WDAC Implementation Specialist / Endpoint Security Engineer
Core
Design, implement, and enforce Windows Defender Application Control (WDAC) policies to prevent unauthorized code execution and ensure application trust across enterprise endpoints.
Role type
Senior IC Endpoint Security Engineer (Application Control)
Builds
WDAC policies, application control rules, and secure deployment pipelines via Intune/ConfigMgr
Domain
Enterprise IT Security / Endpoint Protection
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
WDAC policy development, XML to binary conversion, Microsoft Intune, Endpoint Configuration Manager (ConfigMgr), PowerShell scripting, Code Integrity policies, audit vs enforcement modes, policy signing, Microsoft Defender Antivirus integration, log analysis (Advanced Hunting), application blockage troubleshooting
Preferred skills
Ivanti application control, Zero Trust security models, compliance frameworks (ASD Essential Eight), large-scale deployment management
Technologies
WDAC, XML, Microsoft Intune, ConfigMgr, PowerShell, Microsoft Defender Antivirus, Advanced Hunting
Responsibilities
Design and implement WDAC policies using XML and convert them to binary for enforcement; Deploy WDAC policies via Microsoft Intune, Endpoint Configuration Manager, or PowerShell; Integrate WDAC with Microsoft Defender Antivirus and other endpoint security tools; Analyze WDAC logs using Microsoft Security tools to refine policies; Resolve application blockage issues and maintain policy updates; Provide training and support for IT teams and end-users on WDAC policies
Seniority
Senior, hands-on IC
