Jobless Developer
Unison Group logo

Posted 22 days ago

Open

L1 Support SME - Microsoft Defender for Endpoint, MDCA & Purview

Kuala LumpurOn-siteFull-time

AI Summary

Provides L1 operational support for Microsoft Defender for Endpoint, Microsoft Defender for Cloud Apps, and Microsoft Purview, handling incident triage, alert investigation, ticket management, and escalation to L2/L3 teams.

About this role

  • Provide L1 operational support for Microsoft Defender for Endpoint, Microsoft Defender for Cloud Apps, and Microsoft Purview incidents, alerts, requests, and customer tickets.
  • Perform initial ticket intake, categorisation, prioritisation, user-impact assessment, and investigation based on available evidence and approved support guidance.
  • Investigate MDE alerts, incidents, device timelines, antivirus detections, device health, onboarding status, sensor health, and endpoint policy status.
  • Investigate MDCA alerts, user activities, connected applications, cloud-discovery information, activity policies, anomaly detections, and connector health.
  • Review Purview alerts and events related to Information Protection, sensitivity labels, Data Loss Prevention, Endpoint DLP, Insider Risk Management, and Data Lifecycle Management.
  • Collect screenshots, diagnostic packages, logs, alert details, policy status, connector status, audit records, and validation outputs required for issue investigation.
  • Perform basic runbook-based troubleshooting and escalate unresolved or complex issues to L2, L3, platform SMEs, Microsoft Support, or relevant client teams.
  • Maintain clear ticket notes, investigation findings, supporting evidence, customer updates, escalation details, and closure information within agreed service levels.

Requirements

  • Experience in L1 support, security operations, endpoint support, service desk coordination, or Microsoft 365 operational support.
  • Working knowledge of Microsoft Defender for Endpoint, Microsoft Defender for Cloud Apps, Microsoft Purview, and their respective management portals.
  • Ability to perform initial investigation of MDE incidents, alerts, device timelines, endpoint health, onboarding status, and policy deployment.
  • Ability to review MDCA alerts, activities, connected applications, policies, cloud-discovery information, and connector status.
  • Familiarity with Purview Information Protection, sensitivity labels, DLP, Endpoint DLP, Insider Risk Management, and Data Lifecycle Management.
  • Understanding of customer-ticket handling, alert triage, log collection, evidence documentation, escalation management, and issue lifecycle tracking.
  • Ability to follow approved runbooks, knowledge articles, support guides, and escalation procedures without making unauthorised production changes.

Skills

Connector Health MonitoringData Lifecycle ManagementData Loss PreventionDevice Timeline AnalysisEndpoint DLPInsider Risk ManagementLog CollectionMDCA Alert InvestigationMDE Alert InvestigationMicrosoft 365 Operational SupportMicrosoft Defender For Cloud AppsMicrosoft Defender For EndpointMicrosoft PurviewPurview Information ProtectionRunbook-based TroubleshootingSensitivity LabelsService Desk CoordinationTicket Triage

Explore related jobs

Browse these categories

Market data for this role

All reports →