Posted on: 23/07/2025
ITCI is hiring seasoned Senior Endpoint Security Engineer will be responsible for the design, deployment, and continuous improvement of endpoint security controls using Microsoft Defender for Endpoint.
The role demands strong expertise in endpoint threat protection, ASR (Attack Surface Reduction), automated investigation and remediation, and advanced policy tuning.
This engineer will also lead junior team members, own endpoint compliance reporting, and provide strategic input into broader security governance.
Key Responsibilities :
- Enable and manage automated investigation and remediation for high-confidence alerts.
- Design, enforce, and manage ASR policies to block Office macros, executable content, and script-based threats.
- Utilize Microsoft Purview in test mode for policy validation before enforcement.
- Continuously tune Defender policies using insights from user behaviour analytics, threat intelligence, and
incident data.
- Implement security policies across endpoints, Microsoft 365 applications, and web browsers, as per
guidelines from Landal Security or the enterprise security architecture team.
- Mentor and guide junior endpoint security engineers and analysts, providing technical leadership and quality assurance.
- Generate and submit comprehensive Endpoint Protection and DLP reports to stakeholders and auditors.
- Prepare, review, and present endpoint compliance reports, ensuring alignment with internal and regulatory requirements.
- Participate in or lead project governance, including security planning, documentation, milestone tracking, and risk management.
Required Skills and Experience :
- Strong hands-on experience with Microsoft Defender for Endpoint, Microsoft Purview, and Attack Surface Reduction (ASR).
- Proficiency in automated investigation/remediation workflows and integration with SIEM/SOAR tools (e.g., Sentinel, Splunk).
- Strong analytical skills for behaviour-based policy tuning and incident correlation.
- Experience generating compliance, DLP, and security reports.
- Proven experience in mentoring junior staff, handling escalations, and owning security engineering
initiatives.
- Excellent documentation, communication, and stakeholder management skills.
Preferred Certifications like :
- SC-400 : Microsoft Information Protection Administrator.
- CISSP, CEH, or equivalent security certifications (optional but beneficial).
Did you find something suspicious?
Posted By
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1517958
Interview Questions for you
View All