E logo

Microsoft Defender Security Lead

Essnova Solutions, Inc.Bethesda, MD

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.1

Reclaim your time by letting our AI handle the grunt work of job searching.

We continuously scan millions of openings to find your top matches.

pay-wall

Overview

Schedule
Full-time
Career level
Director
Remote
Hybrid remote

Job Description

Location: Bethesda/Rockville, MD / Hybrid-Telework Eligible

Employment: Full-Time

Status:Contingent Upon Proposal Award

About Essnova

Essnova Solutions, Inc. is seeking an experienced Microsoft Defender Security Lead to lead enterprise endpoint-security delivery supporting a large-scale Microsoft endpoint management and cybersecurity modernization program for the National Institutes of Health (NIH).

This position is contingent upon Essnova receiving contract award.

The Microsoft Defender Security Lead will lead implementation, sustainment, optimization, migration, policy governance, coverage improvement, and remediation activities for Microsoft Defender for Endpoint (MDE) and Microsoft Defender Antivirus (MDAV) across an enterprise environment of approximately 55,000 endpoints and 15,000+ servers.

What You’ll Do

  • Lead enterprise Microsoft Defender for Endpoint (MDE) and Microsoft Defender Antivirus (MDAV) implementation, sustainment, optimization, governance, and operational reporting.
  • Lead remaining Cylance-to-Microsoft Defender Antivirus migration activities and track migrated, excepted, blocked, and unresolved endpoint populations.
  • Implement, maintain, troubleshoot, and govern approved Attack Surface Reduction (ASR), Tamper Protection, device control, endpoint-security, and Microsoft Defender policies.
  • Monitor and report MDE sensor coverage, MDAV active protection, MDAV update currency, policy posture, unhealthy sensors, and approved exceptions.
  • Drive coverage-gap remediation, endpoint and server onboarding, policy issue resolution, and exception remediation.
  • Support Threat and Vulnerability Management (TVM), vulnerability remediation, telemetry validation, detection tuning, and enterprise security reporting.
  • Support Microsoft Defender governance across in-scope endpoint and server populations and coordinate Microsoft Defender for Cloud alignment.
  • Coordinate with the NIH Security Operations Center (SOC) and Government security stakeholders while maintaining appropriate boundaries between endpoint-security engineering, SOC operations, and server administration.
  • Develop and maintain security governance artifacts, operational documentation, metrics, dashboards, reports, remediation evidence, and knowledge-transfer materials.
  • Support security reviews, authorization/ATO activities, assessments, audits, incident readiness, compliance evidence, and security-control documentation.
  • Support applicable federal cybersecurity and compliance requirements, including NIST, FISMA, HHS security/privacy requirements, and Section 508-compliant deliverables.
  • Support transition of NIH endpoint-security capabilities from modernization and migration activities into steady-state enterprise operations.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Assurance, Computer Science, Engineering, or a related technical field.
  • 8+ years of experience in endpoint security and/or cybersecurity engineering.
  • 5+ years of hands-on experience implementing or operating Microsoft Defender technologies.
  • Demonstrated hands-on experience with:
    • Microsoft Defender for Endpoint (MDE)
    • Microsoft Defender Antivirus (MDAV)
    • Endpoint Detection and Response (EDR)
    • Endpoint and server onboarding
    • Endpoint security policies and configuration
    • Attack Surface Reduction (ASR)
    • Security coverage monitoring and remediation
    • Threat and vulnerability management
    • Telemetry validation and detection tuning
    • Exception governance and remediation tracking
    • Enterprise security reporting
  • Experience supporting large-scale enterprise endpoint and server populations in complex, regulated, and/or federal environments.
  • Demonstrated experience executing or supporting antivirus and/or EDR migrations, including management of exceptions, blockers, continuity controls, and remediation.
  • Experience producing technical and security evidence supporting authorization, assessment, audit, vulnerability management, incident readiness, and compliance activities.
  • Must be a U.S. Citizen or otherwise eligible to meet applicable federal contract and Government system-access requirements, as required by the contract.
  • Must be willing and able to undergo and successfully satisfy the applicable federal Public Trust suitability/background investigation and Government system-access requirements.
  • Selected personnel must satisfy applicable post-award security, privacy, training, rules-of-behavior, nondisclosure agreement (NDA), personnel security, and access requirements.

Preferred Qualifications

  • Experience supporting NIH, HHS, or another civilian federal health/science agency.
  • Experience with Cylance-to-Microsoft Defender Antivirus migration or comparable third-party antivirus/EDR migration.
  • Experience with Microsoft Defender for Cloud and MDE server governance.
  • Experience with Microsoft Intune, Microsoft Entra, Azure, Azure Arc, or related Microsoft enterprise security and endpoint-management technologies.
  • Knowledge of NIST SP 800-53, NIST SP 800-171, FISMA, HHS security requirements, federal authorization/ATO processes, and audit requirements.
  • Microsoft Certified: Cybersecurity Architect Expert, Security Operations Analyst Associate, or current equivalent Microsoft certification.
  • CISSP, GIAC, Security+, or comparable cybersecurity certification.
  • Demonstrated experience achieving measurable improvements in MDE sensor coverage, MDAV protection status, update currency, vulnerability remediation, security compliance, or exception closure.

Additional Requirements

Selected personnel must be willing and able to satisfy applicable post-award security, privacy, background investigation, training, rules-of-behavior, NDA, and Government system/access requirements. A signed Letter of Commitment will be required for proposed Key Personnel.

Contingency Notice

This position is contingent upon Essnova Solutions, Inc. receiving contract award and Government approval of proposed Key Personnel. Anticipated contract performance is expected to begin following award.

Equal Employment Opportunity

Essnova Solutions, Inc. is an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, religion, sex, national origin, disability, protected veteran status, or any other status protected by applicable law.

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.

pay-wall

FAQs About Microsoft Defender Security Lead Jobs at Essnova Solutions, Inc.

What is the work location for this position at Essnova Solutions, Inc.?
This job at Essnova Solutions, Inc. is located in Bethesda, MD, according to the details provided by the employer. Some roles may also include multiple work locations depending on the requirement.
What pay range can candidates expect for this role at Essnova Solutions, Inc.?
Employer has not shared pay details for this role.
What employment applies to this position at Essnova Solutions, Inc.?
Essnova Solutions, Inc. lists this role as a Full-time position.
What experience level is required for this role at Essnova Solutions, Inc.?
Essnova Solutions, Inc. is looking for a candidate with "Director" experience level.
What is the process to apply for this position at Essnova Solutions, Inc.?
You can apply for this role at Essnova Solutions, Inc. either through Sonara's automated application system, which helps you submit applications 10X faster with minimal effort, or by applying manually using the direct link on the job page.