Deploy and configure Microsoft Defender XDR components across multiple client tenants, including Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps.
Job Responsibilities
- Onboard endpoints, servers, and identities into the Defender platform and validate signal flow and telemetry health.
- Configure and tune attack surface reduction rules, endpoint detection and response policies, and automated investigation and remediation settings.
- Fine-tune alert and detection policies to reduce noise while maintaining detection coverage across each client setting.
- Integrate Defender XDR with Microsoft Sentinel to ensure unified incident correlation and a single pane of glass for the SOC team.
- Configure and manage threat and vulnerability management, generating remediation guidance for clients based on exposure findings.
- Investigate complex,
cross-domain incidents that span endpoint, identity, and email signals, then hand off enriched context to SOC Analysts.
- Support client onboarding by scoping Defender licensing, deployment prerequisites, and rollout planning.
- Produce and maintain client-facing configuration documentation, deployment runbooks, and hardening guides.
- Advise clients on security posture improvements using Microsoft Secure Score and Defender recommendations.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.