Endpoint Security & Vulnerability Management Engineer
Please note: As per current corporate policy, this position may require you to be in the office up to four (4) days per week and/or as additionally required based on business needs, onboarding, operational support, or leadership direction
3 years of experience in workplace support, desktop support, service desk, endpoint operations, EWS, systems administration, application support, vulnerability remediation support, or related enterprise technology disciplines
JOB SUMMARY
This Endpoint Security & Vulnerability Management Engineer position supports Digital Workplace Planning & Service Management and is focused on reducing enterprise cyber risk through vulnerability remediation, software lifecycle management, endpoint security controls, automation, reporting, and operational modernization
The most qualified candidates will bring strong organizational skills, clear communication, customer-focused support experience, and a demonstrated ability to coordinate work across technical teams. Prior vulnerability management, endpoint security, scripting, or advanced endpoint engineering experience is helpful but may be developed through internal training, mentoring, and hands-on project work
The Endpoint Security & Vulnerability Management Engineer works closely with Cyber Security, Infrastructure, Endpoint Engineering, Service Management, application owners, vendors, and support teams to improve software currency and compliance, accelerate remediation efforts, support secure delivery of endpoint technologies, and strengthen operational efficiency while maintaining a positive end-user experience
This position supports application control, application allowlisting, endpoint privilege management, software lifecycle health, patching support, automation, dashboards, operational documentation, and continuous improvement across the enterprise endpoint environment
JOB REQUIREMENTS
Education:
Bachelor's degree in information technology, Computer Science, Engineering, Cybersecurity, or a related discipline preferred
Military experience, equivalent education, technical training, certifications, and relevant hands-on experience will be considered
Knowledge, Skills and Abilities:
A minimum of 3 years of experience in workplace support, desktop support, service desk, endpoint operations, EWS, systems administration, application support, vulnerability remediation support, or related enterprise technology disciplines.
Certifications, formal technical training, and prior vulnerability management experience are preferred but not required for qualified internal candidates who demonstrate strong ownership, communication, organization, collaboration, troubleshooting, and willingness to learn. The selected candidate may be developed through an internal training plan focused on endpoint security, vulnerability management, automation, reporting, and enterprise remediation practices.
Experience supporting Microsoft Windows endpoints, users, applications, or endpoint-related incidents in an enterprise support environment
Familiarity with Microsoft Intune, MECM/SCCM, Microsoft Configuration Manager, software deployment tools, device management consoles, or comparable endpoint support platforms preferred
Basic understanding of vulnerability management, patching, remediation tracking, compliance follow-up, ticket management, or operational risk reduction preferred; deeper vulnerability management skills may be developed through training
Ability to support vulnerability remediation execution by organizing work, tracking actions, following up with stakeholders, validating outcomes, and escalating blockers as needed
Ability to partner effectively with Cyber Security, Infrastructure, Endpoint Engineering, Service Management, vendors, application owners, Workplace Support, Desktop Support, Service Desk, and EWS teams to coordinate remediation plans and operational follow-through
Exposure to endpoint security concepts such as application control, application allowlisting, endpoint privilege management, least privilege, security baselines, or secure support practices preferred
Experience supporting software installs, application troubleshooting, application upgrades, patching, device remediation, customer validation, or software lifecycle activities
Basic experience with PowerShell, command-line tools, endpoint troubleshooting utilities, or a demonstrated interest in learning scripting and automation preferred
Ability to learn and help develop scripts, workflows, dashboards, reporting methods, and process improvements that increase remediation efficiency and operational visibility
Experience creating, maintaining, or interpreting reports using Excel, Power BI, endpoint management platforms, ITSM data, vulnerability tools, DEX tools, or comparable reporting sources preferred
Working knowledge of ServiceNow, Helix, Remedy, or comparable IT service management platforms
Experience with change management, incident management, problem management, customer validation, operational governance, or audit response activities
Ability to review vulnerability findings, support prioritization discussions, organize remediation actions, and escalate risks based on business impact, operational dependency, asset criticality, and remediation complexity
Exposure to vulnerability management platforms such as Tenable, Qualys, Rapid7, CrowdStrike Spotlight, Tanium, Microsoft Defender Vulnerability Management, or equivalent technologies preferred but not required
Exposure to endpoint privilege management platforms such as Delinea Privilege Manager, BeyondTrust, CyberArk Endpoint Privilege Manager, Microsoft Endpoint Privilege Management, or comparable technologies preferred but not required
Awareness of NIST, CIS, Zero Trust, CVSS, CISA Known Exploited Vulnerabilities, vulnerability prioritization, and risk-based remediation practices preferred; practical knowledge may be developed through internal training and mentoring
Strong troubleshooting, analytical thinking, documentation, follow-up, attention to detail, and problem-solving skills
Excellent written and verbal communication skills, including the ability to communicate technical concepts clearly to technical and non-technical audiences
Ability to manage multiple priorities, organize work across queues or workstreams, coordinate with multiple teams, and drive tasks to completion with appropriate guidance, documentation, and escalation
Strong organizational, documentation, stakeholder management, relationship-building, and customer service skills
Ability to work individually and with a team, as needed, in a fast-paced environment with changing priorities and time-sensitive operational needs
Preferred certifications or equivalent training may include Microsoft 365 Certified: Endpoint Administrator Associate (MD-102), Microsoft Certified: Security Operations Analyst Associate (SC-200), Microsoft Certified: Power BI Data Analyst Associate (PL-300), CompTIA Security+, CompTIA CySA+, ITIL Foundation, Tenable, Qualys, Rapid7, CrowdStrike, Tanium, CyberArk, BeyondTrust, Delinea, Microsoft Security, Identity, Azure, or comparable endpoint security, vulnerability management, endpoint management, reporting, automation, or IT service management training. Certifications are not required at time of hire for qualified internal candidates and may be pursued as part of the internal development plan
Behavioral Attributes:
Committed to safety first through cyber risk reduction, secure endpoint practices, sound judgment, and protection of enterprise systems and users
Positive, persistent, flexible, and able to adapt to changing priorities
Demonstrates intentional inclusion by collaborating respectfully across teams, listening to different perspectives, and building strong relationships with technical and non-technical partners
Drives superior performance through accountability, operational excellence, continuous improvement, and consistent follow-through
Candid, honest, authentic, resourceful, and able to exercise good judgment in complex or time-sensitive situations
About Southern Company
Southern Company (NYSE: SO ) is a leading energy provider serving 9 million customers across the Southeast and beyond through its family of companies. Providing clean, safe, reliable and affordable energy with excellent service is our mission. The company has electric operating companies in three states, natural gas distribution companies in four states, a competitive generation company, a leading distributed energy solutions provider with national capabilities, a fiber optics network and telecommunications services. Through an industry-leading commitment to innovation, resilience and sustainability, we are taking action to meet customers' and communities' needs while advancing our goal of net-zero greenhouse gas emissions by 2050. Our uncompromising values ensure we put the needs of those we serve at the center of everything we do and are the key to our sustained success. We are transforming energy into economic, environmental and social progress for tomorrow. Our corporate culture has been recognized by a variety of organizations, earning the company awards and recognitions that reflect Our Values and dedication to service. To learn more, visit www.southerncompany.com .
Southern Company invests in the well-being of its employees and their families through a comprehensive total rewards strategy that includes competitive base salary, annual incentive awards for eligible employees and health, welfare and retirement benefits designed to support physical, financial, and emotional/social well-being. This position may also be eligible for additional compensation, such as an incentive program, with the amount of any bonus/awards subject to the terms and conditions of the applicable incentive plan(s). A summary of the benefits offered for this position can be found here https://seo.nlx.org/southernco/pdf/SOCO-Benefits.pdf . Additional and specific details about total compensation and benefits will also be provided during the hiring process.
Southern Company is an equal opportunity employer where an applicant's qualifications are considered without regard to race, color, religion, sex, national origin, age, disability, veteran status, genetic information, sexual orientation, gender identity or expression, or any other basis prohibited by law.
Job Identification: 21153
Job Category: Information Technology
Job Schedule: Full time
Company: Southern Company Services