Endpoint Privilege Management Engineer

Damia Group are supporting a leading global technology organisation with the appointment of an experienced BeyondTrust Endpoint Privilege Management (EPM) Engineer.

This is an exciting opportunity to join a large-scale, highly customised EPM environment operating within a secure enterprise setting.

The successful candidate will work closely with Application Packaging, Endpoint Engineering and Security teams, providing expert-level administration, troubleshooting and policy engineering across the BeyondTrust EPM platform.

Candidates with strong CyberArk Endpoint Privilege Manager experience will also be considered, particularly those with a strong endpoint security background who are willing to cross-train into BeyondTrust.

Location: Inverness or Manchester

Working Pattern: On-site within secure facilities

Shift Pattern: 24x7 operational rota

The Role

You will play a key role in maintaining and developing a complex enterprise EPM environment, ensuring applications can be deployed securely while maintaining appropriate privilege and application control policies.

Key Responsibilities

  • Administer, support and maintain a highly customised BeyondTrust EPM environment.
  • Design, implement and maintain policies covering privilege elevation, application control and allowlisting.
  • Work closely with Application Packaging and Endpoint Engineering teams to support application deployment.
  • Analyse application behaviour and identify appropriate privilege management requirements.
  • Troubleshoot complex EPM issues affecting application deployment, endpoint security and user productivity.
  • Develop, test and implement EPM policy changes while maintaining security and operational stability.
  • Support the onboarding of new applications into the EPM environment.
  • Investigate and resolve incidents relating to privilege elevation, application execution and endpoint control.
  • Collaborate with packaging, infrastructure and security teams to ensure application compatibility.
  • Carry out root cause analysis and implement appropriate remediation.
  • Maintain technical documentation, procedures, support guides and policy standards.
  • Contribute to continuous improvement and optimisation of the EPM platform.
  • Participate in a 24x7 operational support rota, including out-of-hours support where required.

Essential Skills & Experience

  • Strong hands-on experience administering and engineering BeyondTrust Endpoint Privilege Management (EPM).
  • Strong understanding of Windows endpoint security architecture.
  • Proven experience creating, modifying and troubleshooting BeyondTrust EPM policies.
  • Experience supporting application packaging and software deployment.
  • Strong knowledge of:
  • Windows Desktop Operating Systems
  • Application Control
  • Privilege Elevation
  • Endpoint Security
  • Software Packaging & Deployment
  • Group Policy Administration
  • Ability to assess application requirements and develop appropriate privilege management solutions.
  • Experience working with highly customised enterprise EPM environments.
  • Excellent troubleshooting and root cause analysis capabilities.
  • Experience working within secure, controlled or highly regulated environments.
  • Strong technical documentation and communication skills.
  • Ability to work independently within a complex operational environment.

Desirable Skills

  • CyberArk Endpoint Privilege Manager experience.
  • Experience migrating between EPM platforms.
  • Microsoft Intune, MECM/SCCM or equivalent endpoint management experience.
  • PowerShell scripting and automation.
  • Experience supporting large-scale enterprise endpoint environments.
  • ITIL-based operational experience.
  • Previous experience working within secure facilities or restricted-access environments.

Please note: Candidates must be able to work on-site from either Inverness or Manchester and be willing to participate in a 24x7 support rota.

Job Details

Company
Damia Group
Location
Manchester, England, United Kingdom
Posted