Skip to main content
Posted 27 July, 2026

Staff Endpoint Security Engineer

ChargePoint
IN-HR-Gurugram-418-419 Full Time
Reference: 102_698740_8575164002

Reports To

Senior Manager - Information Security

ChargePoint is seeking a Staff Endpoint Security Engineer to own and advance our endpoint security programme. This is a hands-on security engineering role focused on protecting corporate assets through EDR, DLP, and insider threat detection and response. You will be responsible for the full lifecycle of endpoint security tooling: deployment, policy management, alert triage, threat hunting, and continuous improvement. You will also develop novel detection use cases and monitoring strategies to stay ahead of emerging threats.

What You Will Be Doing

  • Lead insider threat detection and response efforts - build and maintain detection logic, investigate anomalous user behaviour, and drive incident response for insider threat cases.
  • Manage and mature the enterprise Data Loss Prevention (DLP) programme: define and refine DLP policies, monitor alerts, investigate violations, and coordinate remediation with stakeholders.
  • Own the end-to-end management of the enterprise EDR platform - deployment, policy configuration, tuning, and ongoing optimisation across Windows, macOS, and Linux endpoints.
  • Develop new detection use cases, monitoring strategies and automation workflows for endpoint-based threats, leveraging telemetry from EDR, DLP, UEBA, and other endpoint security tools.
  • Triage, investigate, and respond to endpoint security alerts; perform root cause analysis and recommend containment and remediation actions.
  • Conduct proactive threat hunting across endpoint telemetry to identify advanced threats and attacker techniques that evade signature-based detection.
  • Collaborate with the SOC, threat intelligence, and incident response teams to correlate endpoint findings with broader security events.
  • Evaluate, recommend, and integrate new endpoint security technologies and capabilities as the threat landscape evolves.
  • Develop and maintain runbooks, standard operating procedures, and documentation for endpoint security operations and incident response workflows.
  • Produce metrics, dashboards, and executive-level reports on endpoint security posture, alert trends, and insider threat programme maturity.
  • Partner with IT and infrastructure teams to provide security guidance on endpoint hardening, configuration baselines, and secure deployment practices.

What You Will Bring to ChargePoint

  • 7+ years of experience in information security, with at least 5 years focused on endpoint security engineering.
  • Deep hands-on expertise with enterprise EDR platforms (e.g., CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, Carbon Black).
  • Strong experience deploying, managing, and tuning enterprise DLP solutions (e.g., Microsoft Purview, Symantec DLP, Cyberheaven).
  • Demonstrated experience in insider threat detection and response, including familiarity with UEBA tools and behavioural analytics.
  • Proven ability to develop custom detection rules, use cases, and correlation logic for endpoint-based threats.
  • Experience with SOAR platforms and security automation for endpoint alert triage and response.
  • Solid understanding of endpoint hardening, OS internals (Windows, macOS, Linux), and attack surface reduction techniques.
  • Experience with MITRE ATT&CK framework and its application to endpoint threat detection and threat hunting.
  • Strong scripting and automation skills (Python, PowerShell, Bash) to build tooling, automate workflows, and parse telemetry.
  • Excellent analytical, investigative, and problem-solving skills with the ability to work under pressure during active incidents.
  • Strong written and verbal communication skills; ability to present technical findings to both security peers and executive leadership.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field or equivalent practical experience.

Good to Have

  • Knowledge of user onboarding and offboarding processes and the security controls that should be embedded in those workflows - ability to guide IT teams on automation policies for access provisioning and de-provisioning.
  • Experience with SOAR platforms and security automation for endpoint alert triage and response.
  • Familiarity with Zero Trust architecture principles and their application to endpoint security.
  • Industry certifications such as GCFE, GCIH, GREM, OSCP, CISSP, or equivalent.
  • Experience in securing endpoints in cloud-first or hybrid environments (AWS, Azure, GCP).
  • Prior experience in the EV, automotive, or critical infrastructure industry.

Location

Gurgaon/Remote

Sign up for Job Alerts