> Markdown version of [/jobs/ext/2735851-microsoft-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/2735851-microsoft-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Microsoft Senior Security Engineer - **Company:** CareerCircle - **Location:** Adelphi, MD, United States - **Experience:** Expert - **Salary:** $116,000.0 - $131,000.0 - **Contract:** Permanent contract - **Skills:** C (Programming Language), Java (Programming Language), .NET Framework, Multitier Architecture, Microsoft Windows, Application Programming Interfaces (APIs), Agile Methodology, Amazon Web Services, Antivirus Softwares, Systems Engineering, User Authentication, Automation of Tests, Microsoft Azure, C++ (Programming Language), Client Server Models, Cisco PIX, Cloud Computing, Configuration Management, Control Objectives for Information and Related Technology (COBIT), Code Review, Signals Intelligence, CompTIA Security+, Cyber Security, Information Systems, Computer Networks, Continuous Integration, Data Security, Linux, Digital Forensics, Middleware, Cryptographic Protocols, Firmware, Monitoring of Systems, Networking Hardware, Internet Protocol Security (IP SEC), Intrusion Detection and Prevention, Virtual Private Networks (VPN), Information Systems Security Architecture Professional, JavaScript Libraries, Python (Programming Language), Key Management, Local Area Networks, Network Security, Microsoft Security Essentials, Microsoft Operating Systems, Network Architecture, Network Planning and Design, Wireless Security, Network Protocols, Windows PowerShell, Software Architecture, Ruby on Rails, Role-Based Access Control, Ansible, Zero Trust Network Access, Reverse Engineering, Secure Coding, Web Application Security, Security Software, Service Pack, Security Information and Event Management, Single Sign-On, Software Engineering, SonarQube, Virtual Machines, Software Vulnerability Management, Wide Area Networks, Web Applications, Network Routing, Network Routers, Scripting, Google Cloud, Enterprise Software Applications, Computer Network Operations, ReactJS, Cyber Threat Analysis, Firewalls (Computer Science), Cloudformation, Azure Security Center, Information Technology, Deployment Automation, Patch Management, Nessus, Cloud Migration, ISO/IEC 27002, Oracle Cloud Infrastructure, Splunk, Multiplatform, Devsecops, Cisco, Plan of Action and Milestones, Vulnerability Analysis, Programming Languages - **Published:** September 5, 2026 - **Apply:** https://www.careercircle.com/jobs/all/all/usa/md/adelphi/0c4b739b-79bc-46ec-a009-1d9ddc08ac1a ## About the Role Advocacy Firewall Topology Cisco PIX Management Automation Mentorship Mitigation IT Security Code Review Presentations Ruby On Rails ISO/IEC 27002 Security Risk Change Control .NET Framework Azure Security Security Tools Detail Oriented Risk Management Time Management Authentications Team Leadership Safety Assurance Virtual Machines Network Security, * Demonstrated effective strong team player and self-motivator. Ability to work and interface internally with a IT and other functional support groups with minimal guidance * Demonstrated successful experience in a customer-facing role * Demonstrated communicator both written and verbal, with effective presentation delivery and meeting facilitation * Demonstrated effective time management, organizational and documentation skills * Good analytical and troubleshooting skills with strong attention to detail, * 10 years or more of professional experience with 7 or more years in IT security including security policy development, security architecture models, and information security regulatory compliance * Must have the knowledge of IT security technologies such as firewalls, intrusion detections systems, antivirus, patch management, etc., and the interest and experience to work on security policy and architecture * Hands-on experience with the following technologies: enterprise system administration across multiple operating systems, IPS management (i.e., Cisco ASA, Palo Alto), vulnerability scanning applications, Splunk * Experience in engineering and enterprise system administration roles. * Experience developing a standard set of metrics that measure our security posture on a * monthly/weekly basis. * Proven experience developing security policies, procedures, risk registers and incident * response plans * Intermediate to advanced knowledge of information security concepts. * Experience with one or more applications development languages such as Ruby on Rails, Java, C/C++, .NET. * Solid knowledge of and experience with secure web architectures, tools and processes * Knowledge of network architecture and design, network Security, wireless Security and client/server security. Very strong computer networking skills and understanding of networking protocols. * Security of virtual machine environments is highly desirable. * Knowledge of vulnerability assessment/network discovery and associated tools * Understands infrastructure monitoring * Knowledge of securing Linux and Windows systems. * Experience with various types of firewalls and technologies * Demonstrated process improvement experience * Previous application development experience is very helpful for secure code reviews * Hands-on experience using multiple Amazon Web Services technologies to support an enterprise environment. * Prior experience as a team lead or role mentoring junior team members. * Experience with threat detection and incident management for web applications that deal with PI Certifications: * Possessing at least one professional security certification such as CISSP, CISM, CISA or similar., * Bachelor's degree ## Description Windows Defender Threat Detection Security Testing Patch Management Operating Systems Security Policies Incident Response Wireless Security IT Infrastructure Network Protocols Computer Networks Network Discovery IT Risk Management Wide Area Networks Process Improvement Amazon Web Services Incident Management Local Area Networks Medical Prescription Single Sign-On (SSO) Meeting Facilitation Network Architecture IT Service Management Software Architecture Vulnerability Scanning Application Development Cryptographic Protocols C (Programming Language) Web Application Security IT Security Architecture Vulnerability Assessments Authorization (Computing) C++ (Programming Language) Java (Programming Language) Microsoft Operating Systems Microsoft Defender Antivirus Security Requirements Analysis Enterprise Application Software Software Development Life Cycle Troubleshooting (Problem Solving) Software Defined Networking (SDN) Certified Information Security Manager Cisco Adaptive Security Appliance (ASA) General Data Protection Regulation (GDPR) Certified Information System Auditor (CISA) Information Technology Infrastructure Library Certified Information Systems Security Professional Control Objectives For Information And Related Technology (COBIT) This role is STARs-friendly: Skilled Through Alternative Routes. 35% STARs in role., The Senior Microsoft Security Engineer will be responsible for identifying potential threats to the IT infrastructure, recommending enhancements accordingly and implementing those technologies. The Senior Microsoft Security Engineer provides support to ensure applicable information protection policies, procedures, guidelines, best practices are followed. Performs Security Risk Assessments (SRAs) and performs compliance reviews to ensure applications and servers are operating in accordance with established policies and procedures. The Microsoft Senior Security Engineer will be expected to demonstrate all of these skills while demonstrating specific emphasis on the application of Microsoft's security product suite along with other best in class industry security tools. Educates stakeholders in the assessment process and lead both pre- and post-assessment meetings., * Fully leverage the educational institutions Microsoft A5 license suite of products; in particular as it pertains to the industry leading suit of security products, processes, and strategies * Lead the educational institutions Microsoft security cloud first" strategy leading to fully leverage SDN (Software Defined Networking) Zero Trust, and Least Privilege strategies * Design, implement, and maintain Microsoft security solutions for the educational institution's infrastructure * Ensure that Microsoft operating systems are configured securely and that security patches are regularly applied * Manage the configuration and effective use of Microsoft security products, including Microsoft Defender ATP, Azure Security Center, and Microsoft Information Protection. * Implement Microsoft security best practices to maintain the security posture of the educational institution's infrastructure. * Collaborate with Infrastructure/ITSM/Technical teams to implement security requirements in new and existing technology solutions. * Stay up-to-date with the latest security threats and industry trends, and apply this knowledge to improve security protocols within the educational institution. * Serve as a security expert in network efforts, helping project teams comply with * enterprise and IT security policies, industry regulations, and best practices. * Lead and execute projects on our security roadmap. * Adhere to existing risk management frameworks, such as COBIT, ITIL, and ISO 27002. * Manage incident response for network security events. * Develop and maintain IT security policies. * Research, design, and advocate new technologies, architectures, and security * products that will support security requirements for the enterprise and its customers, * business partners, and vendors. * Support vulnerability assessments on various types of networks and topologies; * Execute risk and vulnerability assessments and remediation activities. * Analyze output from network vulnerability assessments, recommend mitigation strategies and resolve any security incidents through work with pertinent business departments. * Review and provide feedback on security plans and procedures regarding all aspects of LAN, WAN or MANs, as applicable; * Review and provide input into network designs to ensure compliance with security and enterprise architecture. * Provide input and visibility into emerging security technologies, deployment strategies and other security protocols to ensure awareness within the IT security branch. * Build/enhance security architecture and configure network to enhance the security posture of the enterprise. * Review in-house and 3rd-party applications/code for security vulnerabilities and best practices. * Participate in Software Development Lifecycle: code review, QA security testing, launches, etc. * Develop and/or implement automated security testing tools where possible. * Participate in the development of security-related tools and applications, such as multi-platform cookie-based authentication and internal security libraries/frameworks. * Train engineers on common security problems and best practices for writing secure code. * Provide security input on overall software architecture. * Perform hands-on testing of applications, as well as build and enforce information risk management requirements and structure, including providing practical secure architecture skills and developing and implementing Information Security best practices. Skills : * Basic skills needed include: + Secure solutions development + Middleware security + n-tier apps dev infrastructure + Compliance - PCI, GLB, GLBA, CMMC. GDPR, etc. + Risk management and security risk assessments + Code review, reverse engineering + API's and protocols + Authentication and authorization. SSO (Single Sign On), MFA (Multi- Factor Auth.). * Enterprise aware (change control, downstream impacts, understanding of cause and effect, change windows, etc.) * Recognized as a strategic thinker and is results oriented, CI/CD Splunk Nessus Rapid7 Ansible Auditing Firewall Equities Scripting SonarQube DevSecOps Pipelines Operations Automation Purchasing Upskilling Market Data Coordinating Oracle Cloud Cryptography Investigation Cyber Security Key Management Risk Management Authentications Cloud Computing Ancient History Network Security Security Controls Incident Response CompTIA Security+ Digital Forensics System Monitoring Endpoint Security Cyber Engineering Analytical Method Windows PowerShell AWS CloudFormation Systems Engineering Amazon Web Services Time Off Management Security Engineering Software Development Contingency Planning Signals Intelligence Programming Languages Regulatory Frameworks Vulnerability Scanning Security Configuration Cyber Security Policies Configuration Management Vulnerability Management Certified Ethical Hacker Cyber Security Standards Cybersecurity Compliance Risk Management Framework Authorization (Computing) Cyber Threat Intelligence Cyber Security Assessment IT Security Documentation Agile Software Development Splunk Enterprise Security Google Cloud Platform (GCP) Computer Network Operations Change Management Processes Information Systems Security Customer Information Systems React.js (Javascript Library) Python (Programming Language) Enterprise Application Software Endpoint Detection And Response Troubleshooting (Problem Solving) Host Based Security System (HBSS) Intrusion Detection And Prevention CompTIA Cybersecurity Analyst (CySA+) Plan Of Action And Milestones (POA&M) Security Information And Event Management (SIEM) Certified Information Systems Security Professional Top Secret-Sensitive Compartmented Information (TS/SCI Clearance) +0 Firewall Engineer Leidos Arlington, VA*On-Site Firewall Equities DevSecOps Operations Management Automation Market Data Consolidation Cyber Security Self-Motivation Working Capital Cloud Migration Service Catalog Virtual Routers Ancient History Customer Service Security Clearance Service Management Security Solutions Technology Roadmaps Networking Hardware Information Sharing GIAC Certifications Palo Alto Firewalls CompTIA Security+ CE Continuous Integration Continuous Development Web Application Security IAT Level II Certification Virtual Private Networks (VPN) Internet Protocol Security (IP SEC) CompTIA Cybersecurity Analyst (CySA+) Systems Security Certified Practitioner Information Technology Infrastructure Library GIAC Security Essentials Certification (GSEC) Counter Intelligence Polygraph (CI Clearance) GIAC Global Industrial Cyber Security Professional Cisco Certified Network Associate Security (CCNA Security) Top Secret-Sensitive Compartmented Information (TS/SCI Clearance) +0 Information Systems Security Engineer Leidos Linthicum, MD*On-Site Planning Firewall Firmware Equities Mitigation CNSSI 1253 Market Data Gap Analysis Risk Analysis Risk Management Network Routing Ancient History Computer Science Security Systems Operating Systems Security Policies Network Protocols Information Privacy Networking Hardware Network Engineering Network Architecture Information Assurance Communications Systems Information Systems Security Security Requirements Analysis Certified Information Systems Security Professional Top Secret-Sensitive Compartmented Information (TS/SCI Clearance) +0 ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)