Design, implement, and continuously improve security controls across Microsoft Entra ID, Conditional Access, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity ...
Design, implement, and continuously improve security controls across Microsoft Entra ID, Conditional Access, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity ...
Design, implement, and continuously improve security controls across Microsoft Entra ID, Conditional Access, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity ...
Design, implement, and continuously improve security controls across Microsoft Entra ID, Conditional Access, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity ...
Lead SOC Analyst
Grand Rapids, MI · On-site
Preferred : • Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms. • Experience working in a hybrid SOC model (internal + MDR). • Familiarity with compliance ...
Lead SOC Analyst
Grand Rapids, MI · On-site
Preferred : • Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms. • Experience working in a hybrid SOC model (internal + MDR). • Familiarity with compliance ...
Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms. * Experience working in a hybrid SOC model (internal + MDR). * Familiarity with compliance frameworks (e.g., NIST ...
Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms. * Experience working in a hybrid SOC model (internal + MDR). * Familiarity with compliance frameworks (e.g., NIST ...
Lead SOC Analyst
Grand Rapids, MI · On-site
$90 - $120/hr
Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms. * Experience working in a hybrid SOC model (internal + MDR). * Familiarity with compliance frameworks (e.g., NIST ...
Lead SOC Analyst
Grand Rapids, MI · On-site
$90 - $120/hr
Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms. * Experience working in a hybrid SOC model (internal + MDR). * Familiarity with compliance frameworks (e.g., NIST ...
Defender XDR * SCCM Preferred: * Microsoft Certifications such as: (SC-900, SC-100, SC-200, SC-300, SC-400), * Cyber Certifications such as: CCSP, CCSK, CISSP, CCNP, and CCNA. * BA/BS Degree ...
Defender XDR * SCCM Preferred: * Microsoft Certifications such as: (SC-900, SC-100, SC-200, SC-300, SC-400), * Cyber Certifications such as: CCSP, CCSK, CISSP, CCNP, and CCNA. * BA/BS Degree ...
Lead SOC Analyst
Grand Rapids, MI · On-site
Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms. * Experience working in a hybrid SOC model (internal + MDR). * Familiarity with compliance frameworks (e.g., NIST ...
Lead SOC Analyst
Grand Rapids, MI · On-site
Experience with Splunk, Microsoft Sentinel, Defender XDR, and/or similar platforms. * Experience working in a hybrid SOC model (internal + MDR). * Familiarity with compliance frameworks (e.g., NIST ...
Cloud Security Senior Manager - Azure Infrastructure & AI
Detroit, MI · On-site
$64.75 - $86.25/hr
... Defender XDR, and Microsoft Security Copilot; and experience leading project scope, pricing, and delivery across multiple concurrent proposals and projects * 10+ years of experience in enterprise ...
Cloud Security Senior Manager - Azure Infrastructure & AI
Detroit, MI · On-site
$64.75 - $86.25/hr
... Defender XDR, and Microsoft Security Copilot; and experience leading project scope, pricing, and delivery across multiple concurrent proposals and projects * 10+ years of experience in enterprise ...
Cloud Security Senior Consultant - M365
$56.25 - $76.50/hr
Purview, Intune, Sentinel, Security Copilot, Entra ID, Defender for Office, Defender for Endpoints and Servers, Defender for Vulnerabilities, Defender for Cloud Apps, Defender XDR and SCCM * Conduct ...
Cloud Security Senior Consultant - M365
$56.25 - $76.50/hr
Purview, Intune, Sentinel, Security Copilot, Entra ID, Defender for Office, Defender for Endpoints and Servers, Defender for Vulnerabilities, Defender for Cloud Apps, Defender XDR and SCCM * Conduct ...
Cloud Security Senior Manager - Azure Infrastructure & AI
Grand Rapids, MI · On-site
$63 - $83.50/hr
... Defender XDR, and Microsoft Security Copilot; and experience leading project scope, pricing, and delivery across multiple concurrent proposals and projects * 10+ years of experience in enterprise ...
Cloud Security Senior Manager - Azure Infrastructure & AI
Grand Rapids, MI · On-site
$63 - $83.50/hr
... Defender XDR, and Microsoft Security Copilot; and experience leading project scope, pricing, and delivery across multiple concurrent proposals and projects * 10+ years of experience in enterprise ...
Cloud Security Senior Consultant - M365
Detroit, MI · On-site
$58 - $79/hr
Purview, Intune, Sentinel, Security Copilot, Entra ID, Defender for Office, Defender for Endpoints and Servers, Defender for Vulnerabilities, Defender for Cloud Apps, Defender XDR and SCCM * Conduct ...
Cloud Security Senior Consultant - M365
Detroit, MI · On-site
$58 - $79/hr
Purview, Intune, Sentinel, Security Copilot, Entra ID, Defender for Office, Defender for Endpoints and Servers, Defender for Vulnerabilities, Defender for Cloud Apps, Defender XDR and SCCM * Conduct ...
Defender XDR * SCCM Preferred: * Microsoft Certifications such as: (SC-900, SC-100, SC-200, SC-300, SC-400), * Cyber Certifications such as: CCSP, CCSK, CISSP, CCNP, and CCNA. * BA/BS Degree ...
Defender XDR * SCCM Preferred: * Microsoft Certifications such as: (SC-900, SC-100, SC-200, SC-300, SC-400), * Cyber Certifications such as: CCSP, CCSK, CISSP, CCNP, and CCNA. * BA/BS Degree ...
Proactively hunt for threats across the environment using tools like Microsoft Defender XDR. * Develop and implement strategies to defend against prevalent malware types (e.g., ransomware, spyware ...
Quick apply
Proactively hunt for threats across the environment using tools like Microsoft Defender XDR. * Develop and implement strategies to defend against prevalent malware types (e.g., ransomware, spyware ...
Security Architect
Southfield, MI · On-site
$59.75 - $77/hr
Microsoft Sentinel, Defender XDR, automation and incident response * Compliance: CMMC 2.0, NIST 800-171/172, ITAR, risk management Benefits Overview We offer competitive company benefits to eligible ...
Security Architect
Southfield, MI · On-site
$59.75 - $77/hr
Microsoft Sentinel, Defender XDR, automation and incident response * Compliance: CMMC 2.0, NIST 800-171/172, ITAR, risk management Benefits Overview We offer competitive company benefits to eligible ...
Security
Southfield, MI · On-site
$60 - $77.50/hr
Microsoft Sentinel, Defender XDR, automation and incident response * Compliance: CMMC 2.0, NIST 800-171/172, ITAR, risk management Benefits Overview We offer competitive company benefits to eligible ...
Security
Southfield, MI · On-site
$60 - $77.50/hr
Microsoft Sentinel, Defender XDR, automation and incident response * Compliance: CMMC 2.0, NIST 800-171/172, ITAR, risk management Benefits Overview We offer competitive company benefits to eligible ...
... Defender, Cortex XDR, or CrowdStrike, and governance, risk, or compliance work using established frameworks; Palo Alto Networks PCNSE, Certified Cybersecurity Associate, or equivalent cybersecurity ...
... Defender, Cortex XDR, or CrowdStrike, and governance, risk, or compliance work using established frameworks; Palo Alto Networks PCNSE, Certified Cybersecurity Associate, or equivalent cybersecurity ...
... Defender, Cortex XDR, or CrowdStrike, and governance, risk, or compliance work using established frameworks; Palo Alto Networks PCNSE, Certified Cybersecurity Associate, or equivalent cybersecurity ...
... Defender, Cortex XDR, or CrowdStrike, and governance, risk, or compliance work using established frameworks; Palo Alto Networks PCNSE, Certified Cybersecurity Associate, or equivalent cybersecurity ...
IT Security Ops Manager
Ann Arbor, MI · On-site
Responsibilities : • Own and manage enterprise endpoint security platforms including EDR/XDR ... SentinelOne, CrowdStrike, Microsoft Defender for Endpoint, Carbon Black; DLP: Forcepoint ...
IT Security Ops Manager
Ann Arbor, MI · On-site
Responsibilities : • Own and manage enterprise endpoint security platforms including EDR/XDR ... SentinelOne, CrowdStrike, Microsoft Defender for Endpoint, Carbon Black; DLP: Forcepoint ...
IT Security Ops Manager
Ann Arbor, MI · On-site
Responsibilities : • Own and manage enterprise endpoint security platforms including EDR/XDR ... SentinelOne, CrowdStrike, Microsoft Defender for Endpoint, Carbon Black; DLP: Forcepoint ...
IT Security Ops Manager
Ann Arbor, MI · On-site
Responsibilities : • Own and manage enterprise endpoint security platforms including EDR/XDR ... SentinelOne, CrowdStrike, Microsoft Defender for Endpoint, Carbon Black; DLP: Forcepoint ...
IT Network Manager - Endpoint Security
Ann Arbor, MI · On-site
$114.10 - $194/hr
EDR/XDR, endpoint protection, device control, DLP and endpoint privilege management agents**.* Lead ... SentinelOne, CrowdStrike, Microsoft Defender for Endpoint, Carbon Black + DLP: Forcepoint ...
New
IT Network Manager - Endpoint Security
Ann Arbor, MI · On-site
$114.10 - $194/hr
EDR/XDR, endpoint protection, device control, DLP and endpoint privilege management agents**.* Lead ... SentinelOne, CrowdStrike, Microsoft Defender for Endpoint, Carbon Black + DLP: Forcepoint ...
New
Defender Xdr information
What is Defender XDR?
What is the difference between Defender Xdr vs Security Analyst?
| Aspect | Defender Xdr | Security Analyst |
|---|---|---|
| Certifications | CompTIA Security+, CISSP, CEH | CompTIA Security+, CISSP, CEH |
| Work Environment | Security tools, incident response, threat detection | Monitoring, analyzing security data, incident investigation |
| Employer & Industry Usage | Cybersecurity teams, IT departments | Security teams, IT departments, consulting firms |
While both Defender Xdr and Security Analysts work in cybersecurity, Defender Xdr focuses on deploying and managing extended detection and response tools, whereas Security Analysts analyze security data and respond to incidents. Defender Xdr specialists often implement and configure security solutions, while Security Analysts interpret alerts and investigate threats. Both roles require similar certifications and work environments, but their core responsibilities differ in focus and scope.
What are the key skills and qualifications needed to thrive as a Defender XDR specialist?
What are some common challenges faced by professionals working with Microsoft Defender XDR, and how can they be addressed?
Full-time
Medical, Dental, Vision, Retirement, PTO
Posted 18 days ago
BeneSys rating
7.8
Based on 11 frontline employees who took The Breakroom Quiz
150th of 483 rated business services
Job description
- Monitor, investigate, triage, and respond to alerts generated by enterprise security platforms, including:
- Endpoint Detection and Response (EDR)
- Extended Detection and Response (XDR)
- Security Information and Event Management (SIEM)
- Vulnerability management platforms
- Email security systems (malware, phishing, spam, blacklisting, and relay protection)
- External breach notifications and threat intelligence
- Deploy, configure, maintain, upgrade, and decommission cybersecurity software, hardware, and security appliances in collaboration with the IT Infrastructure team.
- Continuously optimize existing security tools and configurations to improve detection capabilities, align with industry best practices, and support business requirements.
- Assist with secure integration of third-party applications and services, including Single Sign-On (SSO), OAuth, and Microsoft Entra ID identity services.
- Design, implement, and continuously improve security controls across Microsoft Entra ID, Conditional Access, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud, and Microsoft Defender for Cloud Apps.
- Administer and continuously enhance the organization's SIEM platform by developing analytics rules, dashboards, workbooks, data connectors, and monitoring content to improve visibility and detection fidelity.
- Develop and maintain Kusto Query Language (KQL) detection libraries, threat hunting queries, automation workflows, Logic Apps, playbooks, and other SOAR capabilities.
- Deploy and maintain endpoint security technologies, including Managed Detection and Response (MDR) solutions.
- Perform vulnerability assessments, prioritize remediation efforts, and coordinate corrective actions with the IT Infrastructure team.
- Support internal and external compliance initiatives, including security audits, penetration testing, risk assessments, and regulatory reviews.
- Investigate, document, and report cybersecurity incidents, including root cause analysis, impact assessments, and remediation activities.
- Assist in developing, maintaining, and improving cybersecurity policies, standards, procedures, and technical documentation.
- Research emerging cybersecurity threats, vulnerabilities, technologies, and industry trends, providing recommendations for improving the organization's security posture.
- Participate in security awareness training and provide technical guidance to IT staff and end users as needed.
- Maintain accurate operational documentation, security metrics, support logs, and incident records.
- Communicate project status, security incidents, operational metrics, and remediation progress to the Manager of Cybersecurity in a timely and professional manner.
- Demonstrate regular attendance, professionalism, accountability, and compliance with all company policies, procedures, and security standards.
- Regular and predictable attendance is an essential function of this job.
- Required Experience
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field, or equivalent professional experience.
- Minimum of four (4) years of progressively responsible experience in cybersecurity, including Security Operations Center (SOC), Incident Response, Threat Hunting, Security Engineering, or similar roles.
- Minimum of one (1) year of experience supporting enterprise IT infrastructure, such as Service Desk, Systems Administration, or Infrastructure Engineering.
- Minimum of two (2) years of hands-on experience administering Microsoft Defender XDR and Microsoft Sentinel.
- Technical Knowledge
- Strong understanding of cybersecurity threats, attacker tactics, techniques, and procedures (TTPs).
- Experience with incident response methodologies and security operations.
- Experience securing hybrid cloud, cloud-native, and on-premises enterprise environments.
- Working knowledge of cybersecurity frameworks and regulatory standards, including NIST, ISO 27001, CIS Controls, HIPAA, HITRUST, and COBIT.
- Strong PowerShell scripting skills and experience using Python (preferred) or another general-purpose programming language for automation, threat detection, and response.
- Experience with Kusto Query Language (KQL) for Microsoft Sentinel and Microsoft Defender.
- Experience with Microsoft Active Directory, Microsoft Entra ID, Windows Server, Group Policy, and enterprise identity management.
- Familiarity with endpoint management technologies, including MDM, MAM, and Microsoft Intune.
- Working knowledge of firewalls, IDS/IPS technologies, encryption, authentication, and identity security.
- Excellent troubleshooting, analytical, and problem-solving skills.
- Professional Competencies
- Self-motivated with the ability to work independently while contributing effectively within a collaborative team.
- Strong verbal and written communication skills with the ability to explain technical concepts clearly to both technical and non-technical audiences.
- Demonstrated ability to manage multiple priorities and adapt quickly to changing business needs.
- Strong organizational skills and attention to detail.
- Ability to summarize incidents, projects, risks, and technical findings in a concise and meaningful manner.
- Commitment to continuous learning and professional development.
- Demonstrates professionalism, accountability, reliability, punctuality, and proactive communication.
Competitive Benefits and Compensation Package
- 12 paid holidays
- Paid Time Off (PTO)
- Pro-rated during first year of employment
- 15 days of PTO provided in the next calendar year!
- 3 days paid bereavement
- Up to 20 days paid jury leave
- Medical, dental, and vision insurance, with option for dependent coverage
- Company-paid basic life, short-term disability, long-term disability, and AD amp;D insurance
- 401k with employer match
- Tuition reimbursement program
- Career development opportunities
- Referral bonus for all successful full-time referrals
- Annual opportunities for increases
BeneSys wants to be a great service provider to the members we serve, and we recognize we can only do that if we are also a great employer with successful employees. In short, our success is driven by our employees' successes. We want to be a place where people want to work, feel proud of what they do and feel fulfilled both professionally and personally. We want to create a place where employees can find long-term growth and potential.
Our culture focuses on three core values:
- Collaboration: working together across 31 locations to achieve the best for the company and our clients
- Dedication: striving to create an environment where all employees work toward a common goal while committing to providing the best customer service to our members and our colleagues
- Integrity: doing what we say we will do. Upholding strong ethical and moral principles
About BeneSys
Sourced by ZipRecruiter
Industry
Insurance and employee benefit funds
Company size
501 - 1,000 Employees
Headquarters location
Troy, MI, US
Year founded
1979