We are looking for an experienced
Microsoft Defender for Endpoint (MDE) SME / Implementation Team Lead to lead enterprise-wide endpoint security implementation and migration activities. The successful candidate will be responsible for translating approved MDE designs into production-ready configurations, leading endpoint onboarding and security policy deployment, and managing migrations from existing antivirus/EDR platforms to Microsoft Defender for Endpoint.
Key Responsibilities
- Lead end-to-end Microsoft Defender for Endpoint implementation activities covering:
- Endpoint onboarding
- Endpoint Detection and Response (EDR)
- Microsoft Defender Antivirus
- Attack Surface Reduction (ASR)
- Endpoint Security
- Device Control
- Web Protection
- Network Protection
- Automated Investigation and Remediation
- Indicators
- Advanced Hunting
- Threat & Vulnerability Management
- Lead migration from existing antivirus, EDR, or endpoint-protection platforms to Microsoft Defender for Endpoint
- Manage migration activities including:
- Endpoint discovery
- Compatibility assessment
- Coexistence/passive mode
- Pilot groups
- Deployment rings
- Phased enforcement
- Production cutover
- Validation
- Rollback planning
- Legacy agent removal
- Translate approved MDE architecture and detailed designs into:
- Configuration workbooks
- Implementation plans
- Build procedures
- Migration procedures
- Test cases
- Deployment plans
- Technical documentation
- Lead MDE onboarding, configuration walkthroughs, technical testing, policy validation, migration validation, defect resolution, and deployment-readiness activities
- Maintain:
- Configuration records
- Migration trackers
- Test evidence
- Implementation trackers
- RAID logs
- Policy inventories
- Technical runbooks
- Rollback procedures
- Knowledge-transfer materials
- Work closely with Security Operations, Identity, Endpoint, IT Security, Infrastructure, and client teams to ensure successful implementation and production rollout
- Lead technical discussions, troubleshoot implementation issues, and provide practical recommendations throughout the deployment lifecycle
Mandatory Technical Skills
- Strong hands-on experience with Microsoft Defender for Endpoint (MDE)
- Enterprise MDE implementation and deployment experience
- Strong knowledge of:
- MDE onboarding
- EDR
- Defender Antivirus
- Attack Surface Reduction (ASR)
- Endpoint Security
- Device Control
- Web Protection
- Network Protection
- Automated Investigation & Remediation
- Indicators
- Advanced Hunting
- Threat & Vulnerability Management
- Experience implementing MDE across:
- Windows 10/11
- Windows Servers
- Mobile devices
- VDI environments
- Cloud-hosted endpoints
- Good understanding of:
- Microsoft Entra ID / Azure AD
- Group Policy
- Microsoft Intune
- Microsoft Defender XDR
- Role-Based Access Control (RBAC)
- Device Groups
Critical Requirement - AV/EDR Migration
Candidates must have practical experience migrating enterprise endpoints from
third-party antivirus/EDR platforms to Microsoft Defender for Endpoint.
Experience should include:
Discovery → Compatibility Assessment → Coexistence/Passive Mode → Pilot → Deployment Rings → Phased Migration → Enforcement → Validation → Rollback → Legacy Agent Removal
Consulting & Leadership Skills
- Ability to lead MDE implementation and migration activities independently
- Strong technical communication and stakeholder-management skills
- Ability to conduct technical workshops and configuration walkthroughs
- Experience coordinating with Security Operations, Identity, Endpoint, IT Security, and client delivery teams
- Strong ownership and structured delivery-management capabilities
- Ability to convert approved designs into tested, validated, and production-ready configurations
Documentation & Knowledge Transfer
Experience creating and maintaining:
- Configuration workbooks
- Implementation plans
- Test cases and evidence
- Migration trackers
- Technical runbooks
- Rollback procedures
- Policy inventories
- Knowledge-transfer materials
- Implementation and deployment documentation
Qualifications
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related discipline is preferred
Preferred Microsoft Certifications
- SC-200 - Security Operations Analyst
- MD-102 - Endpoint Administrator
- SC-900 - Security, Compliance, and Identity Fundamentals
- SC-100 - Cybersecurity Architect
- AZ-500 - Azure Security Engineer
- SC-300 - Identity and Access Administrator
Preferred Experience
Enterprise-scale MDE implementation experience.
Large-scale endpoint security modernization or transformation projects.
Third-party AV/EDR migration to MDE.
MDE architecture/design handover experience.
Endpoint discovery and prerequisite assessment.
Pilot onboarding and phased deployment.
Unit testing, integration testing and UAT.
Production rollout and enforcement.
Legacy security-agent removal.
Experience leading technical implementation teams.