Certified Tanium Administration / Service Lead

Foresite
Foresite

United States · Remote

Posted on Aug 5, 2026

At Foresite, we deliver managed cybersecurity, endpoint certainty, and cloud security operations to organizations worldwide. Through our Tanium as a Service (TANIUMaaS) offerings, we eliminate the endpoint visibility gap, giving our clients 15-second real-time asset discovery, automated hygiene, and scale remediation.

We are seeking a Certified Tanium Administration & Service Lead to champion our managed Tanium capabilities, drive technical operations for our client base, and articulate the value of real-time endpoint management to both technical teams and executive stakeholders.

What you'll do:

As the Certified Tanium Administration / Service Lead, you will serve as Foresite’s core subject matter expert (SME) and operational leader for the Tanium platform. You will lead platform architecture, administration, deployment tuning, and service delivery across multi-tenant and dedicated customer environments. You will bridge technical delivery and customer enablement—guiding clients through continuous IT hygiene, vulnerability reduction, and operational best practices.

  • Act as the Tanium SME and thought leader: Serve as the primary technical point of contact and evangelist for Foresite’s Tanium offerings, leading workshops, operational reviews, and strategic technical discussions with client leadership, security teams, and IT operators.

  • Drive client enablement & use cases: Educate client teams on Tanium workflows, query construction, and platform best practices to maximize platform utilization and ROI. Translate complex Tanium modules (e.g., Asset, Discover, Patch, Deploy, Comply, Enforce) into actionable, high-value outcomes.

  • Architect platform & multi-tenant environments: Design, deploy, and maintain high-availability Tanium server infrastructure across multi-tenant MSSP customer environments, ensuring complete client data isolation and scalable operational delivery across on-prem, cloud, and hybrid estates.

  • Enforce RBAC governance: Architect and enforce strict RBAC policies, user roles, persona groups, and computer group boundaries to ensure granular operational control and adhere to strict multi-tenant access principles.

  • Fine-tune bandwidth & network controls: Configure Tanium network parameters—including bandwidth throttling limits, peer-to-peer linear chain protocols, and WAN/LAN rate limiting—to guarantee high-speed, sub-minute telemetry without impacting network infrastructure.

  • Manage custom sensors & package operations: Evaluate, test, and troubleshoot custom Tanium sensors, packages, action locks, saved queries, and scripts (PowerShell, Bash, Python) provided by developers or Tanium Content to safely meet tailored operational and security requirements.

  • Oversee service operations & SLAs: Manage service performance, deployment health checks, unmanaged device discovery, and vulnerability remediation metrics for managed clients.

  • Serve as Tier 3/4 escalation lead: Act as the final escalation point for complex Tanium client issues, agent troubleshooting, or service disruptions.

  • Build standard operating procedures (SOPs): Build and maintain internal playbooks, client onboarding frameworks, and automated operational runbooks to standardize managed delivery.

Who you are:

  • Experience: 5+ years of direct, hands-on experience administering and operating Tanium at scale (20,000+ endpoints).

  • Mastery of Tanium Architecture: Expert knowledge of Tanium Linear Chain architecture, peer-to-peer distribution, sensor mechanics, action locks, and role-based access controls (RBAC).

  • Comprehensive Module Knowledge: Deep hands-on experience across Core & Operations (Asset, Discover, Direct Connect, Trends, Client Management), Endpoint Management (Patch, Deploy, Performance, Provision), and Risk & Security (Comply, Reveal, Threat Response, Benchmark, Enforce).

  • Strong technical & scripting skills: Proficient in PowerShell, Bash, or Python for custom sensor and package development, with in-depth understanding of OS internals (Windows, macOS, Linux) and core networking concepts (TCP/IP, firewalls, subnets, proxies).

  • Strong client-facing communication: Ability to demystify complex technical architecture (e.g., linear-chain querying vs. legacy hub-and-spoke scan tools) to non-technical business leaders, backed by experience in an MSSP, consulting, or technical account management role.

  • Required Certifications: Must hold active certifications across all four Tanium domains:

    • Tanium Certified Operator (TCO)

    • Tanium Certified Administrator (TCA)

    • Tanium Certified Cloud Specialist (TCCS)

    • Tanium Certified Endpoint Management Specialist (TCEMS)

Nice to have:

  • Additional industry technical credentials: CISSP, CISM, GCED, or GSEC.

Why Join Foresite?

We are a mission-driven partner helping organizations navigate an increasingly complex threat landscape. Founded by security practitioners, we’ve grown into a global leader in SecOps and MDR by staying true to our core value: radical transparency. When you join Foresite, you are part of a "humans-first" culture where your expertise is valued, and your well-being is a priority. We leverage our Google Cloud Premier SecOps Partnership to stay at the cutting edge, but we know that our greatest asset is our people.

What We Offer

  • Comprehensive Health & Wellness: Robust medical insurance options to keep you and your family healthy.

  • Employer-Covered Insurance: We fully provide employer-paid Dental coverage, as well as Short-Term (STD) and Long-Term Disability (LTD).

  • Recharge & Refuel: We believe in a true work-life balance. You’ll start with 3 weeks of paid vacation, plus additional sick leave and paid company holidays to ensure you have time to recharge.

  • Growth & Mentorship: Access to world-class training and mentorship. We support your career trajectory, whether you’re looking to deepen your technical skills or move into leadership.

  • Impactful Work: Help protect global clients using the latest AI-enhanced security tools and GCP native technologies.