Apply
Description
Title: Microsoft Defender EndPoint (MDE) Location: Remote Role Start Date: ASAP Clearance required: Secret or TS Certification Required: IAT Level 2
Requirements
Job Summary:
The Microsoft Defender for Endpoint (MDE) Administrator is responsible for the deployment, configuration, and ongoing management of MDE to ensure endpoint security across the organization. This role plays a critical part in the cybersecurity posture of the company, helping to detect, investigate, and respond to threats at the endpoint level.
Key Responsibilities:
- Deploy and configure Microsoft Defender for Endpoint across Windows, macOS, Linux, and mobile platforms.
- Integrate MDE with other Microsoft security solutions such as Microsoft Sentinel, Microsoft 365 Defender, and Intune.
- Monitor, analyze, and respond to security alerts and incidents using the MDE Security Console.
- Manage device onboarding, policies, configurations, and threat indicators.
- Collaborate with SOC, IT, and compliance teams to maintain endpoint protection and threat detection standards.
- Create and maintain custom detection rules, automated remediation actions, and security baselines.
- Develop and maintain documentation including SOPs, configuration guides, and incident response playbooks.
- Ensure compliance with organizational policies, standards, and regulatory requirements (e.g., ISO, NIST, GDPR).
- Provide support for vulnerability and patch management processes via integration with MDE.
- Stay current with threat intelligence and Microsoft Defender product updates.
Required Skills & Qualifications:
- 3+ years of experience in cybersecurity, with at least 1-2 years specifically managing Microsoft Defender for Endpoint.
- Proficiency in Microsoft 365 Defender, Microsoft Intune, Azure Active Directory, and Group Policy.
- Solid understanding of endpoint detection and response (EDR) concepts.
- Familiarity with scripting and automation tools (e.g., PowerShell, KQL for custom queries).
- Experience with threat hunting, incident response, and remediation processes.
Preferred Qualifications:
- Experience in large enterprise environments.
- Knowledge of frameworks like MITRE ATT&CK, NIST, and Zero Trust architecture.
- Experience with SIEM solutions like Microsoft Sentinel or Splunk.
- Understanding of mobile threat defense integration and Bring Your Own Device (BYOD) security
|