1

Defender Xdr Jobs in Washington (NOW HIRING)

Senior Cyber Defender

Annapolis, MD · On-site

$99K - $127K/yr

Your role and responsibilities As a Senior Cyber Defender, you play a vital role in safeguarding an ... Proficiency in using various cybersecurity tools, including SIEM, SOAR, EDR, and XDR platforms, to ...

Develop and maintain enterprise operational dashboards utilizing Power BI, Microsoft Graph, Log Analytics, Defender XDR, Intune, MECM, and Jamf reporting. * Produce executive, operational, and ...

Your role and responsibilities As a Cyber Defender, you will play a vital role in safeguarding an ... Investigate security incidents using SIEM, SOAR, EDR, and XDR platforms, and apply industry ...

Hybrid Multi-Cloud Engineer SME

Fort Belvoir, VA · Hybrid

$63 - $84.25/hr

This includes integration with SIEM/SOAR (Microsoft Sentinel and Defender XDR), enabling Zero Trust policy and governance across the multi-cloud environment, and implementation of ZT architecture ...

This includes integration with SIEM/SOAR (Microsoft Sentinel and Defender XDR), enabling Zero Trust policy and governance across the multi-cloud environment, and implementation of ZT architecture ...

Hybrid Multi-Cloud Engineer SME

Fort Belvoir, VA · On-site

$63 - $84.25/hr

This includes integration with SIEM/SOAR (Microsoft Sentinel and Defender XDR), enabling Zero Trust policy and governance across the multi-cloud environment, and implementation of ZT architecture ...

EDR/XDR engineering (CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne) · Behavioral threat hunting and detection authoring · Windows/Linux kernel internals and API hooking · Multi ...

New

SOC Analyst

Washington, DC · Remote

$50 - $55/hr

Analyze alerts from EDR/XDR solutions such as Microsoft Defender. * Monitor identity-related risks across platforms including Okta, Entra ID, and Privileged Identity Management. * Investigate ...

Showing results 21-40

Defender Xdr information

What is Defender XDR?

Defender XDR (Extended Detection and Response) is a cybersecurity solution provided by Microsoft that integrates and automates threat detection, investigation, and response across multiple security domains such as endpoints, identities, email, and cloud applications. It provides a unified platform to help security teams identify and respond to sophisticated cyber threats more efficiently. By correlating data and alerts from various sources, Defender XDR enables organizations to detect complex attacks, reduce response times, and improve overall security posture.

What are the key skills and qualifications needed to thrive as a Defender XDR specialist?

To excel as a Defender XDR Specialist, you need a solid understanding of cybersecurity principles, threat detection, and incident response, often supported by certifications like CompTIA Security+ or Microsoft Certified: Security Operations Analyst Associate. Familiarity with Microsoft Defender XDR, SIEM tools, and other security platforms is crucial for monitoring and analyzing threats. Strong analytical thinking, attention to detail, and effective communication skills help you interpret complex security data and collaborate with IT teams. These skills are essential for proactively identifying and mitigating cyber threats, ensuring robust organizational security.

What are some common challenges faced by professionals working with Microsoft Defender XDR, and how can they be addressed?

Professionals working with Microsoft Defender XDR often encounter challenges such as integrating multiple security tools, managing a high volume of alerts, and staying updated with evolving threats. To address these, it's important to develop a strong understanding of the XDR platform, establish clear incident response processes, and leverage automation features to reduce manual workloads. Collaboration with IT, security, and compliance teams is also key to maintaining a cohesive security posture and ensuring timely resolution of incidents.

What is the difference between Defender Xdr vs Security Analyst?

AspectDefender XdrSecurity Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, CEH
Work EnvironmentSecurity tools, incident response, threat detectionMonitoring, analyzing security data, incident investigation
Employer & Industry UsageCybersecurity teams, IT departmentsSecurity teams, IT departments, consulting firms

While both Defender Xdr and Security Analysts work in cybersecurity, Defender Xdr focuses on deploying and managing extended detection and response tools, whereas Security Analysts analyze security data and respond to incidents. Defender Xdr specialists often implement and configure security solutions, while Security Analysts interpret alerts and investigate threats. Both roles require similar certifications and work environments, but their core responsibilities differ in focus and scope.

What are popular job titles related to Defender Xdr jobs in Washington?

For Defender Xdr jobs in Washington, the most frequently searched job titles are:

What job categories do people searching Defender Xdr jobs in Washington look for?

The top searched job categories for Defender Xdr jobs in Washington are:

What cities in Washington are hiring for Defender Xdr jobs?

Cities in Washington with the most Defender Xdr job openings:

Infographic showing various Defender Xdr job openings in Washington as of August 2026, with employment types broken down into 91% Full Time, 4% Part Time, and 5% Contract. Highlights an 79% Physical, 10% Hybrid, and 11% Remote job distribution.

Senior Microsoft Cloud Security Engineer/Architect (On-Site)

Groundswell Agriculture Festival

Mclean, VA • On-site

$66.25 - $88/hr

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 9 days ago


Key responsibilities

  • Serve as the senior on-site technical support for cybersecurity operations, including incident response, investigations, threat identification, containment, recovery, root-cause analysis, and post-incident improvements.

  • Act as an escalation point for complex security, cloud, identity, endpoint, network, Azure Virtual Desktop, and infrastructure issues.

  • Administer privileged access and identity controls, maintain network environment, manage vulnerability and configuration, and lead backup and recovery processes for Microsoft 365 GCC High.


Job description

Who Are We?
Groundswell is a premier technology integrator and solution provider, resolutely committed to solving the most complex challenges facing federal agencies today. Our name, Groundswell, represents our commitment to be an unstoppable, seismic change in government. Ours is a small company culture with big company reach and results. Are you ready to be audacious, be bold and drive change at a rapid pace? Join us, where we'll make a greater impact together.


What You'll do:

Groundswell is seekinganexperienced, hands-on CybersecuritySpecialistto serve as the senior on-site technicalsupportfor cybersecurity operations, Microsoft Azure Government, Microsoft 365 GCC High, cloud infrastructure, identity, endpoint security, networking, and incident response.

This rolewill serve asanescalation point for complex security and infrastructure issues,and to helpstrengthen Groundswell's internal cyber capabilities,supportingthe company's ongoing compliancewith CMMC level 2. The position willberesponsiblefor investigations, configuration, troubleshooting, control implementation, and high-impact issue resolution.

Theindividual contributorposition works closely withsmall internal operations teamand External Supplier teams.

Key Responsibilities

  • Owncybersecurity operationsto includeincident response,investigations,response, threat identificationthreat,containment, recovery, root-cause analysis, and post-incident improvements.

  • escalation point for complex security, cloud, identity, endpoint, network, Azure Virtual Desktop, and infrastructure issues.

  • Administer privileged access and identity controls, including Conditional Access, multifactor authentication, service principals, Privileged Identity Management, least privilege, separation of duties, and time-limited elevation.

  • MaintainCiscoMerakienvironment, including firewalls, switches, wireless access points, VLANs, access-control lists, segmentation, logging, site connectivity, outage response, and recovery documentation.

  • vulnerability and configuration management using Tenable, Microsoft Defender, Microsoft Secure Score, vendor advisories, and threat-intelligence sources. Prioritize findings based on severity, exploitability, exposure, asset criticality, known exploitation, operational risk, and CUI impact; coordinate remediation, documentexceptionsand residual risk, and confirm corrective actions are effective.

  • Lead AvePoint backup and recovery for Microsoft 365 GCC High, including monitoring jobs, resolving failures, testing restores, andmaintainingrecovery practices for Exchange, SharePoint, OneDrive, and Teams.

  • Serve as a technical subject matter expert for CMMC Level 2 and related certification programs bymaintainingthe System Security Plan, Plans of Action and Milestones,etc

  • Provide seniorescalation support while preserving the Helpdesk's responsibility for routine ticket intake and normal user support, and mentor Helpdesk personnel in incident recognition, evidence preservation, escalation, troubleshooting, and documentation.

  • Prepare, review, implement, and document technical changesin supportofCMMI-SVC, ISO 9001, ISO/IEC 20000-1, ISO/IEC 27001, UK Cyber Essentials, and CMMC requirements.

Required Qualifications:

  • Bachelor's degree in cybersecurity, computer science, information systems, engineering, network engineering, or a related technical field.

  • 10yearyears+experience in cybersecurity operations, cloud security, infrastructure engineering, network engineering, incident response, or a related field.

  • Direct hands-on experience with Microsoft GCC High, Azure Government, Department of Defense cloud environments, or a comparable regulated Microsoft environment.

  • Advanced production experience with Microsoft Sentinel, Defender XDR, Entra ID, Intune, Purview, Exchange Online, SharePoint Online, Teams, Azure networking, Azure Virtual Desktop, KQL, and PowerShell.

  • Hands-on experience administering enterprise network infrastructure and resolving complex cloud, identity, endpoint, and network issues.

  • Demonstrated experience producing technical evidence for audits or assessments, remediating security findings,validatingcorrective actions, and explaining technical risks and controls to technical and nontechnical audiences

  • Ability to lead incident response under pressure, remain personally hands-on, exercise discretion with CUI and sensitive records, manage competing priorities, and work effectively witha variety of customers

  • US Citizenship required for clearance purposes.

  • Location: position is full time on-site in our Mclean, VA office.

Preferred Qualifications:

  • Microsoft Cybersecurity Architect Expert, Microsoft Security Operations Analyst Associate, or Microsoft Azure Security Engineer Associate certification.

  • Demonstrated experience leading AvePoint backup and recovery, security automation, or large-scale operational improvement in a regulated Microsoft Government cloud environment.

  • Advanced Cisco networking experience, including CCNP Enterprise or Cisco Meraki Solutions Specialist certification.


Skills:


Certification:

Why You'll Never Want to Leave:

  • Comprehensive medical, dental, and vision plans
  • Flexible Spending Account
  • 4% 401K Match (immediate vesting)
  • Paid Time Off
  • Tuition reimbursement, certification programs, and professional development
  • Flexible work schedule
  • On-site gym and childcare option

The salary range for this role takes into account the wide range of factors that are considered in making compensation decisions, including but not limited to skill sets, experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for any applicable geographic differential associated with the location at which the position may be filled. At Groundswell, it is not typical for an individual to be hired at or near the top of the range for their role, and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is:

$116,724.00 - $209,019.00


NOTE:Groundswell does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Groundswell, and Groundswell will not be obligated to pay a placement fee.

Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.

Read a copy of the Company's Non-Discrimination Policy Statement.
Additional Resources:

  • EO 13496 Notification of Employee Rights under NLRA

  • Know your rights: Workplace Discrimination is Illegal

Disability Accessibility Accommodation: If you are an individual with a disability and would like to request a reasonable accommodation as part of the employment selection process, please contact us athr@gswell.comor703-639-1777.