IT & Software

Principal Microsoft Defender XDR, IRM & Deception Engineer

Willis Towers Watson

London · Greater London · United Kingdom

Overview

You will lead an enterprise deception and unified detection program within the ICSD function, shaping a Defender XDR-enabled security fabric across endpoints, identity, email and cloud workloads. You will design, operate, and continuously improve deception assets and IRM integration to detect adversaries earlier and automate investigations. The role combines deception engineering with Defender XDR mastery and Agentic AI to drive proactive, intelligence-led security operations. You will mentor a team and partner with cross-functional groups to align strategy with business risk and regulatory requirements.

Pay / Benefits
  • 25 days annual leave + 1-day WTW
  • private healthcare
  • life insurance
  • group income protection
  • pension with 10% company matching
  • hybrid working
Responsibilities
  • Own end-to-end enterprise cyber deception programme: strategy, architecture, deployment, operations, and continuous improvement
  • Design and operate a layered deception fabric across on-premises, hybrid, and multi-cloud environments
  • Act as the technical authority for deception engineering and Microsoft Defender XDR
  • Operate deception assets: honeypots, honeytokens, decoy accounts/devices, breadcrumbs
  • Integrate deception signals with Defender XDR and Microsoft Sentinel as high-fidelity detections
  • Lead Defender XDR design and optimization across endpoints, identity, email, and cloud apps
  • Lead Identity deception and Defender for Identity optimization to detect credential-based attacks
  • Design and implement Microsoft Purview DLP policies and leverage IRM for insider risk detection
  • Lead detection engineering across Defender XDR stack and optimize AIR and automation
  • Grow and lead a team of Defender XDR and Deception Engineers; align with SOC, CTI, Identity, Cloud, and Engineering teams
Key requirements
  • Proven experience designing and operating enterprise cyber deception programmes at scale
  • Extensive hands-on experience operating and engineering Microsoft Defender XDR (MDE, MDI, MDO, MDA) in large enterprises
  • Deep expertise across Microsoft security stack: MDI deception assets, Defender for Identity, Sentinel, Security Copilot, Defender for Cloud Apps
  • Hands-on experience with deception platforms (Thinkst Canary, T-Pot, Cowrie, OpenCanary, Zscaler Deception)
  • Advanced KQL for detection engineering and threat hunting at scale
  • Detection-as-code and CI/CD of detection content
  • Strong knowledge of MITRE ATT&CK, MITRE Engage, MITRE D3FEND, and cyber kill chain
  • Experience using Agentic AI or Security Copilot in security operations, automation
  • Incident response leadership across identity, endpoint, email, and cloud
  • Scripting/automation (PowerShell, Python, or equivalent)
  • Understanding of Zero Trust and identity-centric defence
  • leadership and mentorship
  • stakeholder communication
  • cross-functional collaboration
  • Defender XDR (MDE, MDI, MDO, Defender for Cloud Apps)
  • Microsoft Sentinel (analytics rules, hunting, SOAR)
  • Microsoft Security Copilot

Reference: WJ-747_30871169

Apply now

Continue on the employer's official application - the same link they use for every candidate.

More jobs

Find more on GigBlows

This role is listed on GigBlows for discovery and search. Hiring decisions and applications are handled by the employer or their chosen application system.