Senior Microsoft Security Administrator
Summary
Remote Senior Microsoft Security Administrator maintaining Microsoft Defender, Sentinel, Intune, and Purview services for a Department of Defense customer. Day-to-day work involves monitoring EDR/NGAV, enforcing DLP and WDAC policies, integrating SIEM tooling, and reporting across Windows, Linux, and mobile endpoints.
This position is full time remote and requires the candidate hold an active secret clearance.
Are you detail-oriented and passionate about cybersecurity? We’re searching for a Microsoft Security Administrator to join our dynamic team and ensure the smooth, day-to-day operation of our Microsoft Defender services for our Department of Defense (DoD) customer. If you’re committed to maintaining high security standards and eager to contribute to a critical mission, this could be the perfect opportunity for you!
Responsibilities:
1. Monitoring Endpoint Detection and Response (EDR):
• Continuously monitoring Defender health, alerts, onboarding status, sensor health, policy enforcement, and security configuration.
2. Managing Next-Generation Antivirus (NGAV):
• Ensure NGAV solutions are running optimally and address any alerts or issues.
• Perform routine checks and updates to maintain peak performance.
3. Maintaining Attack Surface Reduction:
• Ensure rules and controls are in place to minimize the attack surface of endpoints, as provided by the SOC
• Report any deviations or issues to the engineering team for review.
4. Integrating Cloud-Delivered Protection:
• Verify that real-time updates and threat intelligence from the Microsoft cloud are being received and applied.
• Report any discrepancies or issues to the engineering team.
5. Connecting with SIEM Solutions:
• Ensure seamless integration of Microsoft Defender with Microsoft Sentinel and other SIEM tools.
• Monitor and maintain centralized logging, analytics, and reporting dashboards.
• Perform data analysis via the SIEM tool as required.
6. Ensuring Cross-Platform Protection:
• Verify comprehensive security across Windows, Linux, and mobile devices.
• Report any platform-specific issues to the engineering team.
7. Delivering Comprehensive Reporting and Analytics:
• Generate and review detailed reports on security posture, incidents, and compliance.
• Ensure dashboards and alerts are functioning correctly and report any issues.
8. Applying Prescribed Procedures:
• Follow established procedures and guidelines for maintaining Microsoft Defender solutions.
• Escalate any issues or anomalies to the engineering team.
9. Implementing Windows Defender Application Control (WDAC):
• Ensure WDAC policies are correctly applied and functioning as intended.
• Report any policy violations or issues to the engineering team.
10. Integrating Microsoft Defender, Intune, and Purview for Data Loss Prevention (DLP):
• Ensure DLP policies are correctly implemented and functioning across endpoints, mobile devices, and cloud services.
• Implement approved DLP waivers for authorized users and devices.
• Monitor DLP incidents and report any policy violations or data exfiltration attempts to the engineering team.
• Maintain unified reporting and alerts for any DLP-related issues.