Job Description

This is a hands-on endpoint security operations role built around Microsoft Defender for Endpoint (MDE) and Microsoft Defender Antivirus (MDAV). You keep both services healthy day to day across every supported endpoint and server platform — administering them, watching their health, and fixing what breaks.

The work splits three ways: keeping policy-group assignments accurate, getting devices on and off the platform cleanly, and getting to the bottom of sensor and agent problems. When something serious goes wrong you coordinate the response, raise and drive Microsoft support cases, and carry out approved remediation until the service is back.

You will sit alongside the server, application, endpoint, security operations and change-management teams, and your job is to make sure MDE controls stay available, correctly assigned and actually effective.


Responsibilities

Operations and incident support

  • Run day-to-day administration and technical support for MDE and MDAV across supported endpoints and servers.
  • Raise Microsoft support cases and see them through — vendor assistance, product investigation, service escalation.
  • Take the lead on technical bridge calls during P1 and P2 service, platform-health or critical sensor incidents: pull in the right teams, keep actions tracked.
  • Work inside approved change windows, providing validation, troubleshooting and rollback cover during implementation.
  • Support server, application-health and security incidents wherever endpoint protection is affected or needed for the investigation.
  • Watch the operational queues, service-health notifications, incidents, requests and assigned items, and keep progress updates and technical evidence current.
  • Work to incident, request, change, problem and escalation procedures, recording actions, outcomes, risks and anything still outstanding.
  • Write handovers that actually stand up — unresolved incidents, planned work, changes that need continued support.

Policy groups and membership

  • Build and administer MDE policy groups covering Defender Antivirus, Attack Surface Reduction and approved exclusions.
  • Create, amend, test and maintain dynamic and static device-group membership rules against approved requirements.
  • Move devices in and out of policy groups on authorised request, at lifecycle events, and when troubleshooting or policy assignment calls for it.
  • Confirm membership, policy assignment and control enforcement are still correct after any addition, removal or rule change.
  • Chase down incorrect, duplicate, stale or missing memberships and get them corrected with the relevant platform owners.
  • Keep records of what each group is for, how its membership logic works, who owns it, what was approved and what depends on it — traceability and audit readiness.
  • Provide group-management cover during incidents, including temporary approved assignment changes and putting things back afterwards.
  • Check static memberships and dynamic-rule outcomes periodically, and escalate anything that leaves security coverage weaker than it should be.

System-level support and remediation

  • Gather and read MDE Client Analyzer (MDEAnalyzer) logs and other approved diagnostics to pin down agent, connectivity, onboarding, configuration or service-health faults.
  • Run approved diagnostic and troubleshooting commands and capture the output for the incident record or the Microsoft case.
  • Reboot devices where approved and necessary for troubleshooting, remediation or restoring service.
  • Repair, reset or remediate MDE agents and related components by approved procedure, keeping disruption to the business to a minimum.
  • Carry out approved onboarding, re-onboarding and offboarding, then validate sensor connectivity, policy receipt and reporting status.
  • Disable Tamper Protection locally only under an approved, time-bound troubleshooting activity — and verify protection is back on afterwards.
  • Troubleshoot sensor, service, signature, connectivity, proxy, onboarding and policy-application problems on MDE and MDAV.
  • Prove endpoint health after remediation: sensor status, antivirus status, policy assignment, communication, portal visibility.
  • Work with the server, desktop, network, identity, application and security teams when root cause or fix sits outside the MDE boundary.
  • Escalate unresolved, recurring or high-impact issues with the full picture — evidence, reproduction detail, diagnostic logs, what has already been tried.

Service quality, governance and improvement

  • Use privileged access strictly for authorised work, within least-privilege, segregation-of-duties and secure-administration rules.
  • Make sure exclusions, temporary control changes and troubleshooting actions are approved, documented, narrow in scope, and reversed once no longer needed.
  • Maintain the operational procedures, troubleshooting guides, known-error records, knowledge articles and checklists for recurring MDE work.
  • Contribute to root-cause analysis and problem management on recurring service-health, policy, onboarding or sensor issues.
  • Spot automation and process improvements that cut manual error, speed up restoration and make endpoint health easier to see.
  • Supply operational metrics and evidence on request — incidents, device health, onboarding status, policy-group administration, vendor cases, recurring issues.
  • Support audit, compliance and service reviews with accurate records of approved changes, access, exceptions and remediation.


Requirements
  • Hands-on administration and troubleshooting of Microsoft Defender for Endpoint and Microsoft Defender Antivirus.
  • MDE device groups, dynamic and static membership rules, security settings management, antivirus policies, Attack Surface Reduction rules, exclusions, onboarding and offboarding.
  • Able to use MDE Client Analyzer and make sense of endpoint, sensor, service, connectivity and policy diagnostics.
  • Working knowledge of Windows client and Windows Server administration — services, event logs, PowerShell or command-line diagnostics, networking, proxy and certificate fundamentals.
  • ITIL-aligned incident, request, change, problem and knowledge management, including P1/P2 escalation and change-window support.
  • Endpoint security operations: least privilege, Tamper Protection, change control, audit evidence, risk-based exception handling.
  • A methodical approach to troubleshooting and evidence-gathering, and the ability to stay structured during priority incidents.
  • Clear written and verbal communication — ticket updates, handovers, knowledge articles, incident timelines.
  • Attention to detail on device groups, exclusions, policy assignments and temporary security-control changes.
  • Able to work independently, prioritise competing incidents and requests, and cover planned out-of-hours change windows when assigned.


Experience

  • Minimum 5 years in endpoint, infrastructure, network security or security operations support.
  • At least 2 years of that hands-on with MDE or Microsoft endpoint security administration.
  • Proven troubleshooting of production endpoint-security agents, coordinating priority incidents and working vendor support cases.
  • Enterprise-scale, government, healthcare or other regulated environments preferred.


Qualifications
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering or a related discipline. A relevant technical diploma backed by substantial directly applicable experience may also be considered.
  • Preferred certifications: Microsoft Certified Security Operations Analyst Associate, Microsoft 365 Certified Endpoint Administrator Associate, Microsoft security fundamentals, or equivalent endpoint-security credentials.
  • Comfortable working to an Integrated Management System: compliance with applicable laws, regulations and contractual requirements; acceptable use, code of conduct and confidentiality when handling information assets; protecting information from unauthorised access, disclosure, alteration, loss or destruction.
  • Willing to take part in information security, privacy, business continuity, quality and IT service management awareness activities, and in risk assessments, incident simulations, drills and continuity exercises.
  • Reports security, privacy, continuity, quality or operational incidents, risks and weaknesses promptly through approved channels, and follows secure on-site and remote working, access control and information-handling requirements.



Job Details

Role Level: Entry-Level Work Type: Full-Time
Country: United Arab Emirates City: Abu Dhabi
Company Website: http://www.iconnectitbs.com Job Function: Cybersecurity
Company Industry/
Sector:
Other

What We Offer


About the Company

Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.

Report

Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@talentmate.com.


ad 1
Talentmate Instagram Talentmate Facebook Talentmate YouTube Talentmate LinkedIn