Tech Stack
ITSMJamfLinuxMacOSPythonServiceNow
About the role
- Manage, administer, and optimize Tanium modules including Enforce, Threat Response, Comply, Interact, Patch, Deploy, Certificate Manager, Performance, Investigate, and Impact.
- Configure and apply security baselines and policies (Enforce).
- Conduct real-time threat hunting, forensics, and incident response (Threat Response & Investigate).
- Monitor and report endpoint compliance against CIS, NIST, and custom baselines (Comply).
- Design and execute patch deployment strategies and software rollouts (Patch & Deploy).
- Track, manage, and alert on endpoint certificates across the enterprise (Certificate Manager).
- Monitor and analyze endpoint performance metrics and operational impact (Performance & Impact).
- Build and optimize Tanium sensors, packages, and saved questions for visibility and control (Interact).
- Develop custom Tanium content (sensors, packages, dashboards) tailored to business and security requirements.
- Automate endpoint management tasks using PowerShell, Python, Shell, or VBScript.
- Integrate Tanium with SIEM, ITSM, configuration management, and XDR tools.
- Collaborate with security, infrastructure, and endpoint teams to support compliance, incident response, and operational efficiency.
- Provide documentation, training, and knowledge transfer to stakeholders and internal teams.
- Support lifecycle upgrades and health of Tanium infrastructure and endpoints.
Requirements
- 5+ years of experience in IT security or endpoint management, with at least 3 years of direct Tanium platform experience.
- Deep knowledge and hands-on experience with multiple Tanium modules (Enforce, Threat Response, Comply, Interact, Patch, Deploy, Certificate Manager, Performance, Investigate, Impact).
- Proficiency in scripting languages: PowerShell, Python, Shell (Bash), and VBScript.
- Strong experience building and maintaining custom sensors, packages, and scheduled actions in Tanium.
- Familiarity with endpoint hardening standards, vulnerability management practices, and threat hunting methodologies.
- Experience with enterprise OS platforms (Windows, macOS, Linux).
- Excellent troubleshooting, documentation, and collaboration skills.
- Preferred: Experience with Microsoft Defender for Endpoint and integration with Tanium.
- Preferred: Familiarity with Intune, SCCM, JAMF, or other endpoint management platforms.
- Preferred: Experience integrating Tanium with ServiceNow, or Sentinel.
- Preferred: Tanium Certified Operator or Tanium Certified Administrator certification.
ATS Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
TaniumPowerShellPythonShellVBScriptendpoint managementthreat huntingvulnerability managementendpoint hardeningcustom sensors
Soft skills
troubleshootingdocumentationcollaboration
Certifications
Tanium Certified OperatorTanium Certified Administrator