Enterprise EndpointSecurity Engineer

I engineer endpoint security and automation across 14,000+ Windows and macOS devices. My work spans EDR, MDM, identity, and security-tool recovery when standard management paths fail.

14,000+ enterprise endpoints17,000+ MSSP fleet700+ tenants

Focus

Endpoint security, identity, and MDM

Strength

Automation and fleet recovery

Delivery

Validated changes with rollback plans

let profile = {

focus: 'Endpoint Security',

specialty: 'Identity + Automation',

experience: '10+ years',

location: 'Colorado Springs, CO',

email: 'root@bryant.dev',

}

Experience

Cybersecurity Engineer II

Ensemble Health Partners · Contract

2026 - Present

Endpoint security, identity, and automation for 14,000+ Windows and macOS endpoints.

  • Endpoint Security Engineering
    • Build and maintain CrowdStrike Falcon policies plus PSFalcon and RTR workflows for investigation, containment, remediation, and recovery. Use RTR to repair broken security tooling when the usual management channels are unavailable.
    • Lead the enterprise ThreatLocker deployment as its primary engineer and point of contact. Own policy design, Ringfencing, Secure Mode, application control, rollout decisions, agent recovery, and platform troubleshooting across the fleet.
  • Device Management and Identity
    • Manage macOS MDM (Jamf Pro), including system extensions, launchd services, security-tool deployment, and compliance remediation.
    • Design and implement Intune, Entra ID, and Exchange Online controls for device, identity, and application access.
    • Administer Palo Alto Networks GlobalProtect policies through Strata Cloud Manager to support secure remote access across the enterprise fleet.
  • Automation and Rollouts
    • Automate endpoint, identity, and Microsoft 365 administration with PowerShell, Python, Bash, Microsoft Graph, and REST APIs.
    • Lead the migration from Delinea to Bitwarden. Own policy design, Entra ID onboarding groups, SCIM provisioning, SSO, use-case documentation, and the ServiceNow rollout plan.
CrowdStrike Falcon / RTRThreatLockermacOS MDM (Jamf Pro)Microsoft IntuneMicrosoft Entra ID / SCIM / SSOPalo Alto GlobalProtect / Strata Cloud ManagerPowerShell / Microsoft GraphServiceNow Change Control

Cybersecurity Engineer (ThreatLocker Specialist)

Contract

2026 - Present

ThreatLocker policy and remediation engagement. Additional details are covered by NDA.

ThreatLockerEndpoint SecurityApplication Allowlisting

Cybersecurity Engineer

Visual Edge IT

2025

Led EDR engineering and automation in an MSP/MSSP environment with 17,000+ endpoints across 700+ tenants. Served as the Tier 3 escalation point for endpoint investigations and difficult agent failures.

  • EDR Engineering & Response
    • Managed SentinelOne policies, STAR rules, exclusions, and indicator blocklists across the multi-tenant fleet.
    • Designed configurable network quarantine policies in SentinelOne, using JSON allowlists for essential services (DNS/DHCP/DC) to avoid outages.
    • Led CrowdStrike Falcon onboarding with Flight Control and parent/child CIDs. Wrote PowerShell scripts with PSFalcon to migrate policies across tenants.
  • Automation and Recovery
    • Built the SentinelOne AIO Toolkit, a PowerShell tool used to purge, install, roll back, and recover unhealthy agents at scale.
    • Created Falcon Fusion workflows with Microsoft Teams for host isolation approvals, plus Microsoft Graph automation for Azure app registration.
  • Application Control and Visibility
    • Managed ThreatLocker Ringfencing and reviewed unknown binaries before approving execution.
    • Standardized Horizon3.ai NodeZero assessments and routed firewall telemetry through Cribl into Splunk.
SentinelOneCrowdStrike FalconPowerShell / AutomationThreatLockerMicrosoft GraphSplunk / Cribl

Linux Systems Administrator

HardenedVPN LLC

2019 - 2024

Administered a VPN platform spanning six regions, with responsibility for Linux systems, network security, and incident response.

  • Managed Debian and RHEL systems, including patching, SSH access, service reliability, and host firewall policy.
  • Designed L3/L4 DDoS protection using Cloudflare Magic Transit and GRE tunnels for latency-sensitive services.
  • Diagnosed production issues through logs, process inspection, and configuration review; applied ACLs and rate limits during incidents.
Linux AdministrationNetwork Securityiptables / nftablesCloudflare Magic TransitVPN Infrastructure

System Administrator

Contract

2017 - 2019

Details under NDA

FirewallsInformation SecuritySystems Administration

Sr. Technical Support Advisor III

Apple Inc.

2014 - 2017

Handled Tier 3 AppleCare escalations for complex macOS and iOS issues involving account security, data integrity, device trust, crashes, and performance.

  • Used logs and structured troubleshooting to isolate software and system failures.
  • Coached advisors through escalations and documented unusual defects for engineering and internal knowledge systems.
macOS / iOSTier 3 EscalationAccount SecurityTechnical Documentation

Technical Skills

Core platforms:CrowdStrike FalconThreatLockermacOS MDM (Jamf Pro)Microsoft Entra IDBitwarden
Endpoint Security
Endpoint Management
Identity Engineering
Security Automation
Security Operations
Infrastructure

Detailed Competencies

  • Endpoint Security: CrowdStrike Falcon (policy engineering, RTR, PSFalcon), ThreatLocker (deployment lead, Ringfencing, Secure Mode), SentinelOne (multi-tenant administration, API)
  • Endpoint Management: macOS MDM (Jamf Pro), system extensions, launchd services, Microsoft Intune, compliance remediation
  • Automation: PowerShell, Python, Bash, JavaScript, Microsoft Graph, REST APIs
  • Identity Engineering: Microsoft Entra ID (Conditional Access, SCIM provisioning, SSO), Bitwarden policy administration, Azure, Microsoft 365, Exchange Online
  • Infrastructure and Networking: Palo Alto Networks GlobalProtect (policy management through Strata Cloud Manager), Windows Server, Linux, VMware, Hyper-V, VPNs, ACLs, VLANs, enterprise firewalls
  • Security Operations: Incident response, fleet remediation, ServiceNow change control, Splunk, Cribl, Horizon3.ai NodeZero

Certifications

Selected Projects

SentinelOne AIO Toolkit

Creator & Maintainer2025

Built and maintain a PowerShell toolkit used in production to purge, install, roll back, and recover SentinelOne agents across mixed Windows environments. Added API integration, package hash checks, execution timeouts, and service-tree cleanup to repair failed deployments safely at scale.

PowerShellAutomationSentinelOne API

Home Lab Platform

Designer & OperatorOngoing

Built and operate a home lab with MikroTik routing and switching, 10 GbE, multi-VLAN segmentation, UniFi gateway and access points, Rocky Linux and Windows Server hosts, more than 100 TB of storage, containers, and security tooling for automation and incident-response testing.

Rocky LinuxWindows ServerMikroTikUniFi

Education

Cybersecurity Bootcamp

2023

Colorado State University / Fullstack Academy

Completed 36 CEUs and 360 hours of hands-on labs in network, endpoint, and application security.

Placed first in the cohort's Capture-the-Flag competitions.