
Search by job, company or skills
Security Analyst L2 Support Engineer - Endpoint Security Migration
Duration: 3 months contract
Key Responsibilities
. Provide L2 support for Microsoft Defender for Endpoint onboarding, Defender Antivirus, EDR configuration, Attack Surface Reduction rules, and Intune endpoint security policies.
. Investigate device policy status, endpoint configuration gaps, AV exclusions, ASR behavior, onboarding issues, connector status, logs, screenshots, and other troubleshooting evidence.
. Support go-live and Hypercare discussions related to MDE deployment, policy rollout, endpoint security transition, and post-implementation stabilization.
. Coordinate with endpoint, Intune, identity, SOC, and security teams to validate root cause, confirm remediation steps, and drive issue closure.
. Escalate complex or unresolved issues to L3 engineers, SMEs, or architects where deeper platform or design input is required.
. Maintain clear issue trackers, action notes, closure records, and support documentation throughout Hypercare and warranty support.
Required Skills
. Hands-on experience with Microsoft Defender for Endpoint, Defender Antivirus, EDR, Attack Surface Reduction, and Intune policy deployment.
. Strong troubleshooting skills across endpoint security operations, policy behavior, deployment exceptions, and evidence-based technical triage.
. Familiarity with Entra ID Conditional Access, SOC integration touchpoints, Microsoft Sentinel or Splunk inputs, and enterprise support governance.
. Ability to communicate investigation findings clearly to IT and security stakeholders and manage L2 issues through closure or escalation.
Qualifications and Preferred Experience
. Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related discipline is preferred.
. Microsoft certifications such as SC-200, MD-102, SC-900, SC-100, AZ-500, or SC-300 are desirable.
. Experience in large enterprise endpoint security environments, Defender Antivirus transition, MDE onboarding, Intune-based Defender policy deployment, Hypercare, warranty support, or regulated environments is advantageous.
Job ID: 153751481
Skills:
Siem, Network Monitoring Tools, IOC analysis, EDR, Threat hunting methodologies, YARA rules, Behavioral analysis, Threat intelligence platforms
Skills:
security automation , Dlp, Threat Hunting, Siem, automation, AWS, Azure, GNFA, identity telemetry, AI-enabled Security Operations, EDR, Cissp, gcih, MAS TRM, detection-as-code, MITRE ATT CK framework, SOAR, Detection Engineering, NIST CSF v2.0, ISO IEC 27001 2022, GCTI, DFIR, GREM, gcfa
Skills:
network traffic analysis , Change management, Siem, AWS, Log Analysis, Incident Management, Firewall, Scripting Languages, Waf, Cloud Security Monitoring, Ticketing system, Compliance Management, Microsoft MCAS, EDR, Incident ticket life cycle, Azure Security Center, SLA terms, Access Identity Management, Malware investigation and remediation, XDR, SOAR, SIEM correlation logic and alert generation, nids, Security incident and event management
Skills:
Threat Intelligence, Ips, Incident Response, Security Testing, Siem, Ids, Digital Forensics, Log Analysis, SOAR, TCP IP networking, Windows OS artifacts, malware behaviors, EDR, threat vulnerability response
Skills:
Incident Response, Vulnerability Management, PowerShell, Siem, Iso27001, Python, EDR, KQL, NIST CSF, SOC audits