Endpoint Security & Exposure Engineer (Cyber Security)
Jacobs · Seattle, WA
—
Jul 16, 2026
Seattle, WA
Jul 21, 2026
What this job asks for AI summary
A senior cybersecurity engineering role centred on two connected disciplines: hardening endpoints across Windows, Linux, and macOS through application control, privilege management, and least-privilege policies; and running an enterprise vulnerability management programme that covers scanning, risk-based prioritisation, remediation tracking, and ServiceNow Vulnerability Response administration. The position suits an experienced security engineer comfortable bridging technical implementation and cross-team remediation governance.
Senior level · 5+ years · National
“or” means any one of them counts — you don't need all of them.
Posted 2 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
No work location is specified in the posting — city, state, and CBSA are unknown. The Jacobs EEO boilerplate does not indicate a specific geography.
The posting lists Rapid7, Tenable, and Qualys as interchangeable examples of 'leading vulnerability management platforms'; they are captured as a single required skill with alternatives rather than three separate gates.
Cloud platform requirement names Azure, AWS, and GCP as alternatives ('Azure, AWS, or Google Cloud') — captured as one required skill with alternatives.
Zero Trust and EDR appear under 'Preferred Qualifications' and are marked preferred accordingly.
Security frameworks (NIST CSF, CIS Controls, ISO 27001, NCSC CAF, Cyber Essentials Plus, ACSC Essential Eight) all appear under 'Preferred Qualifications'; only the most widely recognized are surfaced as preferred skills.
Preferred certifications (CISSP, GIAC, CompTIA Security+, CISM, ServiceNow CIS, Tenable Certified, Qualys Certified Specialist, Microsoft Security) are not emitted as skills — certifications are not named technologies or tools.
No compensation figures are stated in the posting.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Microsoft Defender for Endpoint.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.