Security Engineer - Endpoint
Job Description
DXC Technology (NYSE: DXC) is a leading enterprise technology and innovation partner delivering software, services, and solutions to global enterprises and public sector organisations - helping them harness AI to drive outcomes at a time of exponential change with speed. With deep expertise in Managed Infrastructure Services, Application Modernisation, and Industry-Specific Software Solutions, DXC modernises, secures, and operates some of the world’s most complex technology estates. Learn more on dxc.com.
What you will be doing
DXC Managed Cyber Services (MCS) is the specialist, Digital Security division within DXC Technology. Our team provides a broad portfolio of security services offering end-to-end operational management of market-leading technologies and security services for local and multinational clients.
As part of our continued focus on the Australia and New Zealand market, we are enhancing the Security Engineering Team who work within the Secured Infrastructure capacity to deliver security services at the highest standard for our customers.
Only candidates able to gain or currently holding a current National Police Clearance and Australian Federal Government Security Clearance at Baseline will be considered for this role. Australian Citizenship is mandatory.
Who you will be working with
DXC Security is one of the few companies in Australia & New Zealand that can provide end-to-end security solutions—from expert advisory services to fully managed security operations, enabling the delivery of complete remediation plans and security improvement programs.
Responsibilities:
Facilitate the onboarding, deployment, management, and troubleshooting of Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR) services for managed clients
Assist in high-priority incidents including both infrastructure and security-related
Ensure security services—including policies, configuration, and compliance—meet or exceed industry best practices
Manage and maintain Application Allowlisting/Whitelisting policies, application ringfencing, and elevation requests to ensure a Zero Trust security posture on endpoints
Fulfill daily operational tasks to ensure all managed services meet Service Level Agreements (SLAs), actively identifying opportunities to automate repetitive administrative tasks
Implement and execute tasks to fulfill the project requirements
Keep up-to-date with a variety of security technologies, threat intelligence, and emerging AI-driven security tools
Liaise with vendors and their technical support/engineering team to provide advanced-level support
The skills you will bring:
At least 2 years’ experience working in IT/OT security operations for medium and/or large enterprises
Experience and good knowledge in implementation and/or managing and troubleshooting some of the following vendors’ technologies
EDR / XDR: Microsoft Defender (Defender for Endpoint, Microsoft Defender XDR suite, Defender for Cloud), CrowdStrike (Falcon platform), SentinelOne, and Trend Micro
Application Control: ThreatLocker and Airlock Digital
Experience working in cloud environment including Amazon Web Services/Microsoft Azure
Experience in high-priority incident response
Holder of relevant industry/vendor certifications such as Microsoft SC-200 (Security Operations Analyst), CrowdStrike Certified Falcon Administrator (CCFA) / Responder (CCFR), ThreatLocker Certifications / Airlock training, or general certifications like CISSP or CompTIA CySA+
Understanding of operating system internals (Windows, macOS, and Linux) to effectively analyze processes, memory, registry behaviours, and application dependencies
Strong team player with a can-do attitude who works well collaboratively
Highly Desirable (But Not Essential):
Automation & Scripting: Proficiency with languages like PowerShell, Python, or bash for automating deployment scripts, response actions, log collection, and application rule creation
API Integration: Experience utilizing RESTful APIs (such as the CrowdStrike Falcon API, Microsoft Graph API, or ThreatLocker/Airlock APIs) to automate reporting, threat intelligence ingestion, or custom alert notifications
Threat Hunting Queries: Familiarity with Kusto Query Language (KQL) for Microsoft or Event Search/LogScale syntax for CrowdStrike to conduct advanced threat hunting
Artificial Intelligence & Workflows: Familiarity with leveraging AI technologies (e.g., Microsoft Copilot for Security, or CrowdStrike Charlotte AI) to accelerate incident investigations and summarize complex threat data
Configuration Management / IaC: Knowledge of managing endpoint configurations at scale using tools like Microsoft Intune, SCCM, Ansible, or Terraform
