
Search by job, company or skills
Job Summary:
We are seeking a Microsoft Defender for Endpoint (MDE) Implementation Engineer responsible for designing, deploying, and managing Microsoft Defender for Endpoint to enhance endpoint security, threat detection, and automated response. The role involves integration with security tools, endpoint hardening, policy tuning, and automation of incident response workflows.
Key Responsibilities:
1. Deployment & Configuration of Microsoft Defender for Endpoint (MDE):
Deploy and configure MDE security policies across Windows, macOS, Linux, and mobile devices.
Integrate MDE with Microsoft 365 Defender, Azure Security Center, and SIEM platforms (Sentinel, Splunk, QRadar).
Configure attack surface reduction (ASR) rules, endpoint detection & response (EDR), and advanced hunting capabilities.
Implement automated remediation and containment actions for infected endpoints.
2. Endpoint Security & Threat Protection:
Configure real-time malware protection, behavior-based blocking, and next-gen antivirus (NGAV).
Enable exploit protection, web content filtering, and device control (USB, Bluetooth, network isolation).
Develop custom endpoint protection policies to reduce attack surface risks.
3. Integration & Log Management:
Integrate MDE with SIEM (Microsoft Sentinel, Splunk, QRadar) for log collection and correlation.
Configure Threat Intelligence feeds for proactive threat detection.
Enable endpoint event forwarding (EEF) for deep forensic analysis.
4. Threat Hunting & Incident Response:
Develop Kusto Query Language (KQL) queries for threat hunting in Microsoft 365 Defender Portal.
Investigate malware infections, lateral movement, and suspicious endpoint behavior.
Perform incident triage, threat containment, and root cause analysis.
Automate remediation actions using Microsoft Defender XDR playbooks.
5. SOAR & Automation (Defender Automated Investigation & Remediation - AIR):
Implement SOAR workflows using Microsoft Security Orchestration, Automation, and Response (SOAR).
Automate device isolation, process termination, and IOC blocking.
Create Power Automate & Logic Apps-based automation workflows for MDE alerts.
6. Performance Optimization & Best Practices:
Optimize MDE configurations to reduce false positives and enhance detection accuracy.
Fine-tune EDR detections and hunting queries for zero-trust endpoint security.
Monitor MDE health, performance, and latency issues.
Job ID: 144987671