This position is full time remote and requires the candidate hold an active secret clearance.
Are you a dedicated cybersecurity expert looking to take the next step in your career? We're searching for a Microsoft Defender Engineer to join our dynamic team and implement top-notch security solutions for our Department of Defense (DOD) customer. If you're passionate about cybersecurity and eager to contribute to a critical mission, this could be the perfect opportunity for you!
Responsibilities:
- Implementing Endpoint Detection and Response (EDR):
- Deploy and fine-tune EDR solutions to monitor and respond to threats in real-time.
- Configuring Next-Generation Antivirus (NGAV):
- Set up and configure NGAV to provide behavioral-based protection.
- Optimize and tailor NGAV configurations for peak performance.
- Conducting Threat & Vulnerability Management:
- Perform continuous vulnerability assessments and provide remediation recommendations.
- Develop and execute strategies to mitigate endpoint vulnerabilities.
- Managing Attack Surface Reduction:
- Implement and maintain rules and controls to minimize the attack surface of endpoints.
- Regularly review and update strategies to stay ahead of emerging threats.
- Integrating Cloud-Delivered Protection:
- Ensure real-time updates and threat intelligence from the Microsoft cloud are integrated.
- Monitor and adjust cloud-delivered protection features for other services/applications hosted in Azure cloud.
- Connecting with SIEM Solutions:
- Seamlessly connect Microsoft Defender with Microsoft Sentinel and other SIEM tools.
- Create centralized logging, analytics, and reporting dashboards.
- Ensuring Cross-Platform Protection:
- Guarantee comprehensive security across Windows, Linux, and mobile devices.
- Manage and monitor security solutions on diverse platforms.
- Delivering Comprehensive Reporting and Analytics:
- Create detailed reports on security posture, incidents, and compliance.
- Develop customizable dashboards and alerts to keep the security operations center informed.
- Implementing Windows Defender Application Control (WDAC):
- Design, implement, and manage WDAC policies to control which applications can run on endpoints.
- Ensure WDAC configurations align with organizational security policies and compliance requirements.
- Monitor and update WDAC policies to adapt to changing threat landscapes and business needs.
- Integrating Microsoft Defender, Intune, and Purview for Data Loss Prevention (DLP):
- Implement and manage DLP policies using Microsoft Defender for Endpoint.
- Ensure sensitive data on endpoints is monitored, classified, and protected against unauthorized access or exfiltration.
- Configure and enforce device compliance and app protection policies using Microsoft Intune.
- Ensure mobile devices meet security requirements before accessing corporate resources.
- Discover, classify, and protect sensitive data across the organization using Microsoft Purview.
- Create and enforce DLP policies in Microsoft 365 and other cloud services to ensure data compliance and security.
- Monitor and report on DLP incidents, providing detailed alerts and insights to the security team.
- Integrate Microsoft Defender, Intune, and Purview to create a robust, layered DLP strategy.
- Ensure a comprehensive view of DLP incidents across endpoints, mobile devices, and cloud services.
- Set up unified reporting and alerts for any policy violations or data exfiltration attempts.
- Applying the System Engineering Lifecycle:
- Use knowledge of the System Engineering Lifecycle to design, implement, and maintain Microsoft Defender solutions and integrations.
- Ensure all security solutions align with organizational goals and compliance requirements.
Qualifications:
- A Bachelor's degree in Computer Science, Information Security, or a related field. A Master's degree is a plus!
- 8+ Years of relevant experience
- Experience with Microsoft Defender for Endpoint, Cloud, and Servers.
- Experience with endpoint security, threat hunting, and incident response.
- Familiarity with SIEM solutions, especially Microsoft Sentinel.
- Strong analytical and problem-solving skills to address complex security tooling challenges.
- Excellent communication and collaboration skills to interact effectively with stakeholders at all levels.
- Understanding of industry compliance standards (e.g., NIST) and relevant regulations (e.g., GDPR, HIPAA) is advantageous.
- Willingness to stay updated with the latest cybersecurity trends and emerging security tools.
- Required DoD 8140 compliant certification such as CompTIA Security+
- Secret Clearance
Desired Skills:
- Other relevant cybersecurity certifications like Certified Information Systems Security Professional (CISSP), or Certified Information Security Manager (CISM), are a plus.
- ServiceNow integrated workflows/automation
- Experience administering and working with Linux operating systems, specifically Red Hat Enterprise Linux
- Microsoft Active Directory/Entra
- Microsoft Federation Services
- Microsoft PowerBI Dashboarding
- Advanced PowerShell scripting or prior software development experience
- DoD PKI
Accelera Solutions is an Equal Opportunity Employer/Veterans/Disabled.