1

Microsoft 365 Defender Security Engineer Jobs (NOW HIRING)

Engineer, operate, and continuously improve the Microsoft Defender security stack (e.g., Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, Defender ...

Engineer, operate, and continuously improve the Microsoft Defender security stack (e.g., Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, Defender ...

Engineer, operate, and continuously improve the Microsoft Defender security stack (e.g., Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, Defender ...

NSB Omega is searching for a Microsoft 365 Engineer for our Client in Houston, TX. Assignment ... Configure and manage M365 security capabilities: o Microsoft Defender (Office 365, Endpoint ...

Job Summary The Microsoft 365 Engineer is responsible for the design, implementation ... Configure and manage M365 security capabilities: o Microsoft Defender (Office 365, Endpoint ...

next page

Showing results 1-20

Microsoft 365 Defender Security Engineer information

See salary details

$11

$58

$86

How much do microsoft 365 defender security engineer jobs pay per hour?

As of Jun 9, 2026, the average hourly pay for microsoft 365 defender security engineer in the United States is $58.48, according to ZipRecruiter salary data. Most workers in this role earn between $48.56 and $67.55 per hour, depending on experience, location, and employer.

What is a Microsoft 365 Defender Security Engineer?

A Microsoft 365 Defender Security Engineer is a professional responsible for protecting an organization's Microsoft 365 environment from security threats. They use Microsoft 365 Defender tools to detect, investigate, and respond to cyber threats across identities, endpoints, data, and applications. Their role involves configuring security policies, monitoring alerts, and implementing best practices to minimize risks. They also collaborate with IT and security teams to ensure comprehensive protection and compliance within the Microsoft 365 ecosystem.

What are some typical challenges Microsoft 365 Defender Security Engineers face when managing enterprise security environments?

Microsoft 365 Defender Security Engineers often encounter challenges such as staying updated with evolving threat landscapes and ensuring seamless integration across multiple security tools. Managing alerts and minimizing false positives while maintaining real-time incident response can also be demanding. Additionally, collaboration with IT and compliance teams is essential to ensure policies are consistently enforced and security posture is maintained across the organization.

What are the key skills and qualifications needed to thrive as a Microsoft 365 Defender Security Engineer, and why are they important?

To thrive as a Microsoft 365 Defender Security Engineer, you need expertise in cybersecurity concepts, threat detection, and incident response, often supported by a degree in computer science or related certifications like SC-200. Familiarity with Microsoft 365 Defender, Azure Security Center, SIEM tools, and scripting languages such as PowerShell is typically required. Strong analytical thinking, problem-solving skills, and effective communication help you investigate threats and coordinate with IT teams. These abilities are crucial for proactively protecting organizational assets, minimizing security risks, and ensuring rapid response to cyber threats.

What is the difference between Microsoft 365 Defender Security Engineer vs Microsoft 365 Security Engineer?

AspectMicrosoft 365 Defender Security EngineerMicrosoft 365 Security Engineer
CertificationsRelevant security certifications (e.g., MS-500, Security+)Similar security certifications, often including MS-500
Work EnvironmentFocuses on Microsoft 365 Defender suite, threat detection, and incident responseBroader Microsoft 365 security tools, including compliance and identity management
Industry UsagePrimarily in organizations using Microsoft 365 security solutionsWidespread across organizations implementing Microsoft 365 services

The Microsoft 365 Defender Security Engineer specializes in protecting Microsoft 365 Defender tools and managing security incidents within that suite. In contrast, the Microsoft 365 Security Engineer has a broader role, covering various Microsoft 365 security features, including compliance, identity, and threat management. Both roles require similar certifications and are vital in organizations leveraging Microsoft 365 security solutions, but their focus areas differ.

Security Engineer (Microsoft 365 Security & Detection)

PT&C Group LLC

Salt Lake City, UT โ€ข On-site

Full-time

Medical, Retirement

Posted 18 days ago


Job description

Description:

Due to continuing growth, we are seeking a Security Engineer focused on securing and monitoring a Microsoft 365โ€“centric environment. This role is responsible for detecting and responding to threats across Entra ID (Azure AD), Microsoft Defender, Intune-managed endpoints, and Microsoft 365 services including Exchange Online, SharePoint, and Teams.

You will play a key role in improving visibility, strengthening access controls, and building scalable detection and response capabilities across cloud and endpoint systems.


Who we are:

Platform Accounting Group is a rapidly growing professional services firm providing tax, accounting, assurance, IT consulting, and wealth management services to small and medium sized businesses and their owners. We currently have 50+ offices across 15 states with much more growth on the horizon. Enjoy a professional and dynamic work environment while making work/life balance a priority.


What you will do:

  • Monitor and investigate alerts across Microsoft Defender (Defender for Endpoint, Defender for Identity, Defender for Office 365) and associated security platforms
  • Analyze Entra ID (Azure AD) sign-in logs, audit logs, and risky sign-in activity to identify potential account compromise or misuse
  • Respond to security incidents involving endpoints, identities, email, and collaboration platforms
  • Tune and optimize detection rules, alert thresholds, and signal-to-noise ratios within SIEM and Microsoft security tools
  • Perform log analysis and basic threat hunting using tools such as Microsoft Sentinel, Defender Advanced Hunting, and audit logs
  • Implement and validate Conditional Access policies, MFA enforcement, and identity protection controls
  • Support endpoint security through Intune and Defender for Endpoint, including policy enforcement, device compliance, and response actions
  • Collaborate with IT to harden Microsoft 365 configurations (Exchange Online, SharePoint, Teams) and reduce attack surface
  • Support vulnerability management by identifying gaps and coordinating remediation across systems and endpoints
  • Maintain clear and audit-ready documentation of incidents, controls, and response activities
  • Assist with eDiscovery, audit requests, and compliance-related investigations when required
  • Identify gaps in monitoring, coverage, or controls and recommend improvements to security architecture

What we look for:

Core Knowledge & Experience

  • Strong understanding of Microsoft 365 security architecture, including Entra ID, Exchange Online, SharePoint, and Teams
  • Experience with Microsoft Defender security stack (Defender for Endpoint, Office 365, Identity, or Cloud Apps)
  • Familiarity with identity security concepts such as MFA, Conditional Access, and identity risk
  • Experience with endpoint management and security using Microsoft Intune or similar platforms
  • Working knowledge of incident response processes and common attack techniques (phishing, credential abuse, lateral movement)

Technical Skills (One or More of the Following)

  • Log analysis and threat hunting using Microsoft Sentinel or Defender Advanced Hunting (KQL experience preferred)
  • Experience configuring and tuning alerts in SIEM, EDR, or cloud-native security tools
  • Scripting or automation using PowerShell, KQL, or Python
  • Experience with email security, phishing analysis, and investigation within Exchange Online

Operational & Behavioral Skills

  • Ability to investigate and document security incidents with clarity and precision
  • Strong communication skills with both technical and non-technical stakeholders
  • Ability to collaborate across IT, infrastructure, and compliance teams
  • Strong ownership mindset and ability to drive issues through resolution
  • Continuous learning mindset with interest in cloud security and advanced detection

Preferred, but Not Required

  • Experience with Microsoft Purview (compliance, audit, or eDiscovery)
  • Familiarity with regulatory or compliance frameworks (e.g., SOC 2, GLBA, HIPAA)
  • Exposure to automation, detection engineering, or security orchestration (SOAR)
  • Experience supporting security operations in a cloud-first or hybrid environment
  • Experience with AVD and Azure infrastructure

What we offer:

  • Opportunity for advancement within a rapidly growing professional services firm
  • Competitive compensation
  • 401(k) and medical benefits
Requirements: