Endpoint Operations and Resilience Engineer
1 Year FTC,Worldwide / Hybrid / Remote (HQ - Reading, England)
Employees are expected to split their time among office locations, client sites, and remote work.
Baleen Labs is a small, highly capable technology consultancy serving clients in high-stakes operational environments. Over nearly five years, we have modernised legacy technology stacks, developed data strategies that unlock business value, and led transformation and optimisation initiatives.
In response to client demand, we are establishing an Information Security & Operations team. This team addresses inconsistencies across security posture, tenancy management, and endpoint control. We are building a small group of specialists distributed across multiple time zones to deliver follow-the-sun coverage for our clients.
Mission
The Endpoint Operations and Resilience Engineer will build and scale an endpoint configuration and management capability that delivers robust security without compromising operational continuity.
Our initial engagement involves a key client in the business aviation sector. Success requires proving that rigorous security controls can coexist with mission-critical flight operations, ensuring offline resilience for flight crews and eliminating shadow IT in a safety-sensitive environment.
Why This Work Matters
In high-stakes environments, security failures carry consequences beyond data breaches. For our aviation client, endpoint resilience directly affects operational safety and crew effectiveness. Shadow IT creates invisible attack surfaces that compromise mission assurance.
What Good Looks Like
Our approach rejects process for its own sake. We implement the right level of control for the specific risk profile, balancing protection with operational continuity. This pragmatism ensures security enables rather than hinders the work our clients depend on.
Good performance in this role means demonstrating engineering rigour, offline resilience thinking, and endpoint security tuning expertise. You understand that enterprise frameworks often contain redundant layers unsuitable for lean, agile in‑house teams. You can distinguish between what's truly necessary and administrative overhead.
We hire for depth of skill and breadth of curiosity. Our team operates without single points of failure. Each person has enough breadth to support adjacent domains when needed. Knowledge is shared openly rather than siloed. Handovers are precise and documented. Trust is built across distances through clear communication and consistent delivery.
Success is measured by resilient systems that withstand disruption, incident response that operates under constraint, and controls that remain effective in air‑gapped or degraded connectivity conditions.
Who We Are Looking For
These are not entry-level or “follow-the-script” roles. We need mission-driven individuals who can think critically, operate with minimal supervision, and refuse to rely on AI to substitute for their own analysis.
We seek practitioners who understand that security is a discipline of judgement, not automation. If you expect out‑of‑the‑box solutions to work without custom configuration, this position will frustrate you. If you view frameworks as starting points rather than prescriptions, you will thrive here.
The Role
Key Responsibilities:
- Engineer global endpoint hardening, mastering mobile application management and app wrapping for BYOD scenarios
- Oversee mobile device management strategies with enforcement of granular application isolation policies and immediate capability for selective remote wipes or device lockdowns
- Deploy and tune endpoint detection agents to ensure authentic threat visibility
- Guarantee mission‑critical applications function flawlessly in air‑gapped or low‑connectivity environments
- Manage immutable backups and conduct regular disaster recovery tests
- Rapidly deploy mitigations for newly disclosed endpoint vulnerabilities without waiting for vendor patches when necessary
- Understand identity and access management principles, particularly how they integrate with endpoint management platforms and influence security posture
- Provide consultation to SOC roles on endpoint telemetry quality and data collection requirements
Likely Background:
- Strong grounding in system internals and scripting
- Experience solving problems in unreliable connectivity environments
- Working knowledge of identity platforms and their role in endpoint security
- Evidence of adapting frameworks rather than applying them rigidly
- Experience in endpoint security or systems engineering roles
Systems Thinking: You understand why processes exist. You can take established enterprise frameworks and strip away redundancy to fit lean, agile teams. You adapt rather than imitate.
Pragmatic Risk Management: You implement controls proportional to actual risk. You reject process theatre in favour of outcomes that matter. You recognise that over‑engineering creates fragility.
Global Collaboration: You thrive in remote‑first, distributed teams. You prioritise clear documentation, precise handovers, and relationship‑building across time zones. You accept that success depends on trust earned through consistent action.
Continuous Learning: You track industry shifts including changes in NIST SP 800-63, OWASP guidelines, and MITRE ATT&CK frameworks. You translate emerging threats and best practices into operational improvements without waiting for directive.
Operational Depth: You possess genuine systems knowledge. You understand how things work beneath the abstraction layers. You do not expect out‑of‑the‑box solutions to solve custom challenges without configuration.
Coverage Mindset: You recognise that every specialist must understand adjacent domains. You willingly learn new technologies and step beyond your primary focus when team continuity demands it.
Identity Awareness: You understand that endpoint security and identity management converge. Familiarity with identity provider integration, conditional access, and authentication frameworks strengthens your ability to deliver holistic security outcomes.
Discretion: To the outside world - including friends and family in a casual setting - you "work in IT." You do not discuss who we serve, what we secure, or the specifics of our work. Your value is measured by your results, but your reputation is protected by your silence.
Outcomes
Within the first thirty days:
- Define and document a streamlined operating model, including follow‑the‑sun workflow and handover protocols
- Complete a baseline assessment of current configurations against industry standards such as CIS Benchmarks and NIST guidelines
- Establish internal knowledge repositories and initial security tooling configurations
Within sixty days:
- Launch the aviation sector proof of concept, executing tenant migration, mobile application management, and app wrapping for flight crews
- Ensure critical flight planning and navigation tools remain functional in offline or low‑connectivity environments
- Eliminate shadow IT by migrating communications to secure, managed channels
- Validate that security controls do not impede operational safety
- Achieve a fully functional, secure, and resilient environment
Beyond ninety days:
- Refine policies based on aviation proof of concept feedback
- Begin migrating cloud platform tenancy management for broader business units
- Conduct workshops with client IT leads to define governance boundaries
- Roll out endpoint detection and backup strategies to additional clients
- Re‑evaluate all deployed controls against emerging industry guidance
Applications close on Friday 4th September 2026
#J-18808-Ljbffr