> Markdown version of [/jobs/ext/2721440-level-3-end-user-security-engineer](https://www.wearedevelopers.com/jobs/ext/2721440-level-3-end-user-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Level 3 End User Security Engineer - **Company:** InnoCore Solutions, Inc. - **Location:** Dallas, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Command-Line Interface, Cyber Security, Network Connections, Phishing, Kusto Query Language, SAP Security, User Environment Management, Software Vulnerability Management, Malware, Cyber Threat Analysis, Azure Security Center, Information Technology, Cybercrime, Windows Security - **Published:** September 4, 2026 - **Apply:** https://www.dice.com/job-detail/4687d005-a692-402a-8078-e861f77f0d4e ## About the Role * 5+ years of experience in endpoint security, Windows security, cybersecurity, or related IT infrastructure roles. * 3+ years of hands-on experience with Microsoft Defender for Endpoint (MDE) in a medium-to-large enterprise environment. * Ability to develop KQL queries for threat hunting, investigation, detection, and security analytics. * Experience working in an L3 escalation/support environment and independently resolving complex technical issues. * Strong understanding of security incident response processes and evidence preservation. * Excellent troubleshooting, analytical, communication, documentation, and problem-solving skills. Education: * Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering or a related field. ## Description We are looking for a highly skilled Level 3 End User Security Engineer responsible for administering, troubleshooting, monitoring, and enhancing endpoint security using Microsoft Defender for Endpoint (MDE). This role will serve as a senior escalation point for complex endpoint security incidents and will work closely with Security Operations, Infrastructure, Identity, and End User Computing teams., * Serve as the Level 3 escalation point for complex endpoint security incidents, problems, and vulnerabilities. * Administer, monitor, and optimize Microsoft Defender for Endpoint (MDE) across enterprise Windows endpoints. * Investigate and respond to malware, ransomware, phishing, suspicious processes, credential theft, and other endpoint security threats. * Perform advanced threat hunting and incident investigation using Microsoft Defender Advanced Hunting and KQL. * Analyze endpoint timelines, process trees, command-line activity, file/registry changes, network connections, and other security telemetry. * Perform endpoint containment and remediation activities, including device isolation, antivirus scans, Live Response, and remote remediation. * Develop KQL queries, custom detections, dashboards, and threat-hunting queries to identify suspicious activity across the enterprise. * Participate in security incident response, vulnerability remediation, security projects, and continuous improvement initiatives. * Maintain appropriate documentation, audit trails, metrics, and reporting for endpoint security operations. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)