Haystack
← Back to Jobs
Technology
IS

Level 3 End User Security Engineer (Microsoft Defender for Endpoint)

InnoCore Solutions, Inc.Dallas, TX🇺🇸United StatesPosted Sep 19, 2026

Why This Role Stands Out

This hybrid role offers significant opportunities to deepen your expertise in Microsoft Defender for Endpoint, directly impacting enterprise security and providing a senior escalation point for critical incidents. You'll thrive here if you excel at advanced threat hunting, incident investigation using KQL, and enjoy collaborative problem-solving within a reputable technology company. This is a fantastic opportunity to advance your skills and career in a dynamic environment.

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Dallas, TX, United States
Posted
1 week ago

Job Description

We are looking for a highly skilled Level 3 End User Security Engineer responsible for administering, troubleshooting, monitoring, and enhancing endpoint security using Microsoft Defender for Endpoint (MDE). This role will serve as a senior escalation point for complex endpoint security incidents and will work closely with Security Operations, Infrastructure, Identity, and End User Computing teams.

Responsibilities:

  • Serve as the Level 3 escalation point for complex endpoint security incidents, problems, and vulnerabilities.
  • Administer, monitor, and optimize Microsoft Defender for Endpoint (MDE) across enterprise Windows endpoints.
  • Investigate and respond to malware, ransomware, phishing, suspicious processes, credential theft, and other endpoint security threats.
  • Perform advanced threat hunting and incident investigation using Microsoft Defender Advanced Hunting and KQL.
  • Analyze endpoint timelines, process trees, command-line activity, file/registry changes, network connections, and other security telemetry.
  • Perform endpoint containment and remediation activities, including device isolation, antivirus scans, Live Response, and remote remediation.
  • Develop KQL queries, custom detections, dashboards, and threat-hunting queries to identify suspicious activity across the enterprise.
  • Participate in security incident response, vulnerability remediation, security projects, and continuous improvement initiatives.
  • Maintain appropriate documentation, audit trails, metrics, and reporting for endpoint security operations.

Requirements:

  • 5+ years of experience in endpoint security, Windows security, cybersecurity, or related IT infrastructure roles.
  • 3+ years of hands-on experience with Microsoft Defender for Endpoint (MDE) in a medium-to-large enterprise environment.
  • Ability to develop KQL queries for threat hunting, investigation, detection, and security analytics.
  • Experience working in an L3 escalation/support environment and independently resolving complex technical issues.
  • Strong understanding of security incident response processes and evidence preservation.
  • Excellent troubleshooting, analytical, communication, documentation, and problem-solving skills.

Education:

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering or a related field.

Similar jobs