Jobiglo

No results.

Principal Microsoft Defender XDR, IRM & Deception Engineer

WTW · London

🇬🇧 English
Microsoft Defender XDR Defender for Endpoint Defender for Identity Defender for Office 365 Defender for Cloud Apps Microsoft Sentinel Microsoft Security Copilot Microsoft Purview Data Loss Prevention Microsoft Insider Risk Management Deception engineering

Job description

About the role

The Principal Microsoft Defender XDR, IRM & Deception Engineer will lead the enterprise cyber deception programme and unified detection and response across the Microsoft security ecosystem. Working within the Global Information and Cyber Security Defence function, you will design, deploy and operate high‑fidelity deception traps and integrate them with Microsoft Defender XDR, Sentinel and Security Copilot to detect adversaries early.

Key responsibilities

  • Own end‑to‑end strategy, architecture and operation of the cyber deception fabric, including honeypots, honeytokens, decoy accounts, devices and breadcrumbs.
  • Act as the technical authority for deception engineering and Microsoft Defender XDR across the enterprise.
  • Design, implement and optimise Microsoft Defender XDR across endpoint, identity, email and cloud‑app workloads.
  • Integrate deception signals into Microsoft Sentinel as high‑fidelity detections.
  • Lead the design and rollout of Microsoft Purview DLP policies and Insider Risk Management controls.
  • Correlate DLP, IRM and identity signals with Defender XDR to provide unified incident context.

Required profile

  • Proven experience leading large‑scale cyber deception programmes in complex, hybrid or multi‑cloud environments.
  • Deep expertise with Microsoft security solutions, especially Defender XDR suite and Sentinel.
  • Strong understanding of data loss prevention, insider risk management and security automation.
  • Ability to translate deception engineering concepts into operational security controls.

Required skills

  • Microsoft Defender XDR (Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps)
  • Microsoft Sentinel
  • Microsoft Security Copilot
  • Microsoft Purview Data Loss Prevention (DLP)
  • Microsoft Insider Risk Management (IRM)
  • Deception engineering (honeypots, honeytokens, decoy assets)

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec WTW.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in the United Kingdom.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 1 month ago

Expires 3 hours from now

26 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

WTW

London