L2 Microsoft Defender for Endpoint (MDE) Support Engineer
Must-have:Security
Job Description
- We are seeking an experienced L2 Microsoft Defender for Endpoint (MDE) Support Engineer to support enterprise endpoint security migration initiatives.
- The ideal candidate will have strong expertise in Microsoft Defender for Endpoint, Defender Antivirus, Intune policy deployment, EDR configuration, and endpoint troubleshooting, with experience supporting go-live, Hypercare, and post-implementation activities.
Key Responsibilities
- Provide L2 support for endpoint security migration activities focused on Microsoft Defender for Endpoint (MDE), Defender Antivirus, EDR configuration, Attack Surface Reduction (ASR) rules, and Intune-based policy deployment.
- Investigate MDE onboarding, endpoint configuration issues, policy deployment failures, AV exclusions, ASR rule behavior, and operational exceptions.
- Review logs, configuration evidence, device policy status, connector health, and troubleshooting inputs to identify root causes.
- Support go-live, Hypercare, warranty, and post-implementation stabilization activities. Coordinate with endpoint, Intune, identity, SOC, and security teams to resolve technical issues.
- Escalate complex issues to L3 engineers or architects when required.
- Maintain issue tracking, documentation, remediation plans, and support records throughout the project lifecycle.
- Communicate technical findings and remediation recommendations to client stakeholders.
Required Skills & Experience
- Experience supporting Microsoft Defender for Endpoint (MDE) in enterprise environments.
- Strong knowledge of Microsoft Defender Antivirus, Endpoint Detection & Response (EDR), Attack Surface Reduction (ASR), and Intune policy deployment.
- Hands-on experience troubleshooting endpoint onboarding, device policy status, configuration issues, AV exclusions, and deployment failures.
- Familiarity with Microsoft Entra ID Conditional Access, Microsoft Sentinel, Splunk, and enterprise security operations.
- Strong understanding of incident management, issue triage, escalation, and technical documentation.
- Excellent analytical, troubleshooting, communication, and stakeholder management skills.
Preferred Qualifications
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field.
- Microsoft certifications such as SC-200, MD-102, SC-900, SC-100, AZ-500, or SC-300 are highly preferred.
- Experience supporting enterprise endpoint security migrations and post-implementation Hypercare.
- Exposure to regulated enterprise environments is an advantage.
Key Technologies
- Microsoft Defender for Endpoint (MDE)
- Microsoft Defender Antivirus
- Endpoint Detection & Response (EDR)
- Microsoft Intune
- Attack Surface Reduction (ASR)
- Microsoft Entra ID
- Microsoft Sentinel
- Splunk
- Windows Endpoint Security