Job Description
· We are seeking an experienced L1 Support SME – Microsoft Defender XDR Support to provide hypercare and operational support for Microsoft security platforms within a large enterprise environment.
· The successful candidate will be responsible for issue intake, ticket triage, evidence collection, troubleshooting, escalation coordination, and stakeholder communication across Microsoft Defender for Endpoint (MDE), Microsoft Defender for Cloud Apps (MDCA), and Microsoft Purview.
Key Responsibilities
· Provide Level 1 hypercare support for Microsoft Defender for Endpoint, Microsoft Defender for Cloud Apps, and Microsoft Purview.
· Perform issue intake, ticket review, categorization, prioritization, and impact assessment.
· Collect and analyze logs, screenshots, policy status, connector health information, validation outputs, and supporting evidence required for issue investigation.
· Support initial troubleshooting for Defender, Intune policy deployments, MDCA connectors, and Purview policy-related issues.
· Monitor and manage support tickets, ensuring timely updates, tracking, and closure of incidents.
· Coordinate escalations to L2/L3 support teams, SMEs, or client stakeholders when advanced investigation is required.
· Maintain accurate ticket documentation, issue summaries, remediation actions, and status reports.
· Follow established runbooks, support procedures, governance standards, and operational guidelines.
· Collaborate with Security Operations, Endpoint Management, Identity, Compliance, and Infrastructure teams to resolve issues effectively.
· Participate in hypercare activities and ensure adherence to agreed service levels and support processes.
Required Qualifications
· Bachelor's Degree in Information Technology, Cybersecurity, Computer Science, or a related discipline.
· Experience in L1 Support, Microsoft Security Operations, Endpoint Support, Service Desk Operations, or Microsoft 365 Support environments.
· Strong understanding of incident management, ticket lifecycle management, and escalation procedures.
· Excellent communication, documentation, and stakeholder management skills.
· Technical Skills Microsoft Defender for Endpoint (MDE) Microsoft Defender for Cloud Apps (MDCA) Microsoft Purview Microsoft Intune Endpoint Security Support Incident & Ticket Management ITSM Processes and Service Operations Security
· Monitoring and Troubleshooting Evidence Collection and Root Cause Analysis
Preferred Certifications
· Candidates holding any of the following certifications will have an advantage:
· SC-200: Microsoft Security Operations Analyst
· MD-102: Endpoint Administrator
· SC-900: Security, Compliance, and Identity Fundamentals
· AZ-500: Azure Security Engineer Associate
· SC-300: Identity and Access Administrator
· SC-401: Information Security Administrator
Preferred Experience
· Experience supporting enterprise Microsoft security environments.
· Exposure to Microsoft Defender XDR platforms and post-go-live hypercare support.
· Experience working within regulated or highly governed enterprise environments.
· Familiarity with ITSM tools, support queues, incident tracking systems, and structured escalation frameworks.
· Experience collaborating with SOC, Compliance, Identity, Endpoint, and Infrastructure teams.
ELLIOTT MOSS CONSULTING PTE. LTD.
ELLIOTT MOSS CONSULTING PTE. LTD. We at Elliott Moss Consultng inspire individuals and organisations to work more effectively and efficiently, and create greater choice in the work domain, for the benefit of all concerned. Our primary mission is to provide our clients with the best suitable emplo...
Read more about the companyCopyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.