Systems Engineer - Microsoft 365 Security & Compliance / Endpoin
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+23 more
Job description
Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role requires a seasoned professional who can strategically manage and enhance the security and compliance posture of the M365 environment within a GCC (Government Community Cloud) tenant, particularly in a federal agency context. This senior engineering role sits at the center of the organization’s device, identity, and M365 security ecosystem. The engineer is responsible for protecting enterprise Windows, macOS, iOS/iPadOS endpoints; ensuring compliant, reliable access to M365 services, and driving rapid engineering responses to vulnerabilities, outages, and operational risks. The successful candidate will apply with deep technical expertise, cross-platform engineering capability, and high operational security judgment., Strategic security oversight & governance
- Lead the development, implementation, and ongoing management of M365 security policies, standards, and technical guardrails aligned to federal requirements and organizational controls.
- Own governance for data protection capabilities including document classification, labeling, retention, and Data Loss Prevention (DLP) using Microsoft Purview.
Email security & compliance management (Exchange Online)
- Define and enforce email security policies such as encryption, sensitivity labeling, and secure mail flow to reduce unauthorized disclosure.
- Implement and maintain email encryption solutions (S/MIME and/or Microsoft Information Protection) to protect confidentiality of email communications.
- Administer and monitor anti-spam, anti-phishing, and anti-malware protections to defend against evolving threats.
Identity, access, and conditional access (Entra ID)
- Engineer and validate device-compliance-based Conditional Access policies across Windows, macOS, and mobile platforms.
- Investigate and remediate Conditional Access failures, identity anomalies, and external/guest access issues, including M365 B2B trust and secure partner collaboration requirements.
Endpoint & device security engineering (Intune)
- Design, test, and deploy Intune configuration and compliance policies for Windows, macOS, and iOS/iPadOS, including Enrollment Status Pages (ESPs) and OOBE workflows.
- Develop remediation scripts (PowerShell/platform scripts/configuration profiles) to close compliance gaps and enforce security baselines.
- Coordinate enterprise rollout of urgent vulnerability mitigations and validated vendor fixes; support vulnerability reviews and baseline rebuilds.
Risk management & compliance assurance (ATO / controls)
- Establish and operate a risk management approach to identify, assess, and mitigate security risks across the M365 ecosystem.
- Support ATO/control assessment activities by drafting implementation statements, collecting artifacts, and providing evidence aligned to audit/logging requirements.
Security monitoring, SIEM, and telemetry engineering (Defender / Sentinel)
- Lead integration and operational management of Microsoft Defender and Microsoft Sentinel for threat detection, alerting, and response across M365.
- Build and maintain SIEM integrations/connectors (e.g., M365, collaboration and identity systems) and develop ingestion pipelines (e.g., Azure Function Apps) for third-party logs.
- Tune audit retention, analytic rules, and alert logic to improve signal quality and investigation readiness.
Incident response & operational support / collaboration
- Provide Tier 3 troubleshooting for device compliance failures, identity/access incidents, telemetry gaps, and OS/app protection issues.
- Partner with cross-functional teams to align security solutions with business objectives, deliver technical leadership, and support enterprise syncs and operational reviews.
Continuous improvement & innovation
- Stay current on M365 security/compliance updates, industry trends, and emerging capabilities; drive improvements to security posture and operational efficiency (including use of GCC Copilot where appropriate).
Platform Scope / Tooling Microsoft 365 (GCC), Microsoft Purview (DLP/labels/classification/retention), Exchange Online, Entra ID & Conditional Access, Microsoft Intune, Microsoft Defender, Microsoft Sentinel, Azure (Function Apps / Log Analytics), plus integrations with collaboration/IT systems (e.g., ticketing and SaaS log sources).
“Day in the Life”
Morning
- Review Sentinel incidents, Defender telemetry gaps, and compliance drift.
- Respond to overnight CAP failures, Slack EMM issues, or OS update regressions.
- Join device/enterprise standups.
Midday
- Build/test remediation scripts (CVE fixes, NTLM disablement, compliance corrections).
- Deploy or test Intune configuration profiles, ESP changes, or app protection updates.
- Troubleshoot support cases with Microsoft (Purview DSPM, Copilot logs, Okta connector).
Afternoon
- Conduct cross-team investigations (external-user access anomalies, Teams meeting forensics).
- Validate CAP behaviors across platforms using test devices.
- Work on ATO evidence packages and documentation.
End of Day
- Update Jira tasks, Confluence documentation, and CR submissions.
- Send status updates on active investigations, mitigations, and test results.
Requirements
Bachelors Degree and 8+ years of experience. 4 additional years of experience may be substituted in lieu of degree.
Candidate MUST:
be a US Citizen or US Person with the ability to obtain a Public Trust level 5 clearance., Technical Skills
- Deep experience with Microsoft Defender (XDR, Endpoint, Cloud Apps).
- Hands-on with Sentinel SIEM, and cross-platform telemetry pipelines.
- Expert-level Intune engineering across Windows/macOS/iOS/iPadOS.
- Advanced PowerShell for remediation, automation, and OS image manipulation.
- Strong understanding of CAP architecture and identity risk enforcement.
- Experience with ATO control evidence, compliance mapping, and audit support.
Soft Skills
- Growth mindset and willingness to learn emerging security domains.
- Strong cross-team collaboration (Cyber, Ops, EA, ICAM, Comms).
- Excellent communication-clear summaries, user-impact translation, and documentation.
- High reliability, ownership, and situational awareness during high-severity events., * Prior experience in federal security, high-compliance, or high-assurance environments.
- Experience with Jamf, Okta connectors, Copilot audit logging, Graph API operations.
- Experience with mSCP baseline engineering and macOS security hardening.
- Prior involvement in enterprise-wide Conditional Access enforcement.
Benefits & conditions
Pay and benefits are fundamental to any career decision. That’s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits .
About the company
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com .
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
9 Ways to Make Money Hacking