Microsoft Defender Engineer

Accelera Solutions Inc

  • Redmond, WA
  • 11 days ago
  • Remote

    Highlights

    Desired Skills: Other relevant cybersecurity certifications like Certified Information Systems Security Professional (CISSP), or Certified Information Security Manager (CISM), are a plus. Integrating Microsoft Defender, Intune, and Purview for Data Loss Prevention (DLP): Implement and manage DLP policies using Microsoft Defender for Endpoint.

    Numbers & Facts

    LocationRedmond, WA (
    Remote
    )

    Description

    This position is full time remote and requires the candidate hold an active secret clearance.

    Are you a dedicated cybersecurity expert looking to take the next step in your career? We're searching for a Microsoft Defender Engineer to join our dynamic team and implement top-notch security solutions for our Department of Defense (DOD) customer. If you're passionate about cybersecurity and eager to contribute to a critical mission, this could be the perfect opportunity for you!

    Responsibilities:

    1. Implementing Endpoint Detection and Response (EDR):
    • Deploy and fine-tune EDR solutions to monitor and respond to threats in real-time.
    1. Configuring Next-Generation Antivirus (NGAV):
    • Set up and configure NGAV to provide behavioral-based protection.
    • Optimize and tailor NGAV configurations for peak performance.
    1. Conducting Threat & Vulnerability Management:
    • Perform continuous vulnerability assessments and provide remediation recommendations.
    • Develop and execute strategies to mitigate endpoint vulnerabilities.
    1. Managing Attack Surface Reduction:
    • Implement and maintain rules and controls to minimize the attack surface of endpoints.
    • Regularly review and update strategies to stay ahead of emerging threats.
    1. Integrating Cloud-Delivered Protection:
    • Ensure real-time updates and threat intelligence from the Microsoft cloud are integrated.
    • Monitor and adjust cloud-delivered protection features for other services/applications hosted in Azure cloud.
    1. Connecting with SIEM Solutions:
    • Seamlessly connect Microsoft Defender with Microsoft Sentinel and other SIEM tools.
    • Create centralized logging, analytics, and reporting dashboards.
    1. Ensuring Cross-Platform Protection:
    • Guarantee comprehensive security across Windows, Linux, and mobile devices.
    • Manage and monitor security solutions on diverse platforms.
    1. Delivering Comprehensive Reporting and Analytics:
    • Create detailed reports on security posture, incidents, and compliance.
    • Develop customizable dashboards and alerts to keep the security operations center informed.
    1. Implementing Windows Defender Application Control (WDAC):
    • Design, implement, and manage WDAC policies to control which applications can run on endpoints.
    • Ensure WDAC configurations align with organizational security policies and compliance requirements.
    • Monitor and update WDAC policies to adapt to changing threat landscapes and business needs.
    1. Integrating Microsoft Defender, Intune, and Purview for Data Loss Prevention (DLP):
    • Implement and manage DLP policies using Microsoft Defender for Endpoint.
    • Ensure sensitive data on endpoints is monitored, classified, and protected against unauthorized access or exfiltration.
    • Configure and enforce device compliance and app protection policies using Microsoft Intune.
    • Ensure mobile devices meet security requirements before accessing corporate resources.
    • Discover, classify, and protect sensitive data across the organization using Microsoft Purview.
    • Create and enforce DLP policies in Microsoft 365 and other cloud services to ensure data compliance and security.
    • Monitor and report on DLP incidents, providing detailed alerts and insights to the security team.
    • Integrate Microsoft Defender, Intune, and Purview to create a robust, layered DLP strategy.
    • Ensure a comprehensive view of DLP incidents across endpoints, mobile devices, and cloud services.
    • Set up unified reporting and alerts for any policy violations or data exfiltration attempts.
    1. Applying the System Engineering Lifecycle:
    • Use knowledge of the System Engineering Lifecycle to design, implement, and maintain Microsoft Defender solutions and integrations.
    • Ensure all security solutions align with organizational goals and compliance requirements.

    Qualifications:

    • A Bachelor's degree in Computer Science, Information Security, or a related field. A Master's degree is a plus!
    • 8+ Years of relevant experience
    • Experience with Microsoft Defender for Endpoint, Cloud, and Servers.
    • Experience with endpoint security, threat hunting, and incident response.
    • Familiarity with SIEM solutions, especially Microsoft Sentinel.
    • Strong analytical and problem-solving skills to address complex security tooling challenges.
    • Excellent communication and collaboration skills to interact effectively with stakeholders at all levels.
    • Understanding of industry compliance standards (e.g., NIST) and relevant regulations (e.g., GDPR, HIPAA) is advantageous.
    • Willingness to stay updated with the latest cybersecurity trends and emerging security tools.
    • Required DoD 8140 compliant certification such as CompTIA Security+
    • Secret Clearance

    Desired Skills:

    • Other relevant cybersecurity certifications like Certified Information Systems Security Professional (CISSP), or Certified Information Security Manager (CISM), are a plus.
    • ServiceNow integrated workflows/automation
    • Experience administering and working with Linux operating systems, specifically Red Hat Enterprise Linux
    • Microsoft Active Directory/Entra
    • Microsoft Federation Services
    • Microsoft PowerBI Dashboarding
    • Advanced PowerShell scripting or prior software development experience
    • DoD PKI

    Accelera Solutions is an Equal Opportunity Employer/Veterans/Disabled.

    Similar Jobs