Specialist - NetSecOps - MDE Operations And Support
Talentmate
United Arab Emirates
23rd September 2026
2609-37008-35
Job Description
This is a hands-on endpoint security operations role built around Microsoft Defender for Endpoint (MDE) and Microsoft Defender Antivirus (MDAV). You keep both services healthy day to day across every supported endpoint and server platform — administering them, watching their health, and fixing what breaks.
The work splits three ways: keeping policy-group assignments accurate, getting devices on and off the platform cleanly, and getting to the bottom of sensor and agent problems. When something serious goes wrong you coordinate the response, raise and drive Microsoft support cases, and carry out approved remediation until the service is back.
You will sit alongside the server, application, endpoint, security operations and change-management teams, and your job is to make sure MDE controls stay available, correctly assigned and actually effective.
Responsibilities
Operations and incident support
Run day-to-day administration and technical support for MDE and MDAV across supported endpoints and servers.
Raise Microsoft support cases and see them through — vendor assistance, product investigation, service escalation.
Take the lead on technical bridge calls during P1 and P2 service, platform-health or critical sensor incidents: pull in the right teams, keep actions tracked.
Work inside approved change windows, providing validation, troubleshooting and rollback cover during implementation.
Support server, application-health and security incidents wherever endpoint protection is affected or needed for the investigation.
Watch the operational queues, service-health notifications, incidents, requests and assigned items, and keep progress updates and technical evidence current.
Work to incident, request, change, problem and escalation procedures, recording actions, outcomes, risks and anything still outstanding.
Write handovers that actually stand up — unresolved incidents, planned work, changes that need continued support.
Policy groups and membership
Build and administer MDE policy groups covering Defender Antivirus, Attack Surface Reduction and approved exclusions.
Create, amend, test and maintain dynamic and static device-group membership rules against approved requirements.
Move devices in and out of policy groups on authorised request, at lifecycle events, and when troubleshooting or policy assignment calls for it.
Confirm membership, policy assignment and control enforcement are still correct after any addition, removal or rule change.
Chase down incorrect, duplicate, stale or missing memberships and get them corrected with the relevant platform owners.
Keep records of what each group is for, how its membership logic works, who owns it, what was approved and what depends on it — traceability and audit readiness.
Provide group-management cover during incidents, including temporary approved assignment changes and putting things back afterwards.
Check static memberships and dynamic-rule outcomes periodically, and escalate anything that leaves security coverage weaker than it should be.
System-level support and remediation
Gather and read MDE Client Analyzer (MDEAnalyzer) logs and other approved diagnostics to pin down agent, connectivity, onboarding, configuration or service-health faults.
Run approved diagnostic and troubleshooting commands and capture the output for the incident record or the Microsoft case.
Reboot devices where approved and necessary for troubleshooting, remediation or restoring service.
Repair, reset or remediate MDE agents and related components by approved procedure, keeping disruption to the business to a minimum.
Carry out approved onboarding, re-onboarding and offboarding, then validate sensor connectivity, policy receipt and reporting status.
Disable Tamper Protection locally only under an approved, time-bound troubleshooting activity — and verify protection is back on afterwards.
Troubleshoot sensor, service, signature, connectivity, proxy, onboarding and policy-application problems on MDE and MDAV.
Prove endpoint health after remediation: sensor status, antivirus status, policy assignment, communication, portal visibility.
Work with the server, desktop, network, identity, application and security teams when root cause or fix sits outside the MDE boundary.
Escalate unresolved, recurring or high-impact issues with the full picture — evidence, reproduction detail, diagnostic logs, what has already been tried.
Service quality, governance and improvement
Use privileged access strictly for authorised work, within least-privilege, segregation-of-duties and secure-administration rules.
Make sure exclusions, temporary control changes and troubleshooting actions are approved, documented, narrow in scope, and reversed once no longer needed.
Maintain the operational procedures, troubleshooting guides, known-error records, knowledge articles and checklists for recurring MDE work.
Contribute to root-cause analysis and problem management on recurring service-health, policy, onboarding or sensor issues.
Spot automation and process improvements that cut manual error, speed up restoration and make endpoint health easier to see.
Supply operational metrics and evidence on request — incidents, device health, onboarding status, policy-group administration, vendor cases, recurring issues.
Support audit, compliance and service reviews with accurate records of approved changes, access, exceptions and remediation.
Requirements
Hands-on administration and troubleshooting of Microsoft Defender for Endpoint and Microsoft Defender Antivirus.
Able to use MDE Client Analyzer and make sense of endpoint, sensor, service, connectivity and policy diagnostics.
Working knowledge of Windows client and Windows Server administration — services, event logs, PowerShell or command-line diagnostics, networking, proxy and certificate fundamentals.
ITIL-aligned incident, request, change, problem and knowledge management, including P1/P2 escalation and change-window support.
Endpoint security operations: least privilege, Tamper Protection, change control, audit evidence, risk-based exception handling.
A methodical approach to troubleshooting and evidence-gathering, and the ability to stay structured during priority incidents.
Clear written and verbal communication — ticket updates, handovers, knowledge articles, incident timelines.
Attention to detail on device groups, exclusions, policy assignments and temporary security-control changes.
Able to work independently, prioritise competing incidents and requests, and cover planned out-of-hours change windows when assigned.
Experience
Minimum 5 years in endpoint, infrastructure, network security or security operations support.
At least 2 years of that hands-on with MDE or Microsoft endpoint security administration.
Proven troubleshooting of production endpoint-security agents, coordinating priority incidents and working vendor support cases.
Enterprise-scale, government, healthcare or other regulated environments preferred.
Qualifications
Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering or a related discipline. A relevant technical diploma backed by substantial directly applicable experience may also be considered.
Preferred certifications: Microsoft Certified Security Operations Analyst Associate, Microsoft 365 Certified Endpoint Administrator Associate, Microsoft security fundamentals, or equivalent endpoint-security credentials.
Comfortable working to an Integrated Management System: compliance with applicable laws, regulations and contractual requirements; acceptable use, code of conduct and confidentiality when handling information assets; protecting information from unauthorised access, disclosure, alteration, loss or destruction.
Willing to take part in information security, privacy, business continuity, quality and IT service management awareness activities, and in risk assessments, incident simulations, drills and continuity exercises.
Reports security, privacy, continuity, quality or operational incidents, risks and weaknesses promptly through approved channels, and follows secure on-site and remote working, access control and information-handling requirements.
Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.
Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together.
Applicants
are
advised to research the bonafides of the prospective employer independently. We do NOT
endorse any
requests for money payments and strictly advice against sharing personal or bank related
information. We
also recommend you visit Security Advice for more information. If you suspect any fraud
or
malpractice,
email us at abuse@talentmate.com.
You have successfully saved for this job. Please check
saved
jobs
list
Applied
You have successfully applied for this job. Please check
applied
jobs list
Do you want to share the
link?
Please click any of the below options to share the job
details.
Report this job
Success
Successfully updated
Success
Successfully updated
Thank you
Reported Successfully.
Copied
This job link has been copied to clipboard!
Apply Job
Your application for Specialist - NetSecOps - MDE Operations And Support
has been successfully submitted!
To increase your chances of getting shortlisted, we recommend completing your profile.
Employers prioritize candidates with full profiles, and a completed profile could set you apart in the
selection process.
Why complete your profile?
Higher Visibility: Complete profiles are more likely to be viewed by employers.
Better Match: Showcase your skills and experience to improve your fit.
Stand Out: Highlight your full potential to make a stronger impression.
Complete your profile now to give your application the best chance!