1

Microsoft 365 Defender Jobs (NOW HIRING)

... Defender Suite and Compliance • Architect and configure Microsoft Defender for Office 365 -- anti-phishing policies, safe links, safe attachments, attack simulation training, and threat ...

Engineer, operate, and continuously improve the Microsoft Defender security stack (e.g., Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, Defender ...

Engineer, operate, and continuously improve the Microsoft Defender security stack (e.g., Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, Defender ...

Implement and maintain security and compliance controls across M365 (Defender, Purview, audit ... Microsoft 365 environments * Strong expertise in Azure AD / Entra ID, Exchange Online, SharePoint ...

next page

Showing results 1-20

Microsoft 365 Defender information

See salary details

$36K

$68.4K

$116K

How much do microsoft 365 defender jobs pay per year?

As of Jun 9, 2026, the average yearly pay for microsoft 365 defender in the United States is $68,438.00, according to ZipRecruiter salary data. Most workers in this role earn between $43,500.00 and $85,000.00 per year, depending on experience, location, and employer.

What is Microsoft 365 Defender?

Microsoft 365 Defender is a comprehensive security solution that helps protect organizations from sophisticated cyber threats across Microsoft 365 services, including email, endpoints, identities, and applications. It integrates multiple security products—such as Microsoft Defender for Office 365, Defender for Endpoint, Defender for Identity, and Defender for Cloud Apps—into a unified platform. This integration enables automated detection, investigation, and response to threats, providing security teams with greater visibility and control. By correlating signals across different domains, Microsoft 365 Defender helps organizations respond to attacks more efficiently and reduce the impact of potential breaches.

What is the difference between Microsoft 365 Defender vs Security Analyst?

FeatureMicrosoft 365 DefenderSecurity Analyst
Primary RoleCybersecurity platform for threat detection and response within Microsoft 365 environmentHuman cybersecurity professional analyzing threats, managing security incidents
CredentialsCertifications like Microsoft Certified: Security, Compliance, and Identity FundamentalsCertifications such as CompTIA Security+, CISSP, or CEH
Work EnvironmentSecurity tools, dashboards, cloud-based managementMonitoring security alerts, incident investigation, reporting

Microsoft 365 Defender is a security platform that automates threat detection and response within Microsoft 365, while a Security Analyst is a professional who manually investigates and manages security incidents. Both roles often work together to ensure organizational security, but one is technology-driven, and the other is human-driven.

What are the typical daily responsibilities of a Microsoft 365 Defender specialist?

As a Microsoft 365 Defender specialist, your daily responsibilities often include monitoring security alerts, investigating potential threats, and managing incident response activities across Microsoft 365 environments. You'll collaborate closely with IT and security teams to analyze suspicious activity, configure security policies, and ensure the organization remains protected against evolving threats. Regular tasks may also involve conducting vulnerability assessments, reporting on security posture, and providing recommendations for improving defense strategies.

What are the key skills and qualifications needed to thrive as a Microsoft 365 Defender specialist, and why are they important?

To thrive as a Microsoft 365 Defender specialist, you need a solid understanding of cybersecurity principles, threat detection, incident response, and experience with Microsoft security solutions, often supported by certifications like Microsoft Certified: Security Operations Analyst Associate. Proficiency in using Microsoft 365 Defender, Azure Sentinel, and security information and event management (SIEM) tools is crucial. Strong analytical thinking, problem-solving abilities, and effective communication stand out as vital soft skills. These competencies are essential for identifying and mitigating threats, ensuring robust organizational security, and collaborating efficiently across teams.

Microsoft 365 Engineer

PRI Technology

Philadelphia, PA • On-site

$55 - $65/hr

Contractor

This job post has expired 1 day ago. Applications are no longer accepted.


Job description

NO H1S OR 3RD PARTIES

THIS ROLE WILL BE ONSITE 4-5 DAYS PER WEEK IN PHILADELPHIA.

Fast-paced Managed Services Provider needs a Microsoft 365 to work on client projects. This is a long-term contract, likely contract-to-hire. Must be willing to handle basic IT support duties when there are no network projects on the calendar.

Tenant Architecture — Start New or Reconfigure

• Define tenant structure, domain configuration, admin role hierarchy, and governance framework before any user provisioning begins

• Establish licensing architecture — map E3/E5 tiers and add-on licenses to actual client security and compliance requirements; eliminate waste

• Design and enforce naming conventions, group policy, and organizational unit structure that scales as client environments grow

• Set security baselines aligned to CIS Benchmarks and Microsoft Secure Score; document deviations with business justification

• Conduct architecture reviews of existing tenants; produce gap assessments and remediation roadmaps


Identity Architecture — Entra ID and Hybrid Identity

• Own the identity model end to end: Entra ID (Azure AD) design, hybrid identity with on-premises Active Directory synchronization, SSO configuration, and Privileged Identity Management

• Design Conditional Access policy frameworks — device compliance requirements, location-based controls, session policies, and risk-based authentication

• Architect MFA enforcement strategy including DUO integration and phased rollout across managed and unmanaged device populations

• Configure and govern external identity — guest access policies, B2B collaboration controls, and cross-tenant access settings

• Design RBAC frameworks for client administrative teams; enforce least-privilege across all admin roles


Security Architecture — M365 Defender Suite and Compliance

• Architect and configure Microsoft Defender for Office 365 — anti-phishing policies, safe links, safe attachments, attack simulation training, and threat intelligence integration

• Design and implement Microsoft Purview governance: data classification taxonomy, sensitivity labels, DLP policies, retention schedules, and eDiscovery readiness

• Own email authentication architecture — SPF, DKIM, and DMARC configuration, validation, and ongoing monitoring across client domains

• Configure and maintain Mimecast policy frameworks as a layered security control alongside native M365 defenses

• Lead M365 tenant security audits using tools including Prowler and Microsoft Secure Score; produce findings reports and drive remediation to closure

• Design network perimeter integration — Entra ID connectors to Palo Alto for device-group-based conditional access; coordinate with network engineering team


Migration Architecture — On-Premises to Cloud

• Lead the full architecture of on-premises Exchange to Exchange Online migrations: hybrid coexistence design, namespace planning, migration batching strategy, and cutover sequencing

• Architect SharePoint Online and OneDrive migrations from file servers and on-premises SharePoint; define permission model, site architecture, and external sharing policy before data moves

• Own pre-migration assessment — identify legacy dependencies, archive mailbox complexity, and third-party integration conflicts that affect migration timeline

• Direct migration tooling selection and execution — BitTitan MigrationWiz and equivalent platforms; own quality validation at each phase

• Produce client-facing migration plans, change control documentation, and rollback procedures; own stakeholder communication throughout


Endpoint and Device Architecture

• Design Microsoft Intune enrollment and compliance policy frameworks — Windows, macOS, iOS — aligned to Conditional Access requirements

• Architect application deployment and update management strategy through Intune; integrate with Autopilot for zero-touch provisioning

• Configure Apple Business Manager and Apple Push Notification certificate management for mobile device environments


Practice Leadership and Knowledge Transfer

• Serve as the architectural escalation point for the M365 practice team

• Document architecture decisions, configuration standards, and design patterns in a reusable internal knowledge base

• Mentor mid-level M365 engineers on security architecture, platform governance, and design methodology




Required Experience


• 7+ years of Microsoft 365 experience with at least 3 years in an architect or senior design role

• Multiple greenfield M365 tenant builds delivered end-to-end — from initial design through user cutover — in a multi-client environment

• At least 3 completed on-premises Exchange to Exchange Online migrations including hybrid coexistence configuration

• Deep, hands-on expertise with Entra ID, Conditional Access policy design, and hybrid identity architecture

• Demonstrated ownership of M365 security architecture — Defender for Office 365, Purview/Compliance Center, DLP, and sensitivity labeling

• Proficiency in PowerShell for M365 architecture automation, tenant auditing, and reporting

• Experience designing and validating SPF, DKIM, and DMARC configurations across multiple client domains

• Track record of producing architecture documentation — design decisions, gap assessments, remediation roadmaps — that non-technical stakeholders can act on



Preferred Qualifications


• Microsoft Certified: M365 Enterprise Administrator Expert (MS-102)

• Microsoft Certified: Identity and Access Administrator (SC-300)

• Microsoft Certified: Information Protection and Compliance Administrator (SC-400) or Azure Security Engineer (AZ-500)

• Experience with Mimecast policy architecture in conjunction with native M365 security controls

• Familiarity with Lepide, CloudAlly, or equivalent M365 auditing and backup platforms

• Exposure to Microsoft Copilot deployment governance and AI integration policy design

• MSP background with financial services or regulated-industry client base

#PRITechJobs