evidence collection, endpoint isolation, malware containment, and remediation activities under defined incident response procedures.
  • Assist in the collection and preservation of endpoint forensic evidence, supporting chain of custody procedures and forensic acquisition activities under the guidance of senior digital forensics or incident response personnel.
  • Document incident response activities accurately and completely in the program's ITSM platform, ensuring incident records contain sufficient detail to support post-incident review, root cause analysis, and lessons learned activities.
  • Support post-incident review activities, contributing endpoint security observations and technical findings to root cause analysis discussions and corrective action development.

Compliance & Documentation Support

  • Assist in maintaining endpoint security compliance documentation, including security control implementation evidence, configuration compliance records, vulnerability remediation tracking data, and audit artifacts, supporting the program's ATO and continuous monitoring obligations.
  • Support the development and maintenance of endpoint security standard operating procedures, operational runbooks, and knowledge base articles, contributing practical operational knowledge to the program's documentation library.
  • Assist in the preparation of endpoint security status reports, compliance dashboards, and metrics summaries for program leadership and Government stakeholders.
  • Ensure all endpoint security activities are conducted in compliance with applicable Federal regulations, client security policies, and program security requirements, including FISMA, NIST SP 800-53, applicable DISA STIGs, and client-specific cybersecurity policies.
  • Ensure all activities involving personally identifiable information (PII), CUI, or other sensitive data categories are handled in accordance with applicable privacy protection requirements and data handling restrictions.

Professional Development & Learning

  • Actively pursue professional development and skills growth in endpoint security, cybersecurity operations, and Federal IT compliance, leveraging available training resources, mentorship from senior team members, and industry certifications to continuously expand technical capabilities.
  • Participate in team knowledge sharing sessions, security briefings, and technical training activities, contributing to a collaborative learning environment within the cybersecurity team.
  • Stay current with emerging endpoint security threats, vulnerabilities, attacker TTPs, and evolving Federal cybersecurity requirements, incorporating new knowledge into daily monitoring and analysis activities.

Education and Experience: Required:

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related field from an accredited college or university. Equivalent combination of education and directly relevant experience or military service in a cybersecurity-related role may be considered.
  • Minimum of 1–2 years of experience in a cybersecurity, IT operations, or endpoint security support role, including internship, academic project, or entry-level professional experience in a relevant discipline.
  • Foundational knowledge of endpoint security concepts, including antivirus and anti-malware technologies, EDR platforms, endpoint hardening, patch management, and mobile device management.
  • Foundational knowledge of Windows operating system administration and security, including Active Directory, Group Policy, Windows Security Center, and Windows Event Logs.
  • Ability to obtain and maintain a government background investigation, PIV credentials, and all requisite IT access authorizations prior to performing work.

Preferred:

  • Prior experience supporting endpoint security or cybersecurity operations in a federal government IT contracting environment.
  • Exposure to Linux or macOS endpoint security administration and hardening.
  • Familiarity with enterprise vulnerability scanning platforms such as Tenable Nessus, Qualys, or equivalent tools.

Required Skills and Competencies:

  • Foundational technical knowledge of endpoint security technologies and concepts, including EDR platforms, antivirus and anti-malware solutions, host-based intrusion detection, application control, patch management, and mobile device management.
  • Basic understanding of cybersecurity principles, including the CIA triad, defense-in-depth, least-privilege access control, and common attack vectors targeting enterprise endpoints.
  • Familiarity with Windows operating system security, including Active Directory, Group Policy Objects, Windows Event Logs, Windows Defender, and common Windows-based security monitoring tools.
  • Basic understanding of Federal cybersecurity frameworks and compliance requirements, including NIST SP 800-53, FISMA, DISA STIGs, CIS Benchmarks, and applicable Federal endpoint security policies.
  • Strong analytical and attention-to-detail skills with the demonstrated ability to review security alerts, event logs, and platform dashboards systematically and accurately under the guidance of senior security personnel.
  • Strong written and verbal communication skills with the ability to document security events, alert triage findings, and operational activities clearly and accurately in ITSM tickets, incident records, and status reports.
  • Demonstrated ability to work effectively as a member of a cross-functional technical team, following established procedures, escalating issues appropriately, and actively seeking guidance from senior personnel.
  • Basic proficiency with Microsoft Office Suite and collaboration tools such as Microsoft Teams for documentation, reporting, and team communication activities.
  • Strong commitment to professional growth and continuous learning, with demonstrated motivation to develop cybersecurity knowledge, technical skills, and Federal compliance expertise over time.
  • Ability to manage multiple concurrent tasks and priorities with a high degree of accuracy and attention to detail in a fast-paced operational environment.

Desired Skills and Competencies:

  • CompTIA Security+ certification or active pursuit of CompTIA Security+ as a near-term professional development objective.
  • CompTIA A+, CompTIA Network+, or equivalent foundational IT certification demonstrating baseline technical knowledge.
  • Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900) or Microsoft Certified: Azure Fundamentals (AZ-900) certification.
  • Familiarity with enterprise EDR platforms such as CrowdStrike Falcon, Microsoft Defender for Endpoint, Carbon Black, SentinelOne, or equivalent tools.
  • Familiarity with enterprise vulnerability scanning platforms such as Tenable Nessus, Qualys, Rapid7 InsightVM, or equivalent tools.
  • Basic familiarity with SIEM platforms such as Splunk, Microsoft Sentinel, or equivalent tools for security event monitoring and alert triage support.
  • Familiarity with DISA STIG Viewer or SCAP Compliance Checker tools for endpoint configuration compliance assessment support.
  • Basic scripting knowledge in PowerShell, Python, or Bash for operational task automation and data parsing under the guidance of senior engineers.
  • Familiarity with ITIL-based IT Service Management concepts and enterprise ITSM platforms such as ServiceNow for incident documentation and ticket management.
  • Familiarity with the MITRE ATT&CK framework and its application to understanding common adversary tactics, techniques, and procedures targeting enterprise endpoints.
  • Basic familiarity with cloud security concepts as they relate to endpoint protection in hybrid on-premises and cloud environments, including Microsoft Azure and/or AWS.
  • Familiarity with mobile device security and MDM/UEM platform concepts, including device enrollment, compliance policy enforcement, and remote wipe capabilities.
  • Participation in cybersecurity competitions, Capture the Flag (CTF) events, academic cybersecurity programs, or equivalent hands-on learning activities demonstrating initiative and practical skill development.

Our Equal Employment Opportunity Policy:

The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.

The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or to apply to a position on our website, please contact Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.

Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag\-gs.com.

Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352

Koniag Government ServicesJr Endpoint Protection Analyst
Apply to this job