Defender Administrator- Active SC Required
Job Title: Defender Administrator- Active SC Required
Location: Remote,UK
Duration: 3Months+
Rate: 450GBP/Day Inside IR35
Role Overview
We are looking for an experienced Microsoft Defender Administrator to join a major security transformation programme for a leading UK Energy client. The successful candidate will lead the migration from legacy antivirus solutions (McAfee/Symantec) to Microsoft Defender for Endpoint (MDE) across Windows and Linux server environments.This role requires strong Microsoft Defender expertise, hands-on migration experience, and the ability to work within a complex, highly secure enterprise infrastructure.
Key Responsibilities
- Lead migration from McAfee/Symantec to Microsoft Defender for Endpoint (MDE).
- Onboard Windows and Linux servers into Microsoft Defender.
- Validate and implement antivirus exclusion policies.
- Configure and deploy Microsoft Defender security policies.
- Create Azure AD device groups for policy deployment.
- Develop migration plans for complex enterprise environments.
- Perform network connectivity testing during migration.
- Build and distribute Defender installation packages.
- Work closely with infrastructure and image management teams.
- Remove legacy antivirus solutions from servers.
- Deploy Defender using GPO, SCCM, or Microsoft Intune.
- Configure endpoint security policies, exclusions, dashboards, and reporting.
- Troubleshoot security incidents and support Defender operations.
- Produce technical documentation, deployment guides, and operational procedures.
- Strong hands-on experience with Microsoft Defender for Endpoint (MDE).
- Experience migrating enterprise environments from McAfee or Symantec to Microsoft Defender.
- Experience managing antivirus policies and exclusions.
- Knowledge of:
- Microsoft Defender for Endpoint
- Microsoft Defender for Servers
- Microsoft Defender for Office 365
- Microsoft Defender for Identity
- Microsoft Cloud App Security
- Good understanding of:
- Endpoint Detection & Response (EDR)
- Threat & Vulnerability Management (TVM)
- Attack Surface Reduction (ASR)
- Automated Investigation & Remediation (AIR)
- Experience with Windows Server and Linux (RHEL).
- Experience deploying Defender through GPO, SCCM, or Intune.
- Strong understanding of threat hunting, endpoint security, and security best practices.
- Excellent troubleshooting and documentation skills.
- Active SC Clearance (must be transferable).
- Minimum 3 months validity remaining on SC Clearance.
- Experience working within secure or highly regulated environments.
- Ability to start quickly.