An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Essnova Solutions, Inc. seeks a seasoned Microsoft Defender Security Lead to guide enterprise endpoint-security delivery for NIH modernization.
You will lead MDE/MDAV deployment, governance, and reporting across ~55,000 endpoints and 15,000+ servers in a large federal environment. This hybrid, full-time role requires hands-on Defender expertise, Cylance-to-Defender migration experience, and collaboration with NIH SOC and security stakeholders.
Location: Bethesda/Rockville, MD / Hybrid-Telework Eligible Employment: Full-Time Status: Contingent Upon Proposal Award
About Essnova Essnova Solutions, Inc. is seeking an experienced Microsoft Defender Security Lead to lead enterprise endpoint-security delivery supporting a large-scale Microsoft endpoint management and cybersecurity modernization program for the National Institutes of Health (NIH) . This position is contingent upon Essnova receiving contract award .
Microsoft Defender Security Lead will lead implementation, sustainment, optimization, migration, policy governance, coverage improvement, and remediation activities for Microsoft Defender for Endpoint (MDE) and Microsoft Defender Antivirus (MDAV) across an enterprise environment of approximately 55,000 endpoints and 15,000+ servers .
Lead enterprise Microsoft Defender for Endpoint (MDE) and Microsoft Defender Antivirus (MDAV) implementation, sustainment, optimization, governance, and operational reporting. Lead remaining Cylance-to-Microsoft Defender Antivirus migration activities and track migrated, excepted, blocked, and unresolved endpoint populations. Implement, maintain, troubleshoot, and govern approved Attack Surface Reduction (ASR), Tamper Protection, device control, endpoint-security, and Microsoft Defender policies . Monitor and report MDE sensor coverage, MDAV active protection, MDAV update currency, policy posture, unhealthy sensors, and approved exceptions . Drive coverage-gap remediation , endpoint and server onboarding, policy issue resolution, and exception remediation. Support Threat and Vulnerability Management (TVM) , vulnerability remediation, telemetry validation, detection tuning, and enterprise security reporting. Support Microsoft Defender governance across in-scope endpoint and server populations and coordinate Microsoft Defender for Cloud alignment. Coordinate with the NIH Security Operations Center (SOC) and Government security stakeholders while maintaining appropriate boundaries between endpoint-security engineering, SOC operations, and server administration. Develop and maintain security governance artifacts, operational documentation, metrics, dashboards, reports, remediation evidence, and knowledge-transfer materials. Support security reviews, authorization/ATO activities, assessments, audits, incident readiness, compliance evidence, and security-control documentation . Support applicable federal cybersecurity and compliance requirements, including NIST, FISMA, HHS security/privacy requirements, and Section 508-compliant deliverables . Support transition of NIH endpoint-security capabilities from modernization and migration activities into steady-state enterprise operations .
Selected personnel must be willin