Experience: 4 to 8 years
Location : CHN/BLR/HYD
Technical Skills: Hands-on experience with Microsoft defender suite, especially Email security/Valimail
Role Overview:
We are looking for a cybersecurity professional with strong hands on experience across the Microsoft Defender security suite, with a primary focus on Microsoft Defender for Office 365. The role requires in depth expertise in email threat protection, phishing and Business Email Compromise (BEC) investigations, policy governance, and advanced threat remediation.
The candidate will be responsible for operating, managing, and continuously improving the organization’s email security posture, while leveraging the broader Microsoft Defender XDR ecosystem to support cross domain visibility and response. This role supports enterprise scale environments and focuses on reducing false positives, improving detection quality, and ensuring consistent, audit ready security operations
Responsibilities:
Operate, manage, and continuously improve Exchange Online Protection (EOP) and Microsoft Defender for Office 365.
Maintain and govern the baseline configuration for EOP and MDO, including periodic reviews and drift remediation.
Administer and tune email security policies: Anti-Phishing, Anti-Spam, Anti-Malware, Safe Links, Safe Attachments, Quarantine, and Advanced Delivery.
Document and maintain baseline configurations (Excel or equivalent) in an audit-ready manner.
Manage Tenant Allow / Block Lists (IPs, domains, senders/recipients, URLs, file hashes) through approved change processes.
Manage Priority Accounts and Impersonation Protection scopes, including periodic reviews and joiner/leaver updates.
Investigate and remediate email-based threats, including phishing, BEC, malware, and targeted attacks, using MDO capabilities.
Operate and provide expertise across the Microsoft Defender platform: Defender for Office 365, Endpoint, Identity, and Cloud Apps.
Correlate email threats with endpoint, identity, and cloud signals using Defender (non-SOC operational model).
Tune configurations and Automated Investigation & Response (AIR) to reduce false positives and improve detection quality.
Provide expert advisory on best-practice gaps, security posture improvements, and Defender/MDO feature adoption.
Operate within defined processes, SLAs, and ServiceNow workflows, ensuring controlled, documented, and compliant service delivery.
Preferred Skills:
Experience with Valimail for DMARC, DKIM, and SPF management and monitoring.
Strong understanding of email authentication reporting and enforcement models.
Experience integrating third-party email authentication tooling with Microsoft 365.
Certifications (Good to Have)
SC-200 – Microsoft Security Operations Analyst
AZ-500 – Azure Security Engineer
MS 500 – Microsoft 365 Security Administrator Associate
Responsibilities
Experience: 4 to 8 years
Location : CHN/BLR/HYD
Technical Skills: Hands-on experience with Microsoft defender suite, especially Email security/Valimail
Role Overview:
We are looking for a cybersecurity professional with strong hands on experience across the Microsoft Defender security suite, with a primary focus on Microsoft Defender for Office 365. The role requires in depth expertise in email threat protection, phishing and Business Email Compromise (BEC) investigations, policy governance, and advanced threat remediation.
The candidate will be responsible for operating, managing, and continuously improving the organization’s email security posture, while leveraging the broader Microsoft Defender XDR ecosystem to support cross domain visibility and response. This role supports enterprise scale environments and focuses on reducing false positives, improving detection quality, and ensuring consistent, audit ready security operations
Responsibilities:
Operate, manage, and continuously improve Exchange Online Protection (EOP) and Microsoft Defender for Office 365.
Maintain and govern the baseline configuration for EOP and MDO, including periodic reviews and drift remediation.
Administer and tune email security policies: Anti-Phishing, Anti-Spam, Anti-Malware, Safe Links, Safe Attachments, Quarantine, and Advanced Delivery.
Document and maintain baseline configurations (Excel or equivalent) in an audit-ready manner.
Manage Tenant Allow / Block Lists (IPs, domains, senders/recipients, URLs, file hashes) through approved change processes.
Manage Priority Accounts and Impersonation Protection scopes, including periodic reviews and joiner/leaver updates.
Investigate and remediate email-based threats, including phishing, BEC, malware, and targeted attacks, using MDO capabilities.
Operate and provide expertise across the Microsoft Defender platform: Defender for Office 365, Endpoint, Identity, and Cloud Apps.
Correlate email threats with endpoint, identity, and cloud signals using Defender (non-SOC operational model).
Tune configurations and Automated Investigation & Response (AIR) to reduce false positives and improve detection quality.
Provide expert advisory on best-practice gaps, security posture improvements, and Defender/MDO feature adoption.
Operate within defined processes, SLAs, and ServiceNow workflows, ensuring controlled, documented, and compliant service delivery.
Preferred Skills:
Experience with Valimail for DMARC, DKIM, and SPF management and monitoring.
Strong understanding of email authentication reporting and enforcement models.
Experience integrating third-party email authentication tooling with Microsoft 365.
Certifications (Good to Have)
SC-200 – Microsoft Security Operations Analyst
AZ-500 – Azure Security Engineer
MS 500 – Microsoft 365 Security Administrator Associate
Salary : As per industry standard.
Industry :IT-Software / Software Services
Functional Area : IT Software - Application Programming , Maintenance