Job Description:
- Experienced in Microsoft Defender for Endpoint support, technical troubleshooting, and client-facing operational engagement.
- Focus on L2 MDE support, deeper issue investigation, policy deployment troubleshooting, stakeholder coordination, and escalation management during go-live, Hypercare, and warranty support.
- Provide L2 support for endpoint security migration activities focused on Microsoft Defender for Endpoint, Defender Antivirus, EDR configuration, Attack Surface Reduction rules, and related Intune-based policy deployment guidance.
- Investigate MDE onboarding, policy deployment behavior, endpoint configuration issues, AV exclusion or ASR rule concerns, and deviations from signed-off Defender design or build guidance.
- Review configuration evidence, screenshots, logs, connector status, device policy status, and troubleshooting inputs shared by client IT teams.
- Support go-live and Hypercare troubleshooting discussions for MDE policy deployment through Intune and endpoint security transition activities.
- Coordinate with endpoint, Intune, identity, SOC, and security teams to validate root cause, confirm remediation guidance, and track closure.
- Escalate unresolved or complex technical issues to L3 engineers, SMEs, or architects where deeper design or platform guidance is required.
- Maintain issue tracker updates, action notes, closure inputs, and clear support documentation during Hypercare and warranty phases.
Required technical skills:
- Experience in endpoint security support, Microsoft Defender for Endpoint operations, MDE onboarding support, or enterprise Microsoft security support.
- Hands-on understanding of Microsoft Defender for Endpoint, Defender Antivirus, EDR configuration, Attack Surface Reduction rules, and Intune policy deployment.
- Ability to investigate device policy status, configuration evidence, endpoint deployment issues, AV exclusions, ASR behavior, and operational exceptions.
- Familiarity with Entra ID Conditional Access, SOC integration touchpoints, Sentinel or Splunk inputs, and enterprise support governance.
- Good understanding of issue logging, technical triage, escalation, closure tracking, and evidence-based troubleshooting.
Requirements:
- Able to engage directly with client IT and security stakeholders, explain investigation findings clearly, and coordinate remediation guidance.
- Strong ownership mindset, structured troubleshooting approach, accurate documentation habits, and ability to manage L2 issues through closure or escalation.
Qualifications:
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field is preferred.
- Desirable Microsoft certifications include SC-200, MD-102, SC-900, SC-100, AZ-500, SC-300.
Preferred experience:
- Experience supporting Microsoft Defender for Endpoint in large enterprise endpoint security environments.
- Exposure to endpoint security migration, Defender Antivirus transition, MDE onboarding, and Intune-based Defender policy deployment.
- Experience supporting go-live, Hypercare, warranty support, and post-implementation stabilization activities.
- Exposure to regulated enterprise environments is advantageous.
- Experience working in client-facing support or delivery support environments is beneficial.
About you:
- You bring mature L2 MDE support capability, structured troubleshooting, and stakeholder confidence.
- You are evidence-driven, collaborative, practical, and comfortable escalating complex issues.