Endpoint & Microsoft 365 Security Engineer (Ghent)

D-ploy
Gent, Belgium
14 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Access Microsoft Excel Microsoft Windows Audit Trail Cyber Security System Configuration Information Leak Prevention Data Security Domainkeys Identified Mail Domain-Based Message Authentication Reporting and Conformance (DMARC) Multi-Factor Authentication Information Technology Operations
+13 more
Power BI Azure Active Directory Phishing Kusto Query Language Software Vulnerability Management Microsoft InTune Azure Security Center Sender Policy Framework (SPF) Spoofing Microsoft Sentinel Qualys Servicenow Vulnerability Analysis

Job description

We are looking for an experienced Security Engineer specialising in endpoint, Microsoft 365 and email security. This is a hands-on role focused on protecting user devices, collaboration platforms and communication technologies by ensuring that security controls are correctly configured, effectively monitored and continuously improved. The role combines technical engineering with operational security ownership. You will review security configurations, identify weaknesses and risky exceptions, coordinate remediation activities and provide clear visibility into the organisation’s endpoint, Microsoft 365 and email security posture. This is a remote-first position, with occasional travel to company offices when required. You will collaborate with Workplace Technology, IT Operations, Security Operations, business stakeholders, external vendors and specialist service providers. Your responsibilities will include:

  • Protecting corporate laptops, desktops, supported mobile devices and other managed endpoints throughout their lifecycle, ensuring they remain securely configured, monitored and compliant.
  • Maintaining and improving endpoint security baselines, including endpoint protection, EDR/XDR health, vulnerability scanning, device telemetry, patching and update compliance.
  • Investigating and coordinating the remediation of devices that are degraded, non-compliant or no longer reporting correctly.
  • Managing or supporting organisational controls for permitted and prohibited applications.
  • Operating and enhancing Microsoft 365 and Entra ID security controls, particularly Conditional Access, device compliance, privileged access and local administrator protection.
  • Supporting Microsoft Purview security and compliance capabilities, including information protection, Data Loss Prevention, audit, eDiscovery and retention-related controls.
  • Working with privacy and compliance stakeholders to ensure that relevant Purview controls are appropriately implemented and maintained.
  • Managing or providing strong operational support for Microsoft 365 and Mimecast email security controls.
  • Reviewing and improving anti-spoofing, spam, phishing, attachment handling, impersonation and Business Email Compromise protections.
  • Maintaining email authentication and reporting controls, including DMARC, DKIM, SPF and user phishing-reporting processes.
  • Identifying and resolving email security assessment findings, configuration gaps and inappropriate exceptions in collaboration with internal teams and external specialists.
  • Establishing practical operating procedures, dashboards, control evidence, KPIs and continuous improvement actions for endpoint, Microsoft 365 and email security.
  • Using security incidents, phishing trends, audit observations, assessment results and user experience issues to develop sustainable improvements to security controls.
  • Documenting remediation activities, assigning clear ownership and ensuring that actions are supported by appropriate evidence.

Requirements

  • At least five years of relevant security engineering or operational security experience within enterprise environments.
  • Practical experience configuring, governing, reviewing or assessing endpoint and Microsoft 365 security controls.
  • Strong hands-on knowledge of endpoint security, endpoint hardening, EDR/XDR, endpoint telemetry and patch or update compliance.
  • Experience working with Microsoft Defender for Endpoint and Microsoft Intune, including device compliance and the monitoring of endpoint security health.
  • Strong knowledge of Microsoft 365 and Microsoft Entra ID security, particularly Conditional Access, Multi-Factor Authentication, device posture, privileged access, audit logging and secure access governance.
  • Good understanding of Microsoft 365 email security and secure email gateway controls.
  • Experience with anti-spoofing, phishing and spam protection, attachment policies, impersonation and Business Email Compromise controls.
  • Knowledge of DMARC, DKIM, SPF, phishing-reporting processes, exception handling and safe links or safe attachments concepts.
  • Familiarity with Microsoft Purview capabilities, including information protection, Data Loss Prevention, audit, eDiscovery and retention concepts.
  • Experience using administrative and investigation tools such as Microsoft Defender portal, Microsoft Intune, Microsoft Entra admin centre and Exchange admin centre.
  • Familiarity with Mimecast administration or comparable secure email gateway technology. Direct Mimecast experience is strongly preferred.
  • Experience with Microsoft Sentinel, KQL or similar security monitoring and investigation tools.
  • Familiarity with vulnerability scanning or vulnerability management platforms such as Qualys.
  • Experience working with ServiceNow or similar platforms for incident management, exception handling and remediation tracking.
  • Ability to produce and maintain meaningful security reports and dashboards using tools such as Excel or Power BI.
  • Strong ability to review technical configurations, identify weak controls, bypasses or risky exceptions and convert findings into structured remediation plans.
  • Experience with operational governance, evidence collection, security exception management, incident or alert handover and remediation follow-up.
  • Strong communication and collaboration skills, with the ability to work effectively with technical teams, vendors and business stakeholders.
  • Ability to balance security requirements with operational constraints and user experience considerations.
  • Relevant security or Microsoft certifications are desirable but not mandatory.
  • Valid criminal record extract, not older than three months, required.

About the company

D-ploy is an IT and Engineering Solutions company delivering services to organisations across the EMEA region and the United States. We work closely with our clients to provide reliable, secure and practical technology solutions, supported by collaborative teams and a people-focused working environment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.be

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

44 sec

Blocking container spoofing attacks by removing raw network access

Mathias Tausig · WWC 2023

1:26 min

Spear phishing IT administrators with malicious VoIP spoofing

Mauro Verderosa · LIVE

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · WWC Europe 2026

Videos

See all

Related articles

See all