Jobs and Careers
CA

Senior Microsoft Defender Engineer

CACI International Inc
United Statesfull_timeVerifiedPosted 9 Apr 2026
💰 $218,100/yr($103,800/yr$218,100/yr)

About the role

Job Title: Senior Microsoft Defender Engineer

Job Category: Information Technology

Time Type: Full time

Minimum Clearance Required to Start: Secret

Employee Type: Regular

Percentage of Travel Required: Up to 10%

Type of Travel: Continental US

* * *

The Opportunity:

CACI is seeking a highly skilled and experienced Senior Microsoft Defender Engineer to join our Endpoint Device Management team. The ideal candidate will have deep expertise in Microsoft Defender for Endpoint, Cloud, Identity, and Servers, with a strong understanding of the System Engineering Lifecycle. This role will be responsible for designing, implementing, and managing our Microsoft Defender solutions with the overarching automation platform to protect our organization from cyber threats.  In addition, the candidate will be responsible for implementing automation strategies to allow for seamless management of applicable MDE capabilities into broader workflows via ServiceNow and other automation tools.

Responsibilities:

Overseeing Endpoint Detection and Response (EDR):

  • Guide mid-level engineers in deploying and fine-tuning EDR solutions to monitor and respond to threats in real-time.
  • Review and approve automated response playbooks created by your team.

Leading Next-Generation Antivirus (NGAV) Implementation:

  • Supervise the setup and configuration of NGAV to provide behavioral-based protection.
  • Ensure NGAV algorithms are optimized for peak performance under your team’s management.

Directing Threat & Vulnerability Management:

  • Oversee continuous vulnerability assessments conducted by your team and provide remediation recommendations.
  • Develop and execute strategies to mitigate endpoint vulnerabilities in collaboration with the larger vulnerability management team, ensuring your team’s plans align with organizational goals.

Managing Attack Surface Reduction:

  • Lead the implementation and maintenance of rules and controls to minimize the attack surface of endpoints.
  • Regularly review and update your team’s strategies to stay ahead of emerging threats.

Supervising Cloud-Delivered Protection:

  • Ensure your team integrates real-time updates and threat intelligence from the Microsoft cloud.
  • Monitor and adjust cloud-delivered protection features configured by your team.

Integrating with SIEM Solutions:

  • Guide your team in seamlessly connecting Microsoft Defender with Microsoft Sentinel and other SIEM tools.
  • Review and approve centralized logging, analytics, and reporting dashboards created by your team.

Ensuring Cross-Platform Protection:

  • Guarantee comprehensive security across Windows, Linux, and mobile devices under your team’s management.
  • Manage and monitor security solutions on diverse platforms, ensuring your team’s configurations are effective.

Delivering Comprehensive Reporting and Analytics:

  • Oversee the creation of detailed reports on security posture, incidents, and compliance by your team.
  • Approve customizable dashboards and alerts developed by your team to keep the security operations center informed.

Deploying Windows Defender Application Control (WDAC):

  • Lead the design, implementation, and management of WDAC policies to control which applications can run on endpoints.
  • Ensure your team’s WDAC configurations align with organizational security policies and compliance requirements.
  • Monitor and update WDAC policies to adapt to changing threat landscapes and business needs, providing guidance and oversight to your team.

Integrating Microsoft Defender, Intune, and Purview for Data Loss Prevention (DLP):

  • Oversee the implementation and management of DLP policies using Microsoft Defender for Endpoint.
  • Ensure sensitive data on endpoints is monitored, classified, and protected against unauthorized access or exfiltration.
  • Lead the configuration and enforcement of device compliance and app protection policies using Microsoft Intune.
  • Guide the discovery, classification, and protection of sensitive data across the organization using Microsoft Purview.
  • Create and enforce DLP policies in Microsoft 365 and other cloud services to ensure data compliance and security.
  • Monitor and report on DLP incidents, providing detailed alerts and insights to the security team.
  • Integrate Microsoft Defender, Intune, and Purview to create a robust, layered DLP strategy.
  • Ensure a comprehensive view of DLP incidents across endpoints, mobile devices, and cloud services.
  • Set up unified reporting and alerts for any po

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

CACI International Inc

View company profile →