We are looking for an experienced Microsoft Defender for Endpoint (MDE) SME / Implementation Team Lead to lead enterprise-wide endpoint security implementation and migration activities. The successful candidate will be responsible for translating approved MDE designs into production-ready configurations, leading endpoint onboarding and security policy deployment, and managing migrations from existing antivirus/EDR platforms to Microsoft Defender for Endpoint.
Key Responsibilities
-
Lead end-to-end Microsoft Defender for Endpoint implementation activities covering:
-
Endpoint onboarding
-
Endpoint Detection and Response (EDR)
-
Microsoft Defender Antivirus
-
Attack Surface Reduction (ASR)
-
Endpoint Security
-
Device Control
-
Web Protection
-
Network Protection
-
Automated Investigation and Remediation
-
Indicators
-
Advanced Hunting
-
Threat & Vulnerability Management
-
Lead migration from existing antivirus, EDR, or endpoint-protection platforms to Microsoft Defender for Endpoint.
-
Manage migration activities including:
-
Endpoint discovery
-
Compatibility assessment
-
Coexistence/passive mode
-
Pilot groups
-
Deployment rings
-
Phased enforcement
-
Production cutover
-
Validation
-
Rollback planning
-
Legacy agent removal
-
Translate approved MDE architecture and detailed designs into:
-
Configuration workbooks
-
Implementation plans
-
Build procedures
-
Migration procedures
-
Test cases
-
Deployment plans
-
Technical documentation
-
Lead MDE onboarding, configuration walkthroughs, technical testing, policy validation, migration validation, defect resolution, and deployment-readiness activities.
-
Maintain:
-
Configuration records
-
Migration trackers
-
Test evidence
-
Implementation trackers
-
RAID logs
-
Policy inventories
-
Technical runbooks
-
Rollback procedures
-
Knowledge-transfer materials
-
Work closely with Security Operations, Identity, Endpoint, IT Security, Infrastructure, and client teams to ensure successful implementation and production rollout.
-
Lead technical discussions, troubleshoot implementation issues, and provide practical recommendations throughout the deployment lifecycle.
Mandatory Technical Skills
-
Strong hands-on experience with Microsoft Defender for Endpoint (MDE).
-
Enterprise MDE implementation and deployment experience.
-
Strong knowledge of:
-
MDE onboarding
-
EDR
-
Defender Antivirus
-
Attack Surface Reduction (ASR)
-
Endpoint Security
-
Device Control
-
Web Protection
-
Network Protection
-
Automated Investigation & Remediation
-
Indicators
-
Advanced Hunting
-
Threat & Vulnerability Management
-
Experience implementing MDE across:
-
Windows 10/11
-
Windows Servers
-
Mobile devices
-
VDI environments
-
Cloud-hosted endpoints
-
Good understanding of:
-
Microsoft Entra ID / Azure AD
-
Group Policy
-
Microsoft Intune
-
Microsoft Defender XDR
-
Role-Based Access Control (RBAC)
-
Device Groups
Critical Requirement – AV/EDR Migration
Candidates must have practical experience migrating enterprise endpoints from third-party antivirus/EDR platforms to Microsoft Defender for Endpoint.
Experience should include:
Discovery Compatibility Assessment Coexistence/Passive Mode Pilot Deployment Rings Phased Migration Enforcement Validation Rollback Legacy Agent Removal
Consulting & Leadership Skills
-
Ability to lead MDE implementation and migration activities independently.
-
Strong technical communication and stakeholder-management skills.
-
Ability to conduct technical workshops and configuration walkthroughs.
-
Experience coordinating with Security Operations, Identity, Endpoint, IT Security, and client delivery teams.
-
Strong ownership and structured delivery-management capabilities.
-
Ability to convert approved designs into tested, validated, and production-ready configurations.
Documentation & Knowledge Transfer
Experience creating and maintaining:
-
Configuration workbooks
-
Implementation plans
-
Test cases and evidence
-
Migration trackers
-
Technical runbooks
-
Rollback procedures
-
Policy inventories
-
Knowledge-transfer materials
-
Implementation and deployment documentation
Qualifications
-
Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related discipline is preferred.
Preferred Microsoft Certifications
-
SC-200 – Security Operations Analyst
-
MD-102 – Endpoint Administrator
-
SC-900 – Security, Compliance, and Identity Fundamentals
-
SC-100 – Cybersecurity Architect
-
AZ-500 – Azure Security Engineer
-
SC-300 – Identity and Access Administrator
Preferred Experience
Enterprise-scale MDE implementation experience.
Large-scale endpoint security modernization or transformation projects.
Third-party AV/EDR migration to MDE.
MDE architecture/design handover experience.
Endpoint discovery and prerequisite assessment.
Pilot onboarding and phased deployment.
Unit testing, integration testing and UAT.
Production rollout and enforcement.
Legacy security-agent removal.
Experience leading technical implementation teams.