This position is full time remote and requires the candidate hold an active secret clearance.
Are you detail-oriented and passionate about cybersecurity? We’re searching for a Microsoft Defender Operator to join our dynamic team and ensure the smooth, day-to-day operation of our Microsoft Defender services for our Department of Defense (DOD) customer. If you’re committed to maintaining high security standards and eager to contribute to a critical mission, this could be the perfect opportunity for you!
Responsibilities:
1. Monitoring Endpoint Detection and Response (EDR):
• Continuously monitor EDR solutions to detect and report threats to the Security Operations Center (SOC) in real-time.
2. Managing Next-Generation Antivirus (NGAV):
• Ensure NGAV solutions are running optimally and address any alerts or issues.
• Perform routine checks and updates to maintain peak performance.
3. Maintaining Attack Surface Reduction:
• Ensure rules and controls are in place to minimize the attack surface of endpoints, as provided by the SOC
• Report any deviations or issues to the engineering team for review.
4. Integrating Cloud-Delivered Protection:
• Verify that real-time updates and threat intelligence from the Microsoft cloud are being received and applied.
• Report any discrepancies or issues to the engineering team.
5. Connecting with SIEM Solutions:
• Ensure seamless integration of Microsoft Defender with Microsoft Sentinel and other SIEM tools.
• Monitor and maintain centralized logging, analytics, and reporting dashboards.
• Perform data analysis via the SIEM tool as required.
6. Ensuring Cross-Platform Protection:
• Verify comprehensive security across Windows, Linux, and mobile devices.
• Report any platform-specific issues to the engineering team.
7. Delivering Comprehensive Reporting and Analytics:
• Generate and review detailed reports on security posture, incidents, and compliance.
• Ensure dashboards and alerts are functioning correctly and report any issues.
8. Applying Prescribed Procedures:
• Follow established procedures and guidelines for maintaining Microsoft Defender solutions.
• Escalate any issues or anomalies to the engineering team.
9. Implementing Windows Defender Application Control (WDAC):
• Ensure WDAC policies are correctly applied and functioning as intended.
• Report any policy violations or issues to the engineering team.
10. Integrating Microsoft Defender, Intune, and Purview for Data Loss Prevention (DLP):
• Ensure DLP policies are correctly implemented and functioning across endpoints, mobile devices, and cloud services.
• Implement approved DLP waivers for authorized users and devices.
• Monitor DLP incidents and report any policy violations or data exfiltration attempts to the engineering team.
• Maintain unified reporting and alerts for any DLP-related issues.
• A Bachelor’s degree in Computer Science, Information Security, or a related field.
• 3+ Years of relevant experience
• Experience with Microsoft Defender for Endpoint, Cloud, and Servers.
• Familiarity with endpoint security, threat hunting, and incident response.
• Familiarity with SIEM solutions, especially Microsoft Sentinel.
• Excellent attention to detail and problem-solving skills.
• Good communication and collaboration skills to interact effectively with stakeholders at all levels.
• Understanding of industry compliance standards (e.g., NIST) and relevant regulations (e.g., GDPR, HIPAA) is advantageous.
• Willingness to stay updated with the latest cybersecurity trends and emerging security tools.
• Required DoD 8140 compliant certification such as CompTIA Security+
• Secret Clearance
Desired Skills:
• Experience with ServiceNow or other ticketing system
• Experience administering and working with Windows and Linux operating systems
• Microsoft Active Directory/Entra
• Microsoft PowerBI Dashboarding
• Advanced PowerShell scripting or prior software development experience
• DoD PKI
Accelera Solutions is an Equal Opportunity Employer/Veterans/Disabled.
Skills Required
- Bachelor's degree in Computer Science, Information Security, or related field
- 3+ years of relevant experience
- Experience with Microsoft Defender for Endpoint, Cloud, and Servers
- Familiarity with endpoint security, threat hunting, and incident response
- Familiarity with SIEM solutions, especially Microsoft Sentinel
- Ability to verify integration between Microsoft Defender and SIEM (Sentinel) and maintain centralized logging/analytics
- Implement and validate Windows Defender Application Control (WDAC) policies
- Integrate Microsoft Defender, Intune, and Purview for DLP and monitor DLP incidents
- Excellent attention to detail and problem-solving skills
- Good communication and collaboration skills
- Understanding of industry compliance standards (e.g., NIST) and relevant regulations (advantageous)
- Willingness to stay updated with cybersecurity trends and tools
- DoD 8140 compliant certification (e.g., CompTIA Security+)
- Active Secret clearance
- Experience with ServiceNow or other ticketing systems
- Experience administering Windows and Linux operating systems
- Microsoft Active Directory/Entra experience
- Microsoft Power BI dashboarding experience
- Advanced PowerShell scripting or prior software development experience
- DoD PKI
What We Do
Accelera Solutions is an AI-first federal engineering organization and award-winning leader in digital transformation and IT modernization. The company delivers secure cloud, cybersecurity, and DevSecOps solutions specifically for DoD, civilian, and intelligence customers. Specializing in virtualization and systems engineering, Accelera has been helping government agencies modernize their infrastructure and accelerate the federal frontier since 2002.


.png)





