Full-Time

Staff Endpoint Security Engineer

Endpoint Security

Posted on 9/5/2025

Included Health

Included Health

51-200 employees

Accessible primary, behavioral, and virtual care

Compensation Overview

$149.4k - $274.4k/yr

+ Equity

Remote in USA

Remote

Category
IT & Security (1)
Required Skills
TCP/IP
PowerShell
Bash
Python
Go
Requirements
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • 5+ years of experience in endpoint security, with a strong emphasis on designing, building, implementing, and managing security controls, detection mechanisms, and defensive capabilities across a diverse range of endpoint operating systems (Windows, macOS, iOS, Android).
  • Proven hands-on experience with leading Endpoint Detection and Response (EDR/XDR) solutions (e.g., CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, Carbon Black) for threat detection engineering and security policy enforcement.
  • Demonstrable experience with Mobile Device Management (MDM) / Unified Endpoint Management (UEM) platforms (e.g., Microsoft Intune, Jamf Pro, VMware Workspace ONE, Kandji, MobileIron) for enforcing security configurations and policies.
  • Strong knowledge of endpoint hardening techniques, security configuration management, and policy enforcement across multiple OS platforms, with a focus on building resilient systems.
  • Experience designing and implementing endpoint Data Loss Prevention (DLP) strategies and tools.
  • Proficiency in scripting languages (e.g., Python, PowerShell, Bash) for automating endpoint security tasks, tool integrations, and deployment of defensive measures.
  • Experience with endpoint attack vectors, malware, persistence mechanisms, and designing effective mitigation and detection techniques.
  • Experience with endpoint vulnerability management, patch management processes, and tools, focused on proactive remediation.
  • Experience with network security principles (TCP/IP, DNS, DHCP, VPNs, firewalls) as they relate to designing and implementing endpoint security controls.
  • Experience working in regulated environments and a strong understanding of HIPAA compliance requirements as they apply to endpoint protection and data handling.
Responsibilities
  • Develop, implement, and maintain a comprehensive endpoint security strategy, architecture, and roadmap covering all corporate and BYOD endpoints, with a focus on proactive defense and detection engineering.
  • Design and enforce security configurations, hardening standards, and baselines for diverse operating systems (Windows, macOS, ChromeOS, iOS, Android, and potentially others) to minimize attack surfaces.
  • Lead the selection, deployment, administration, and optimization of endpoint security solutions, including Endpoint Detection and Response (EDR/XDR) for threat detection, Mobile Device Management (MDM/UEM) for policy enforcement, Data Loss Prevention (DLP) for data protection, anti-malware, and endpoint encryption.
  • Develop and implement robust DLP policies and controls to prevent PHI and other sensitive data from leaving authorized systems via endpoints.
  • Manage endpoint encryption technologies (e.g., BitLocker, FileVault, mobile encryption) to ensure data at rest is protected.
  • Proactively look for threats on endpoints to identify gaps in defenses and inform the development of new detection capabilities.
  • Support and provide expertise during incident response activities for endpoint-related security events, with a focus on root cause analysis to enhance preventative and detective controls.
  • Conduct vulnerability assessments, manage endpoint patching and remediation efforts to address identified weaknesses in a timely manner, strengthening overall endpoint resilience.
  • Develop, document, and enforce endpoint security policies, standards, and procedures, particularly for BYOD environments, ensuring compliance with HIPAA and other relevant regulations.
  • Automate endpoint security tasks, compliance checks, defensive measure deployments, and reporting using scripting languages (e.g., Python, Go) and security orchestration tools.
  • Collaborate closely with IT operations, network security, application development, and legal/compliance teams to ensure a cohesive security posture and integrate endpoint defenses.
  • Provide expert consultation and support to end-users and IT staff on endpoint security matters and best practices.
  • Stay current with the latest endpoint threats, vulnerabilities, and security technologies to continuously improve our defenses.

Included Health coordinates accessible healthcare and advocacy for underserved populations, offering primary care, behavioral health, therapy, psychiatry, and virtual care. Members access a unified platform with 24/7 on-demand care from dedicated providers, integrating primary and behavioral health with care guidance. It differentiates itself through care advocacy, integrated services for underserved groups, and partnerships with employers and consultants that aim for measurable clinical and financial outcomes. The goal is to improve the member experience, achieve better health outcomes, and lower costs for client organizations.

Company Size

51-200

Company Stage

Growth Equity (Venture Capital)

Total Funding

$347M

Headquarters

San Francisco, California

Founded

2020

Simplify Jobs

Simplify's Take

What believers are saying

  • DispatchHealth partnership enables virtual-to-home care reducing emergency visits.
  • Dot processed ten billion AI tokens, scaling with largest employers since 2025.
  • AI tools empower clinicians for predictive recommendations and better outcomes.

What critics are saying

  • Teladoc erodes virtual primary care share with superior AI in 6-12 months.
  • Amazon One Medical diverts 20-30% enterprise clients in 12-18 months.
  • CMS cuts virtual care reimbursements 25%, slashing margins in 6-12 months.

What makes Included Health unique

  • Dot AI assistant integrates claims data with clinician oversight for personalized navigation.
  • AI + EQ model combines technology and human expertise for whole-person care.
  • Copay-first plan design centers PCP engagement with nationwide provider network.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Along with comprehensive medical, dental and vision plans; all employee spouses and children can access Included Health services at no cost. For time off, take it when you need it with our unaccrued discretionary time off for all exempt employees.

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
PR Newswire
May 11th, 2021
Grand Rounds Health and Doctor On Demand Complete Merger to Form the Only Virtual Care Company of its Kind

/PRNewswire/ -- Grand Rounds Health, a leader in healthcare quality and navigation, and Doctor On Demand, a leading virtual care provider, today announced the...

HIT Consultant
Apr 12th, 2021
SOC Telemed Inc. acquired Accesstelecare for $194M on Oct 18th 20'.

SOC Telemed acquired Access Physicians for $194mm to solidify its acute care telemedicine services.

Talk to Mira
Dec 20th, 2020
Talktomira hired Lorrie Evans as Vice President Business Strategy and Operations on Dec 20th 20'.

I am extremely happy to announce today that Lorrie Evans has joined its team as Mira‚s Vice President Business Strategy and Operations.

Private Equity Wire
Sep 9th, 2020
Carlyle leads USD175 million round into Grand Rounds

Grand Rounds, a healthcare quality and clinical navigation company, has secured a USD175 million round led by investment funds affiliated with global investment firm The Carlyle Group.

INACTIVE