L2 Microsoft Defender for Endpoint (MDE) Support Engineer

Recruitment agencyELLIOTT MOSS CONSULTING PTE. LTD.Singaporemycareersfuturepublished 07/22/2026
Must-have:Security

Job Description

  • We are seeking an experienced L2 Microsoft Defender for Endpoint (MDE) Support Engineer to support enterprise endpoint security migration initiatives.
  • The ideal candidate will have strong expertise in Microsoft Defender for Endpoint, Defender Antivirus, Intune policy deployment, EDR configuration, and endpoint troubleshooting, with experience supporting go-live, Hypercare, and post-implementation activities.

Key Responsibilities

  • Provide L2 support for endpoint security migration activities focused on Microsoft Defender for Endpoint (MDE), Defender Antivirus, EDR configuration, Attack Surface Reduction (ASR) rules, and Intune-based policy deployment.
  • Investigate MDE onboarding, endpoint configuration issues, policy deployment failures, AV exclusions, ASR rule behavior, and operational exceptions.
  • Review logs, configuration evidence, device policy status, connector health, and troubleshooting inputs to identify root causes.
  • Support go-live, Hypercare, warranty, and post-implementation stabilization activities. Coordinate with endpoint, Intune, identity, SOC, and security teams to resolve technical issues.
  • Escalate complex issues to L3 engineers or architects when required.
  • Maintain issue tracking, documentation, remediation plans, and support records throughout the project lifecycle.
  • Communicate technical findings and remediation recommendations to client stakeholders.

Required Skills & Experience

  • Experience supporting Microsoft Defender for Endpoint (MDE) in enterprise environments.
  • Strong knowledge of Microsoft Defender Antivirus, Endpoint Detection & Response (EDR), Attack Surface Reduction (ASR), and Intune policy deployment.
  • Hands-on experience troubleshooting endpoint onboarding, device policy status, configuration issues, AV exclusions, and deployment failures.
  • Familiarity with Microsoft Entra ID Conditional Access, Microsoft Sentinel, Splunk, and enterprise security operations.
  • Strong understanding of incident management, issue triage, escalation, and technical documentation.
  • Excellent analytical, troubleshooting, communication, and stakeholder management skills.

Preferred Qualifications

  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field.
  • Microsoft certifications such as SC-200, MD-102, SC-900, SC-100, AZ-500, or SC-300 are highly preferred.
  • Experience supporting enterprise endpoint security migrations and post-implementation Hypercare.
  • Exposure to regulated enterprise environments is an advantage.

Key Technologies

  • Microsoft Defender for Endpoint (MDE)
  • Microsoft Defender Antivirus
  • Endpoint Detection & Response (EDR)
  • Microsoft Intune
  • Attack Surface Reduction (ASR)
  • Microsoft Entra ID
  • Microsoft Sentinel
  • Splunk
  • Windows Endpoint Security