Enterprise EndpointSecurity Engineer
I engineer endpoint security and automation across 14,000+ Windows and macOS devices. My work spans EDR, MDM, identity, and security-tool recovery when standard management paths fail.
Focus
Endpoint security, identity, and MDM
Strength
Automation and fleet recovery
Delivery
Validated changes with rollback plans
let profile = {
focus: 'Endpoint Security',
specialty: 'Identity + Automation',
experience: '10+ years',
location: 'Colorado Springs, CO',
email: 'root@bryant.dev',
}
Experience
Cybersecurity Engineer II
Ensemble Health Partners · Contract
Endpoint security, identity, and automation for 14,000+ Windows and macOS endpoints.
- Endpoint Security Engineering
- Build and maintain CrowdStrike Falcon policies plus PSFalcon and RTR workflows for investigation, containment, remediation, and recovery. Use RTR to repair broken security tooling when the usual management channels are unavailable.
- Lead the enterprise ThreatLocker deployment as its primary engineer and point of contact. Own policy design, Ringfencing, Secure Mode, application control, rollout decisions, agent recovery, and platform troubleshooting across the fleet.
- Device Management and Identity
- Manage macOS MDM (Jamf Pro), including system extensions, launchd services, security-tool deployment, and compliance remediation.
- Design and implement Intune, Entra ID, and Exchange Online controls for device, identity, and application access.
- Administer Palo Alto Networks GlobalProtect policies through Strata Cloud Manager to support secure remote access across the enterprise fleet.
- Automation and Rollouts
- Automate endpoint, identity, and Microsoft 365 administration with PowerShell, Python, Bash, Microsoft Graph, and REST APIs.
- Lead the migration from Delinea to Bitwarden. Own policy design, Entra ID onboarding groups, SCIM provisioning, SSO, use-case documentation, and the ServiceNow rollout plan.
Cybersecurity Engineer (ThreatLocker Specialist)
Contract
ThreatLocker policy and remediation engagement. Additional details are covered by NDA.
Cybersecurity Engineer
Visual Edge IT
Led EDR engineering and automation in an MSP/MSSP environment with 17,000+ endpoints across 700+ tenants. Served as the Tier 3 escalation point for endpoint investigations and difficult agent failures.
- EDR Engineering & Response
- Managed SentinelOne policies, STAR rules, exclusions, and indicator blocklists across the multi-tenant fleet.
- Designed configurable network quarantine policies in SentinelOne, using JSON allowlists for essential services (DNS/DHCP/DC) to avoid outages.
- Led CrowdStrike Falcon onboarding with Flight Control and parent/child CIDs. Wrote PowerShell scripts with PSFalcon to migrate policies across tenants.
- Automation and Recovery
- Built the SentinelOne AIO Toolkit, a PowerShell tool used to purge, install, roll back, and recover unhealthy agents at scale.
- Created Falcon Fusion workflows with Microsoft Teams for host isolation approvals, plus Microsoft Graph automation for Azure app registration.
- Application Control and Visibility
- Managed ThreatLocker Ringfencing and reviewed unknown binaries before approving execution.
- Standardized Horizon3.ai NodeZero assessments and routed firewall telemetry through Cribl into Splunk.
Linux Systems Administrator
HardenedVPN LLC
Administered a VPN platform spanning six regions, with responsibility for Linux systems, network security, and incident response.
- Managed Debian and RHEL systems, including patching, SSH access, service reliability, and host firewall policy.
- Designed L3/L4 DDoS protection using Cloudflare Magic Transit and GRE tunnels for latency-sensitive services.
- Diagnosed production issues through logs, process inspection, and configuration review; applied ACLs and rate limits during incidents.
System Administrator
Contract
Details under NDA
Sr. Technical Support Advisor III
Apple Inc.
Handled Tier 3 AppleCare escalations for complex macOS and iOS issues involving account security, data integrity, device trust, crashes, and performance.
- Used logs and structured troubleshooting to isolate software and system failures.
- Coached advisors through escalations and documented unusual defects for engineering and internal knowledge systems.
Technical Skills
Detailed Competencies
- Endpoint Security: CrowdStrike Falcon (policy engineering, RTR, PSFalcon), ThreatLocker (deployment lead, Ringfencing, Secure Mode), SentinelOne (multi-tenant administration, API)
- Endpoint Management: macOS MDM (Jamf Pro), system extensions, launchd services, Microsoft Intune, compliance remediation
- Automation: PowerShell, Python, Bash, JavaScript, Microsoft Graph, REST APIs
- Identity Engineering: Microsoft Entra ID (Conditional Access, SCIM provisioning, SSO), Bitwarden policy administration, Azure, Microsoft 365, Exchange Online
- Infrastructure and Networking: Palo Alto Networks GlobalProtect (policy management through Strata Cloud Manager), Windows Server, Linux, VMware, Hyper-V, VPNs, ACLs, VLANs, enterprise firewalls
- Security Operations: Incident response, fleet remediation, ServiceNow change control, Splunk, Cribl, Horizon3.ai NodeZero
Certifications
Selected Projects
SentinelOne AIO Toolkit
Built and maintain a PowerShell toolkit used in production to purge, install, roll back, and recover SentinelOne agents across mixed Windows environments. Added API integration, package hash checks, execution timeouts, and service-tree cleanup to repair failed deployments safely at scale.
Home Lab Platform
Built and operate a home lab with MikroTik routing and switching, 10 GbE, multi-VLAN segmentation, UniFi gateway and access points, Rocky Linux and Windows Server hosts, more than 100 TB of storage, containers, and security tooling for automation and incident-response testing.
Education
Cybersecurity Bootcamp
Colorado State University / Fullstack Academy
Completed 36 CEUs and 360 hours of hands-on labs in network, endpoint, and application security.
Placed first in the cohort's Capture-the-Flag competitions.