> Markdown version of [/jobs/ext/2126465-security-engineer](https://www.wearedevelopers.com/jobs/ext/2126465-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Chickasaw Nation Industries, Inc. - **Location:** Annapolis, MD, United States - **Experience:** Expert - **Salary:** $100,000.0 - $120,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Microsoft Azure, BitLocker Drive Encryption, System Configuration, Local Security Policy, Microsoft Security Essentials, System Center Configuration Manager, Virtual Desktops, Windows PowerShell, Role-Based Access Control, Zero Trust Network Access, Software Vulnerability Management, Firewalls (Computer Science), Microsoft InTune, Azure Security Center, Deployment Automation, Casper Suite, CIS Benchmarks, Firewall Services Module, Unified Endpoint Management - **Published:** August 19, 2026 - **Apply:** https://www.jofdav.com/jobs/59311061-security-engineer ## About the Role The ideal candidate possesses experience with Microsoft security technologies, endpoint hardening, compliance policies, CIS and Microsoft Security Baselines, and enterprise endpoint management platforms within highly regulated federal environments., The ability to obtain, maintain and access classified information at the Public Trust level. Strong understanding of cybersecurity frameworks, access control, endpoint security, and incident response. * Experience administering Microsoft Intune and Microsoft Endpoint Manager. * Experience with MECM/SCCM administration. * Experience implementing Microsoft Security Baselines and CIS Benchmarks. * Knowledge of Microsoft Defender for Endpoint. * Experience configuring BitLocker, Windows Firewall, ASR rules, Device Control, and endpoint protection policies. * Familiarity with Entra ID, Conditional Access, RBAC, and device compliance. * Understanding of NIST 800-53, Zero Trust Architecture, and federal cybersecurity requirements. * Strong PowerShell scripting experience. * Excellent troubleshooting and documentation skills. Preferred Qualifications * Experience with Jamf Pro administration. * Experience supporting Azure Virtual Desktop environments. * Microsoft Intune Administrator Associate (MD-102). * Microsoft Security Administrator (SC-300 or equivalent). * CISSP, Security+, or similar security certification. * Experience supporting HHS, NIH, or other federal agencies., * Bachelors degree and 4+ years supporting enterprise endpoint management environments., Work is primarily performed in an office environment. Regularly required to sit. Regularly required use hands to finger, handle, or feel, reach with hands and arms to handle objects andoperatetools, computer, and/or controls. Required to speak and hear. Occasionally required to stand,walkand stoop, kneel, crouch, or crawl. Mustfrequentlylift and/or move up to 10 pounds and occasionally lift and/or move up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision, depth perception, and ability to adjust focus. Exposed to general office noise with computers printers and light traffic. ## Description CNI seeking an Endpoint Security Baseline Engineer to support the engineering, implementation, and operational management of enterprise endpoint security configurations across Microsoft Intune, Microsoft Endpoint Configuration Manager (MECM), and Jamf Pro environments. This role is responsible for designing, implementing, validating, and maintaining standardized security baselines that improve the organization's cybersecurity posture while ensuring operational stability across Windows and macOS endpoints., * Engineer and maintain Microsoft Intune Security Baselines, Endpoint Security policies, and Configuration Profiles. * Develop and maintain Group Policy, MECM Configuration Baselines, and Jamf security configurations. * Implement Microsoft Defender for Endpoint security settings, attack surface reduction (ASR) rules, firewall policies, BitLocker, FileVault, Credential Guard, Application Control, and device encryption policies. * Configure compliance policies and Conditional Access dependencies supporting Zero Trust initiatives. * Validate security baseline deployments through testing, pilot implementations, and production rollout. * Perform impact assessments for Microsoft monthly security baseline updates and recommend adoption strategies. * Collaborate with cybersecurity, RMF, ISSO, and engineering teams to ensure endpoint configurations meet organizational security requirements. * Develop configuration documentation, implementation guides, rollback procedures, and standard operating procedures. * Support vulnerability remediation initiatives through endpoint configuration changes. * Troubleshoot policy conflicts between Intune, MECM, Active Directory Group Policy, and Jamf. * Participate in change management, CAB reviews, and production implementation activities. * Support enterprise modernization initiatives including Autopilot, cloud-native management, and migration from traditional management solutions. ## Related Videos - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)