Sr Engineer, Cybersecurity
T-Mobile USA, Inc.About the role
At T-Mobile, we invest in YOU! Our Total Rewards Package ensures that employees get the same big love we give our customers. All team members receive a competitive base salary and compensation package - this is Total Rewards. Employees enjoy multiple wealth-building opportunities through our annual stock grant, employee stock purchase plan, 401(k), and access to free, year-round money coaches. That’s how we’re UNSTOPPABLE for our employees!
Job OverviewThis role is essential for protecting enterprise endpoints and privileged access while maintaining the integrity of the organization’s cybersecurity infrastructure. It focuses on engineering, operating, and continuously improving endpoint security and privilege management platforms to defend against modern cyber threats. The role is distinguished by hands-on ownership of endpoint detection, response, and enforcement technologies, with a strong emphasis on proactive risk reduction. Success is measured by improved endpoint visibility, reduced attack surface, and effective response to endpoint-based incidents. The work strengthens organizational resilience and supports compliance and security objectives for internal and external stakeholders.
Job Responsibilities:
• Develops, engineers, and supports endpoint security and privilege management platforms (e.g., EDR, EPP, endpoint privilege controls) to protect against cyber threats and vulnerabilities
• Proactively identifies endpoint, identity, and privilege-related risks and implements mitigation measures across enterprise environments
• Collaborates with infrastructure, identity, and SOC teams to align endpoint security controls with organizational goals and regulatory requirements
• Enhances resilience to cyber incidents through endpoint detection, response, and containment practices
• Monitors, tunes, and maintains endpoint protection platforms, including agent health, performance, and enforcement policies
• Conducts regular endpoint security assessments, access reviews, and control validation activities
• Participates in other duties or projects as assigned
QUALIFICATIONS
Required Minimum Qualifications
• Bachelor’s Degree plus 5 years of related work experience OR Advanced degree with 3 years of related experience
• Acceptable areas of study include Computer Science or Information Technology
Additional Qualifications
• 4–7 years of experience with endpoint security platforms such as Microsoft Defender for Endpoint, SentinelOne, or similar EDR/EPP technologies
• 4–7 years of experience implementing or operating endpoint privilege management solutions (e.g., CyberArk EPM or equivalent)
• 4–7 years of experience managing endpoint protection policies, agent deployment, incident response, and threat remediation in enterprise environments
• 4–7 years of experience working with cloud-integrated security controls, including identity and access management platforms (e.g., Azure AD or equivalent)
Knowledge, Skills, and Abilities (required)
• Advanced understanding of endpoint security architecture, endpoint detection and response, privilege management, and identity-integrated security controls
• Strong problem-solving skills with the ability to exercise judgment and flexibility in complex environments
• Effective communication skills, including the ability to present technical concepts to varied audiences
• Ability to collaborate cross-functionally and build effective working relationships across teams
Licenses and Certifications:
- Certified Information Systems Security Professional (CISSP). (Preferred)
- Certified Information Security Manager (CISM) Offered by ISACA, this certification is for management-focused IT professionals who are responsible for developing, managing, and overseeing information security systems in enterprise-level applications, or for developing best organizational security practices. (Preferred)
- Certified in Risk & Informaitonal Systems Control (CRISC) Also provided by ISACA, CRISC is aimed at IT professionals, project managers, and others whose job it is to identify and manage risks to IT and the business. (Preferred)
- At least 18 years of age
- Legally authorized to work in the United States
Travel:
Travel Required (Yes/No): No
DOT Regulated:
DOT Regulated Position (Yes/No): No
Safety Sensitive Position (Yes/No): No
Base Pay Range: $103,400 - $186,400Corporate Bonus Target: 15%
The pay range above is the general base pay range for a successful candidate in the role. The successful candidate’s actual pay will be based on various factors, such as work location, qualifications, and experience, so the actual starting pay w
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s