Why This Role Stands Out
This hybrid role offers significant opportunities to deepen your expertise in Microsoft Defender for Endpoint, directly impacting enterprise security and providing a senior escalation point for critical incidents. You'll thrive here if you excel at advanced threat hunting, incident investigation using KQL, and enjoy collaborative problem-solving within a reputable technology company. This is a fantastic opportunity to advance your skills and career in a dynamic environment.
Quick Overview
Job Description
We are looking for a highly skilled Level 3 End User Security Engineer responsible for administering, troubleshooting, monitoring, and enhancing endpoint security using Microsoft Defender for Endpoint (MDE). This role will serve as a senior escalation point for complex endpoint security incidents and will work closely with Security Operations, Infrastructure, Identity, and End User Computing teams.
Responsibilities:
- Serve as the Level 3 escalation point for complex endpoint security incidents, problems, and vulnerabilities.
- Administer, monitor, and optimize Microsoft Defender for Endpoint (MDE) across enterprise Windows endpoints.
- Investigate and respond to malware, ransomware, phishing, suspicious processes, credential theft, and other endpoint security threats.
- Perform advanced threat hunting and incident investigation using Microsoft Defender Advanced Hunting and KQL.
- Analyze endpoint timelines, process trees, command-line activity, file/registry changes, network connections, and other security telemetry.
- Perform endpoint containment and remediation activities, including device isolation, antivirus scans, Live Response, and remote remediation.
- Develop KQL queries, custom detections, dashboards, and threat-hunting queries to identify suspicious activity across the enterprise.
- Participate in security incident response, vulnerability remediation, security projects, and continuous improvement initiatives.
- Maintain appropriate documentation, audit trails, metrics, and reporting for endpoint security operations.
Requirements:
- 5+ years of experience in endpoint security, Windows security, cybersecurity, or related IT infrastructure roles.
- 3+ years of hands-on experience with Microsoft Defender for Endpoint (MDE) in a medium-to-large enterprise environment.
- Ability to develop KQL queries for threat hunting, investigation, detection, and security analytics.
- Experience working in an L3 escalation/support environment and independently resolving complex technical issues.
- Strong understanding of security incident response processes and evidence preservation.
- Excellent troubleshooting, analytical, communication, documentation, and problem-solving skills.
Education:
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering or a related field.
Similar jobs
- AS
Information Security Analyst IV
NewApex Systems
Cincinnati, OH🇺🇸On-site14 hours agoEncryptionTechnology - AS
CipherTrust Security Engineer
NewApex Systems
Columbus, OH🇺🇸Hybrid14 hours agoEncryptionScrumAgile+6Technology - LE
IT Security Engineer
NewLeidos
Silver Spring, MD🇺🇸$107.9k - $195.1k/yrRemoteYesterdaySpringTCP/IPTechnology - LE
IT Security Engineer
NewLeidos
Rockville, MD🇺🇸$107.9k - $195.1k/yrRemoteYesterdayTechnology - LE
IT Security Engineer
NewLeidos
Glen Echo, MD🇺🇸$107.9k - $195.1k/yrRemoteYesterdayEchoTCP/IPTechnology - LE
IT Security Engineer
NewLeidos
Arlington, VA🇺🇸$107.9k - $195.1k/yrRemoteYesterdayTechnology