Principal Microsoft Defender XDR, IRM & Deception Engineer
Listed on 2026-07-22
-
Security
Cybersecurity
The Principal Microsoft Defender XDR, IRM & Deception Engineer, working within the Global Information and Cyber Security Defence (ICSD) function, is the technical leader for enterprise cyber deception and unified detection and response across the Microsoft security ecosystem. The role focuses on building, operating, and continuously evolving an enterprise-grade Insider Risk Management (IRM) and deception programme - including honeypots, honey tokens, decoy users, decoy devices, deceptive credentials, and breadcrumbs - fully integrated with Microsoft Defender XDR (Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps), Microsoft Sentinel, and Microsoft Security Copilot.
The role exists to detect adversaries earlier in the kill chain by deceiving attackers into engaging with high-fidelity traps, while delivering unified detection, automated investigation, and response across endpoint, identity, email, and cloud workloads. It combines deep deception engineering expertise with hands-on Defender XDR mastery and the use of Agentic AI to drive proactive, intelligence-led, and largely autonomous security operations.
The Role:
- Deception Engineering Leadership
- Own and lead the enterprise cyber deception programme end-to-end, including strategy, architecture, deployment, operations, and continuous improvement.
- Design, deploy, and operate a layered deceptio...
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: