1

Microsoft Defender Jobs in Reston, VA (NOW HIRING)

Microsoft Defender XDR * Correlate log and alert data to detect lateral movement, privilege escalation, anomalous behavior, and advanced persistent threats using Microsoft Defender data and ...

Sr. CrowdStrike Engineer

Washington, DC · On-site

$118.40K - $162.50K/yr

Provide engineering, architecture, and Tier 3 support for EDR/NGAV platforms (CrowdStrike, Microsoft Defender) * Design, implement, and optimize endpoint protection policies across enterprise ...

Proficient in one or more EDR platforms (Trellix HX/EDRF or Microsoft Defender for Endpoint EDR, preferably both). • Cloud Applications: Experience with cloud security and familiarity with cloud ...

next page

Showing results 1-20

Microsoft Defender information

See Reston, VA salary details

$11.4K

$63.9K

$82.7K

How much do microsoft defender jobs pay per year?

As of May 30, 2026, the average yearly pay for microsoft defender in Reston, VA is $63,892.00, according to ZipRecruiter salary data. Most workers in this role earn between $53,100.00 and $74,900.00 per year, depending on experience, location, and employer.

What is a Microsoft Defender job?

A Microsoft Defender job typically involves working with Microsoft's security solutions to protect systems, networks, and data from cyber threats. Professionals in this role may focus on threat detection, incident response, vulnerability management, and security policy enforcement. They use Microsoft Defender products, such as Defender for Endpoint and Defender for Office 365, to monitor and mitigate security risks. This role is common in cybersecurity teams within enterprises, managed security service providers (MSSPs), and Microsoft itself. Strong knowledge of cybersecurity principles, threat intelligence, and Microsoft security tools is essential.

What are the key skills and qualifications needed to thrive in the Microsoft Defender position, and why are they important?

To thrive as a Microsoft Defender (Security Engineer or Analyst), you need a solid background in cybersecurity, network administration, and threat detection, often demonstrated by a relevant degree and certifications like CompTIA Security+ or Microsoft Certified: Security Operations Analyst Associate. Mastery of Microsoft security solutions such as Microsoft Defender for Endpoint, Azure Security Center, and SIEM tools is essential. Strong analytical thinking, attention to detail, proactive communication, and teamwork are key soft skills for success in this role. These abilities ensure you can effectively identify and mitigate threats while collaborating with cross-functional teams to maintain organizational security.

What are the typical day-to-day duties of a professional working in a Microsoft Defender security role?

In a Microsoft Defender security role, your daily responsibilities usually include monitoring security alerts, analyzing potential threats, conducting vulnerability assessments, and responding to incidents using Microsoft technologies. You’ll collaborate with IT and business teams to implement security best practices, perform regular system audits, and continuously optimize defense strategies. The role may also involve preparing security documentation, participating in incident response drills, and providing guidance on the safe use of digital resources. This position is both dynamic and collaborative, often requiring fast problem-solving to protect organizational assets effectively.
What are the most commonly searched types of Microsoft Defender jobs in Reston, VA? The most popular types of Microsoft Defender jobs in Reston, VA are:
What are popular job titles related to Microsoft Defender jobs in Reston, VA? For Microsoft Defender jobs in Reston, VA, the most frequently searched job titles are:
What job categories do people searching Microsoft Defender jobs in Reston, VA look for? The top searched job categories for Microsoft Defender jobs in Reston, VA are:
What cities near Reston, VA are hiring for Microsoft Defender jobs? Cities near Reston, VA with the most Microsoft Defender job openings:
Infographic showing various Microsoft Defender job openings in Reston, VA as of May 2026, with employment types broken down into 67% Full Time, 13% Part Time, 7% Temporary, and 13% Contract. Highlights an 60% In-person, 20% Hybrid, and 20% Remote job distribution, with an average salary of $63,892 per year, or $30.7 per hour.
Tier 2/3 Cyber Security Analyst / Microsoft Sentinel/Microsoft Defender

Tier 2/3 Cyber Security Analyst / Microsoft Sentinel/Microsoft Defender

Peraton

Washington, DC

Full-time

Posted 26 days ago


Peraton rating

8.3

Company rating: 8.3 out of 10

Based on 52 frontline employees who took The Breakroom Quiz

38th of 203 rated it services


Job description

Responsibilities

Position: Tier 2/3 Cyber Security Analyst - Microsoft Sentinel and Microsoft DefenderProgram: Peraton Federal Strategic Cyber Mission

Peraton is seeking an experienced Tier 2/3 Cyber Security Analyst to join our Federal Strategic Cyber Mission program. This role requires a seasoned cybersecurity professional with extensive handson experience implementing, configuring, and operating Microsoft Sentinel and Microsoft Defender security solutions. The ideal candidate will serve as a senior escalation point for complex security incidents, lead advanced threathunting operations, and drive the maturation of detection capabilities across the Microsoft security ecosystem.

Key Responsibilities: 

Incident Detection, Analysis, and Response Detect, classify, process, track, and report cybersecurity events and incidents across the enterprise. Serve as senior escalation point for Tier 1 and Tier 2 triage, conducting indepth analysis of complex and coordinated threats in a 24x7x365 environment. Analyze logs from multiple sources (host, EDR, firewalls, IDS, servers) to identify, contain, and remediate suspicious activity. Characterize and analyze network traffic to identify anomalies and potential threats. Perform forensic analysis of host artifacts, network traffic, and email content. Analyze malicious scripts and code to mitigate threats. Conduct malware analysis and develop IOCs to support threat identification and mitigation.

Microsoft Sentinel & Defender Engineering and Operations Design, implement, configure, and maintain Microsoft Sentinel SIEM, including workspace architecture, data connectors, and log ingestion pipelines. Develop and tune analytics rules, scheduled queries, NRT rules, and fusion rules to optimize detection fidelity. Create and maintain Sentinel workbooks, hunting queries, and automation playbooks (Logic Apps). Implement and manage Microsoft Defender for Endpoint (MDE), including ASR rules, AIR, policy configuration, and KQL-based advanced hunting. Configure and operationalize Microsoft Defender for Identity, including sensor deployment, threatdetection tuning, and lateral movement path analysis. Manage Microsoft Defender for Office 365, including Safe Attachments, Safe Links, anti-phishing policies, and investigation capabilities. Implement and maintain Microsoft Defender for Cloud for CSPM, workload protection, and cloud-native threat detection across multi-cloud environments. Develop custom KQL queries for hunting, detection engineering, and security analytics across M365 Defender and Sentinel. Integrate Sentinel with SOAR, developing automated response playbooks and orchestration workflows. Monitor data connector health, troubleshoot ingestion issues, and optimize log collection. Implement and manage Microsoft Entra ID security capabilities including Conditional Access, Identity Protection, PIM, and access reviews.

Threat Hunting & Intelligence Conduct proactive hunts for APTs using Sentinel and MDE hunting capabilities. Integrate and operationalize threat intelligence within Sentinel to enhance detection. Analyze threat intelligence reporting and apply adversary methodology knowledge to improve detection posture. Map detections and hunting hypotheses to MITRE ATT&CK and D3FEND frameworks.

Collaboration & Reporting Collaborate with customer teams to investigate and respond to events and incidents. Monitor and respond via SOAR, hotline, and designated email inboxes. Create tickets and initiate workflows in accordance with SOPs. Coordinate and report incident information to CISA as required. Engage with local, national, and international CIRTs as directed. Submit alert tuning requests and lead ongoing detection engineering efforts. Mentor and provide technical guidance to Tier 1 and Tier 2 analysts on Microsoft security tools and incident response processes.

Qualifications

Minimum Requirements

Education & Experience Bachelor's degree and a minimum of 5 years of cybersecurity experience, OR a high school diploma and 9 years of cybersecurity experience. Minimum 3 years of hands-on experience implementing and operating Microsoft Sentinel (workspace deployment, analytics rule development, workbook creation, playbook automation). Minimum 3 years of experience implementing and managing Microsoft Defender solutions (Defender for Endpoint, Defender for Identity, Defender for Office 365, and/or Defender for Cloud).

CertificationsMust possess (or be able to obtain prior to start date) at least one of the following; continued certification is required as a condition of employment: CCNA-Security; CND; CySA+; GICSP; GSEC; Security+ CE; SSCP

Technical Skills:  Extensive proficiency in Kusto Query Language (KQL) for advanced detections, hunting queries, and Sentinel/M365 Defender analytical workbooks. Experience designing and implementing Microsoft Sentinel analytics rules (scheduled, NRT, fusion). Proven experience deploying and managing Microsoft Defender for Endpoint (policy configuration, ASR rules, AIR, live response). Experience with Microsoft Defender for Identity (sensor deployment, detection tuning, identity-based investigations). Demonstrated experience across the full Incident Response lifecycle (Preparation through Lessons Learned). Knowledge of SOAR platforms and automated response systems (ServiceNow, Splunk SOAR, Sentinel Playbooks/Logic Apps). Experience with SIEM platforms (Sentinel, Splunk, Elastic, QRadar). Experience with EDR solutions (MDE, ElasticXDR, CarbonBlack, CrowdStrike). Knowledge of cloud security monitoring and incident response, especially in Azure. Ability to integrate IOCs and track APT actor activity. Ability to analyze threat intelligence and understand adversary techniques. Knowledge of static and dynamic malware analysis techniques. Knowledge of MITRE ATT&CK and D3FEND frameworks and ability to map detections.

Clearance & Citizenship U.S. Citizenship required. Ability to obtain a Top Secret security clearance.

Preferred Qualifications: 

Microsoft SC200 (Security Operations Analyst) - highly preferred Microsoft SC100 (Cybersecurity Architect) Microsoft AZ500 (Azure Security Engineer) Microsoft SC300 (Identity and Access Administrator) Experience architecting multitenant or multiworkspace Sentinel environments Experience with Sentinel content hub solutions and custom content development Proficiency with Microsoft Defender for Cloud workload protection across Azure, AWS, and GCP Experience developing Logic Apps and Power Automate flows for security automation Proficiency with Splunk for monitoring, alerting, and threat hunting Knowledge of Microsoft Azure/Entra ID access and identity management (Conditional Access, PIM, Identity Protection) Experience with digital forensics tools (Autopsy, Magnet Forensics, KAPE, CyLR, Volatility, Zimmerman tools) Experience with ServiceNow SOAR for automated ticketing and response Proficiency in Python, PowerShell, and Bash for automation and tool development Ability to perform static/dynamic malware analysis and reverse engineering Experience integrating cyber threat intelligence and IOC-based hunting into Sentinel TI module Experience leading purple team exercises and translating findings into actionable detections Additional preferred certifications:

  • Microsoft: SC200, SC100, AZ500, SC300, SC900
  • Industry: SecurityX/CASP+, CySA+, Cloud+, GCIH, GCIA, GCFA, GNFA, GREM, GEIR, CCSP, CCSK, CHFI, GCLD, PRMP
  • Practical: TryHackMe SAL1, HackTheBox CDSA, CyberDefenders CCD
Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.

Target Salary Range$80,000 - $128,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.EEOEEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.Employment Type: FULL_TIME

What Peraton employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Peraton logo

About Peraton

Sourced by ZipRecruiter

At Peraton, we re at the forefront of delivering the next big thing every day. We re the partner of choice to help solve some of the world s most daunting challenges, delivering bold, new solutions to keep people around the world safer and more secure.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Herndon, VA, US

Year founded

2017