Security Analyst, L2 Support Engineer – Endpoint (Contract)
Job Description
Security Analyst L2 Support Engineer – Endpoint Security Migration Duration: 13-week contract
Key Responsibilities • Provide L2 support for Microsoft Defender for Endpoint onboarding, Defender Antivirus, EDR configuration, Attack Surface Reduction rules, and Intune endpoint security policies. • Investigate device policy status, endpoint configuration gaps, AV exclusions, ASR behavior, onboarding issues, connector status, logs, screenshots, and other troubleshooting evidence. • Support go-live and Hypercare discussions related to MDE deployment, policy rollout, endpoint security transition, and post-implementation stabilization. • Coordinate with endpoint, Intune, identity, SOC, and security teams to validate root cause, confirm remediation steps, and drive issue closure. • Escalate complex or unresolved issues to L3 engineers, SMEs, or architects where deeper platform or design input is required. • Maintain clear issue trackers, action notes, closure records, and support documentation throughout Hypercare and warranty support. Required Skills • Hands-on experience with Microsoft Defender for Endpoint, Defender Antivirus, EDR, Attack Surface Reduction, and Intune policy deployment. • Strong troubleshooting skills across endpoint security operations, policy behavior, deployment exceptions, and evidence-based technical triage. • Familiarity with Entra ID Conditional Access, SOC integration touchpoints, Microsoft Sentinel or Splunk inputs, and enterprise support governance. • Ability to communicate investigation findings clearly to IT and security stakeholders and manage L2 issues through closure or escalation. Qualifications and Preferred Experience • Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related discipline is preferred. • Microsoft certifications such as SC-200, MD-102, SC-900, SC-100, AZ-500, or SC-300 are desirable. • Experience in large enterprise endpoint security environments, Defender Antivirus transition, MDE onboarding, Intune-based Defender policy deployment, Hypercare, warranty support, or regulated environments is advantageous.