Microsoft Security Administrator
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+16 more
Job description
Be an Early Applicant Remote Hiring Remotely in USA Senior level Remote Hiring Remotely in USA Senior level Administers Microsoft Defender services for a DoD customer, monitoring endpoint security, EDR, NGAV, attack-surface reduction, cloud protection, SIEM integrations, cross-platform controls, WDAC, DLP, compliance reporting, and security dashboards. Escalates anomalies, maintains policies and procedures, investigates alerts, and supports Windows, Linux, and mobile-device protection. Requires cybersecurity experience, Microsoft security expertise, DoD compliance knowledge, Security+ certification, and an active Secret clearance. The summary above was generated by AI, Are you detail-oriented and passionate about cybersecurity? We’re searching for a Microsoft Security Administrator to join our dynamic team and ensure the smooth, day-to-day operation of our Microsoft Defender services for our Department of Defense (DoD) customer. If you’re committed to maintaining high security standards and eager to contribute to a critical mission, this could be the perfect opportunity for you!, 1. Monitoring Endpoint Detection and Response (EDR):
- Continuously monitoring Defender health, alerts, onboarding status, sensor health, policy enforcement, and security configuration. 2. Managing Next-Generation Antivirus (NGAV):
- Ensure NGAV solutions are running optimally and address any alerts or issues.
- Perform routine checks and updates to maintain peak performance. 3. Maintaining Attack Surface Reduction:
- Ensure rules and controls are in place to minimize the attack surface of endpoints, as provided by the SOC
- Report any deviations or issues to the engineering team for review. 4. Integrating Cloud-Delivered Protection:
- Verify that real-time updates and threat intelligence from the Microsoft cloud are being received and applied.
- Report any discrepancies or issues to the engineering team. 5. Connecting with SIEM Solutions:
- Ensure seamless integration of Microsoft Defender with Microsoft Sentinel and other SIEM tools.
- Monitor and maintain centralized logging, analytics, and reporting dashboards.
- Perform data analysis via the SIEM tool as required. 6. Ensuring Cross-Platform Protection:
- Verify comprehensive security across Windows, Linux, and mobile devices.
- Report any platform-specific issues to the engineering team. 7. Delivering Comprehensive Reporting and Analytics:
- Generate and review detailed reports on security posture, incidents, and compliance.
- Ensure dashboards and alerts are functioning correctly and report any issues. 8. Applying Prescribed Procedures:
- Follow established procedures and guidelines for maintaining Microsoft Defender solutions.
- Escalate any issues or anomalies to the engineering team. 9. Implementing Windows Defender Application Control (WDAC):
- Ensure WDAC policies are correctly applied and functioning as intended.
- Report any policy violations or issues to the engineering team. 10. Integrating Microsoft Defender, Intune, and Purview for Data Loss Prevention (DLP):
- Ensure DLP policies are correctly implemented and functioning across endpoints, mobile devices, and cloud services.
- Implement approved DLP waivers for authorized users and devices.
- Monitor DLP incidents and report any policy violations or data exfiltration attempts to the engineering team.
- Maintain unified reporting and alerts for any DLP-related issues.
Requirements
- A bachelor’s degree in computer science, Information Security, or a related field.
- 3+ Years of relevant experience
- Experience with Microsoft Defender for Endpoint and Microsoft Defender for Cloud, including Defender for Servers.
- Familiarity with endpoint security, threat hunting, and incident response.
- Familiarity with SIEM solutions, especially Microsoft Sentinel.
- Excellent attention to detail and problem-solving skills.
- Good communication and collaboration skills to interact effectively with stakeholders at all levels.
- Understanding of industry compliance standards (e.g., NIST SP 800-53) and relevant regulations (e.g., RMF, DISA STIGs, DoDI 8500.01/8510.01, CMMC/NIST 800-171) is advantageous.
- Willingness to stay updated with the latest cybersecurity trends and emerging security tools.
- Required DoD 8140 compliant certification such as CompTIA Security+
- Secret Clearance
Desired Skills:
- Experience with ServiceNow or other ticketing system
- Experience administering and working with Windows and Linux operating systems
- Microsoft Active Directory/Entra
- Microsoft PowerBI Dashboarding
- Advanced PowerShell scripting or prior software development experience
- DoD PKI
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
9 Ways to Make Money Hacking
Why Upskilling And Reskilling is Important For Developers
Understanding and Mitigating Common Web Vulnerabilities