Microsoft Defender Administrator

 Posted 2 hours ago
  
 Worldwide
  
2-5 years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

The role involves monitoring EDR and NGAV solutions to detect threats and maintain the security posture for a DOD customer. Responsibilities include integrating Microsoft Defender with SIEM tools and implementing DLP and WDAC policies.
Job DetailsThis position is full time remote and requires the candidate hold an active secret clearance. Are you detail-oriented and passionate about cybersecurity? We’re searching for a Microsoft Defender Operator to join our dynamic team and ensure the smooth, day-to-day operation of our Microsoft Defender services for our Department of Defense (DOD) customer. If you’re committed to maintaining high security standards and eager to contribute to a critical mission, this could be the perfect opportunity for you! Responsibilities: 1.    Monitoring Endpoint Detection and Response (EDR): •    Continuously monitor EDR solutions to detect and report threats to the Security Operations Center (SOC) in real-time. 2.    Managing Next-Generation Antivirus (NGAV): •    Ensure NGAV solutions are running optimally and address any alerts or issues. •    Perform routine checks and updates to maintain peak performance. 3.    Maintaining Attack Surface Reduction: •    Ensure rules and controls are in place to minimize the attack surface of endpoints, as provided by the SOC •    Report any deviations or issues to the engineering team for review. 4.    Integrating Cloud-Delivered Protection: •    Verify that real-time updates and threat intelligence from the Microsoft cloud are being received and applied. •    Report any discrepancies or issues to the engineering team. 5.    Connecting with SIEM Solutions: •    Ensure seamless integration of Microsoft Defender with Microsoft Sentinel and other SIEM tools. •    Monitor and maintain centralized logging, analytics, and reporting dashboards. •    Perform data analysis via the SIEM tool as required. 6.    Ensuring Cross-Platform Protection: •    Verify comprehensive security across Windows, Linux, and mobile devices. •    Report any platform-specific issues to the engineering team. 7.    Delivering Comprehensive Reporting and Analytics: •    Generate and review detailed reports on security posture, incidents, and compliance. •    Ensure dashboards and alerts are functioning correctly and report any issues. 8.    Applying Prescribed Procedures: •    Follow established procedures and guidelines for maintaining Microsoft Defender solutions. •    Escalate any issues or anomalies to the engineering team. 9.    Implementing Windows Defender Application Control (WDAC): •    Ensure WDAC policies are correctly applied and functioning as intended. •    Report any policy violations or issues to the engineering team. 10.    Integrating Microsoft Defender, Intune, and Purview for Data Loss Prevention (DLP): •    Ensure DLP policies are correctly implemented and functioning across endpoints, mobile devices, and cloud services. •    Implement approved DLP waivers for authorized users and devices. •    Monitor DLP incidents and report any policy violations or data exfiltration attempts to the engineering team. •    Maintain unified reporting and alerts for any DLP-related issues.Qualifications•    A Bachelor’s degree in Computer Science, Information Security, or a related field. •    3+ Years of relevant experience •    Experience with Microsoft Defender for Endpoint, Cloud, and Servers. •    Familiarity with endpoint security, threat hunting, and incident response. •    Familiarity with SIEM solutions, especially Microsoft Sentinel. •    Excellent attention to detail and problem-solving skills. •    Good communication and collaboration skills to interact effectively with stakeholders at all levels. •    Understanding of industry compliance standards (e.g., NIST) and relevant regulations (e.g., GDPR, HIPAA) is advantageous. •    Willingness to stay updated with the latest cybersecurity trends and emerging security tools. •    Required DoD 8140 compliant certification such as CompTIA Security+ •    Secret Clearance  Desired Skills: •    Experience with ServiceNow or other ticketing system •    Experience administering and working with Windows and Linux operating systems •    Microsoft Active Directory/Entra •    Microsoft PowerBI Dashboarding •    Advanced PowerShell scripting or prior software development experience •    DoD PKI Accelera Solutions is an Equal Opportunity Employer/Veterans/Disabled.

Similar Jobs

See all Remote Software Development jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Software Development

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified