Specialist - NetSecOps - MDE Operations And Support

iConnect IT Business Solutions DMCC

Abu Dhabi

On-site

AED 180,000 - 300,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

iConnect IT Business Solutions DMCC seeks a hands-on endpoint security operations engineer focused on Microsoft Defender for Endpoint and Defender Antivirus. You’ll keep protection healthy across endpoints and servers, administer the platforms, monitor health, and fix issues quickly.

You’ll lead on policy-group management, device onboarding/offboarding, and remediation during incidents, coordinating with cross-functional teams and Microsoft support to restore service.

Qualifications

  • Minimum 5 years in endpoint or security operations.
  • Hands-on with Microsoft Defender for Endpoint and Defender Antivirus.
  • Experience coordinating high-severity incidents and vendor support.

Responsibilities

  • Run day-to-day admin for MDE/MDAV across endpoints and servers.
  • Raise and manage Microsoft support cases.
  • Lead bridge calls during P1/P2 incidents.
  • Perform change-window validation and rollback.
  • Maintain accurate incident records and handovers.
  • Ensure policy groups and memberships are correct.
  • Support onboarding/offboarding and sensor connectivity.
  • Document procedures and contribute to improvements.

Skills

MDE administration
MDAV management
Windows OS
ITIL processes
Incident management
PowerShell/CLI
Security operations

Education

Bachelor's degree in Cybersecurity/CS/IT or related

Tools

MDE Client Analyzer
Microsoft Defender portal

Job description

Job Description:

This is a hands-on endpoint security operations role built around Microsoft Defender for Endpoint (MDE) and Microsoft Defender Antivirus (MDAV). You keep both services healthy day to day across every supported endpoint and server platform — administering them, watching their health, and fixing what breaks.

The work splits three ways: keeping policy-group assignments accurate, getting devices on and off the platform cleanly, and getting to the bottom of sensor and agent problems. When something serious goes wrong you coordinate the response, raise and drive Microsoft support cases, and carry out approved remediation until the service is back.

You will sit alongside the server, application, endpoint, security operations and change-management teams, and your job is to make sure MDE controls stay available, correctly assigned and actually effective.

Responsibilities
Operations and incident support
  • Run day-to-day administration and technical support for MDE and MDAV across supported endpoints and servers.
  • Raise Microsoft support cases and see them through — vendor assistance, product investigation, service escalation.
  • Take the lead on technical bridge calls during P1 and P2 service, platform-health or critical sensor incidents: pull in the right teams, keep actions tracked.
  • Work inside approved change windows, providing validation, troubleshooting and rollback cover during implementation.
  • Support server, application-health and security incidents wherever endpoint protection is affected or needed for the investigation.
  • Watch the operational queues, service-health notifications, incidents, requests and assigned items, and keep progress updates and technical evidence current.
  • Work to incident, request, change, problem and escalation procedures, recording actions, outcomes, risks and anything still outstanding.
  • Write handovers that actually stand up — unresolved incidents, planned work, changes that need continued support.
Policy groups and membership
  • Build and administer MDE policy groups covering Defender Antivirus, Attack Surface Reduction and approved exclusions.
  • Create, amend, test and maintain dynamic and static device-group membership rules against approved requirements.
  • Move devices in and out of policy groups on authorised request, at lifecycle events, and when troubleshooting or policy assignment calls for it.
  • Confirm membership, policy assignment and control enforcement are still correct after any addition, removal or rule change.
  • Chase down incorrect, duplicate, stale or missing memberships and get them corrected with the relevant platform owners.
  • Keep records of what each group is for, how its membership logic works, who owns it, what was approved and what depends on it — traceability and audit readiness.
  • Provide group-management cover during incidents, including temporary approved assignment changes and putting things back afterwards.
  • Check static memberships and dynamic-rule outcomes periodically, and escape anything that leaves security coverage weaker than it should be.
System-level support and remediation
  • Gather and read MDE Client Analyzer (MDEAnalyzer) logs and other approved diagnostics to pin down agent, connectivity, onboarding, configuration or service-health faults.
  • Run approved diagnostic and troubleshooting commands and capture the output for the incident record or the Microsoft case.
  • Reboot devices where approved and necessary for troubleshooting, remediation or restoring service.
  • Repair, reset or remediate MDE agents and related components by approved procedure, keeping disruption to the business to a minimum.
  • Carry out approved onboarding, re-onboarding and offboarding, then validate sensor connectivity, policy receipt and reporting status.
  • Disable Tamper Protection locally only under an approved, time-bound troubleshooting activity — and verify protection is back on afterwards.
  • Troubleshoot sensor, service, signature, connectivity, proxy, onboarding and policy-application problems on MDE and MDAV.
  • Prove endpoint health after remediation: sensor status, antivirus status, policy assignment, communication, portal visibility.
  • Work with the server, desktop, network, identity, application and security teams when root cause or fix sits outside the MDE boundary.
  • Escalate unresolved, recurring or high-impact issues with the full picture — evidence, reproduction detail, diagnostic logs, what has already been tried.
Service quality, governance and improvement
  • Use privileged access strictly for authorised work, within least-privilege, segregation-of-duties and secure-administration rules.
  • Make sure exclusions, temporary control changes and troubleshooting actions are approved, documented, narrow in scope, and reversed once no longer needed.
  • Maintain the operational procedures, troubleshooting guides, known-error records, knowledge articles and checklists for recurring MDE work.
  • Contribute to root-cause analysis and problem management on recurring service-health, policy, onboarding or sensor issues.
  • Spot automation and process improvements that cut manual error, speed up restoration and make endpoint health easier to see.
  • Supply operational metrics and evidence on request — incidents, device health, onboarding status, policy-group administration, vendor cases, recurring issues.
  • Support audit, compliance and service reviews with accurate records of approved changes, access, exceptions and remediation.
Requirements
  • Hands-on administration and troubleshooting of Microsoft Defender for Endpoint and Microsoft Defender Antivirus.
  • MDE device groups, dynamic and static membership rules, security settings management, antivirus policies, Attack Surface Reduction rules, exclusions, onboarding and offboarding.
  • Able to use MDE Client Analyzer and make sense of endpoint, sensor, service, connectivity and policy diagnostics.
  • Working knowledge of Windows client and Windows Server administration — services, event logs, PowerShell or command-line diagnostics, networking, proxy and certificate fundamentals.
  • ITIL-aligned incident, request, change, problem and knowledge management, including P1/P2 escalation and change-window support.
  • Endpoint security operations: least privilege, Tamper Protection, change control, audit evidence, risk-based exception handling.
  • A methodical approach to troubleshooting and evidence-gathering, and the ability to stay structured during priority incidents.
  • Clear written and verbal communication — ticket updates, handovers, knowledge articles, incident timelines.
  • Attention to detail on device groups, exclusions, policy assignments and temporary security-control changes.
  • Able to work independently, prioritise competing incidents and requests, and cover planned out-of-hours change windows when assigned.
Experience
  • Minimum 5 years in endpoint, infrastructure, network security or security operations support.
  • At least 2 years of that hands-on with MDE or Microsoft endpoint security administration.
  • Proven troubleshooting of production endpoint-security agents, coordinating priority incidents and working vendor support cases.
  • Enterprise-scale, government, healthcare or other regulated environments preferred.
Qualifications
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering or a related discipline. A relevant technical diploma backed by substantial directly applicable experience may also be considered.
  • Preferred certifications: Microsoft Certified Security Operations Analyst Associate, Microsoft 365 Certified Endpoint Administrator Associate, Microsoft security fundamentals, or equivalent endpoint-security credentials.
  • Comfortable working to an Integrated Management System: compliance with applicable laws, regulations and contractual requirements; acceptable use, code of conduct and confidentiality when handling information assets; protecting information from unauthorised access, disclosure, alteration, loss or destruction.
  • Willing to take part in information security, privacy, business continuity, quality and IT service management awareness activities, and in risk assessments, incident simulations, drills and continuity exercises.
  • Reports security, privacy, continuity, quality or operational incidents, risks and weaknesses promptly through approved channels, and follows secure on-site and remote working, access control and information-handling requirements.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Endpoint Security Engineer – MDE & MDAV Operations
Endpoint Security Engineer – MDE & MDAV Operations

iConnect IT Business Solutions DMCC • Abu Dhabi

On-site
AED 180,000 - 300,000
Specialist – Endpoint Security
Specialist – Endpoint Security

CPX • Abu Dhabi

On-site
AED 240,000 - 360,000
Senior Cybersecurity Specialist
Senior Cybersecurity Specialist

Tanqeeb • Dubai

On-site
AED 300,000 - 420,000
Security Specialist
Security Specialist

ICONNECT IT BUSINESS SOLUTIONS DMCC • Abu Dhabi

On-site
AED 180,000 - 280,000
Senior Specialist – InfoSec Ops Management
Senior Specialist – InfoSec Ops Management

Tanqeeb • Abu Dhabi

On-site
AED 250,000 - 420,000
Cloud Security Specialist
Cloud Security Specialist

CPX • Abu Dhabi

On-site
AED 120,000 - 170,000
Senior Detection and Response Engineer
Senior Detection and Response Engineer

Jobtailor • Dubai

On-site
AED 300,000 - 450,000
System Administrator
System Administrator

Confidential Company • Dubai

On-site
AED 180,000 - 240,000
Senior Security Engineer - EDR & NDR
Senior Security Engineer - EDR & NDR

Help AG • Dubai

Hybrid
AED 260,000 - 460,000
Health insurance
Flexible/Hybrid working environment
Information Security Engineer
Information Security Engineer

GBM • Dubai

On-site
AED 200,000 - 320,000