CompTIA Cybersecurity Analyst (CySA+) Systems Security Certified Practitioner

CareerCircle
Pittsburgh, PA, United States
1 day ago
Apply on www.careercircle.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$107,900.0 - $195,050.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Application Programming Interfaces (APIs) Antivirus Softwares Microsoft Antivirus Apache Tomcat Apple IOS Apple Mac Systems Software System Penetration Testing Confluence JIRA Audit Trail Microsoft Azure
+52 more
Software as a Service Cloud Computing Cloud Computing Security CompTIA Security+ Cyber Security Information Leak Prevention Data Security Digital Forensics Email Filtering Federal Information Processing Standards (FIPS) Information Technology Operations Intrusion Detection and Prevention Virtual Private Networks (VPN) Key Management Network Security Log Analysis Microsoft Security Essentials Microsoft Office Multi-Purpose Internet Mail Extensions (MIME) NT LAN Manager Public Key Infrastructure Windows PowerShell Red Hat Enterprise Linux Cloud Services Phishing Security Information and Event Management Systems Integration TCP/IP Software Technical Review Software Vulnerability Management Data Logging Scripting Transport Layer Security Okta Data Ingestion Cyber Threat Analysis Firewalls (Computer Science) Microsoft InTune Information Technology Google Cloud Functions Microsoft Sentinel Casper Suite Malware Detection Graphql 3-tier Architectures CIS Benchmarks Document Classification Serverless Computing Cisco Servicenow Plan of Action and Milestones Vulnerability Analysis

Job description

JIRA Jamf Mac OS Tooling Auditing Teamwork Equities Phishing Telemetry Apple IOS Management Automation Governance Encryption Market Data Communication Investigation Microsoft 365 Email Security Azure Sentinel NT LAN Manager Risk Management Law Enforcement Azure Functions Confidentiality Slack (Software) Windows Defender Threat Detection Operating Systems Security Policies Incident Response Windows PowerShell Facebook Graph API Security Solutions Business Objectives Information Privacy Operations Security Security Governance Security Engineering Business To Business Technical Leadership Willingness To Learn Data Loss Prevention Atlassian Confluence Anti-Spam Techniques Compliance Assurance Compliance Management Packaging And Labeling Information Technology Operational Efficiency Document Classification Product Family Engineering Office 365 Exchange Online Software As A Service (SaaS) Troubleshooting (Problem Solving) Security Information And Event Management (SIEM) Microsoft Intune (Mobile Device Management Software) Secure/Multipurpose Internet Mail Extensions (S/MIME), Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role requires a seasoned professional who can strategically manage and enhance the security and compliance posture of the M365 environment within a GCC (Government Community Cloud) tenant, particularly in a federal agency context. This senior engineering role sits at the center of the organization’s device, identity, and M365 security ecosystem. The engineer is responsible for protecting enterprise Windows, macOS, iOS/iPadOS endpoints; ensuring compliant, reliable access to M365 services, and driving rapid engineering responses to vulnerabilities, outages, and operational risks. The successful candidate will apply with deep technical expertise, cross-platform engineering capability, and high operational security judgment., Strategic security oversight & governance

  • Lead the development, implementation, and ongoing management of M365 security policies, standards, and technical guardrails aligned to federal requirements and organizational controls.
  • Own governance for data protection capabilities including document classification, labeling, retention, and Data Loss Prevention (DLP) using Microsoft Purview.

Email security & compliance management (Exchange Online)

  • Define and enforce email security policies such as encryption, sensitivity labeling, and secure mail flow to reduce unauthorized disclosure.
  • Implement and maintain email encryption solutions (S/MIME and/or Microsoft Information Protection) to protect confidentiality of email communications.
  • Administer and monitor anti-spam, anti-phishing, and anti-malware protections to defend against evolving threats.

Identity, access, and conditional access (Entra ID)

  • Engineer and validate device-compliance-based Conditional Access policies across Windows, macOS, and mobile platforms.
  • Investigate and remediate Conditional Access failures, identity anomalies, and external/guest access issues, including M365 B2B trust and secure partner collaboration requirements.

Endpoint & device security engineering (Intune)

  • Design, test, and deploy Intune configuration and compliance policies for Windows, macOS, and iOS/iPadOS, including Enrollment Status Pages (ESPs) and OOBE workflows.
  • Develop remediation scripts (PowerShell/platform scripts/configuration profiles) to close compliance gaps and enforce security baselines.
  • Coordinate enterprise rollout of urgent vulnerability mitigations and validated vendor fixes; support vulnerability reviews and baseline rebuilds.

Risk management & compliance assurance (ATO / controls)

  • Establish and operate a risk management approach to identify, assess, and mitigate security risks across the M365 ecosystem.
  • Support ATO/control assessment activities by drafting implementation statements, collecting artifacts, and providing evidence aligned to audit/logging requirements.

Security monitoring, SIEM, and telemetry engineering (Defender / Sentinel)

  • Lead integration and operational management of Microsoft Defender and Microsoft Sentinel for threat detection, alerting, and response across M365.
  • Build and maintain SIEM integrations/connectors (e.g., M365, collaboration and identity systems) and develop ingestion pipelines (e.g., Azure Function Apps) for third-party logs.
  • Tune audit retention, analytic rules, and alert logic to improve signal quality and investigation readiness.

Incident response & operational support / collaboration

  • Provide Tier 3 troubleshooting for device compliance failures, identity/access incidents, telemetry gaps, and OS/app protection issues.
  • Partner with cross-functional teams to align security solutions with business objectives, deliver technical leadership, and support enterprise syncs and operational reviews.

Continuous improvement & innovation

  • Stay current on M365 security/compliance updates, industry trends, and emerging capabilities; drive improvements to security posture and operational efficiency (including use of GCC Copilot where appropriate).

Platform Scope / Tooling Microsoft 365 (GCC), Microsoft Purview (DLP/labels/classification/retention), Exchange Online, Entra ID & Conditional Access, Microsoft Intune, Microsoft Defender, Microsoft Sentinel, Azure (Function Apps / Log Analytics), plus integrations with collaboration/IT systems (e.g., ticketing and SaaS log sources).

Day in the Life”

Morning

  • Review Sentinel incidents, Defender telemetry gaps, and compliance drift.
  • Respond to overnight CAP failures, Slack EMM issues, or OS update regressions.
  • Join device/enterprise standups.

Midday

  • Build/test remediation scripts (CVE fixes, NTLM disablement, compliance corrections).
  • Deploy or test Intune configuration profiles, ESP changes, or app protection updates.
  • Troubleshoot support cases with Microsoft (Purview DSPM, Copilot logs, Okta connector).

Afternoon

  • Conduct cross-team investigations (external-user access anomalies, Teams meeting forensics).
  • Validate CAP behaviors across platforms using test devices.
  • Work on ATO evidence packages and documentation.

End of Day

  • Update Jira tasks, Confluence documentation, and CR submissions.
  • Send status updates on active investigations, mitigations, and test results.

Please Note:

Please be advised that if you are moved to the interview stage, during the interview you will be required to keep your camera on, and your interviewer will be taking your picture for identification purposes if an offer letter is extended to you *

If you’re looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We’re not hiring followers. We’re recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We’re already at step 30 - and moving faster than anyone else dares., #Featuredjob Related Jobs Security Engineer TEKsystems

Pittsburgh, PA*Remote

Scripting Operations Automation Encryption Cryptography Key Management Risk Management Business Valuation Enterprise Security Quantum Cryptography Full Stack Development Business Transformation Public Key Infrastructure Application Programming Interface (API) Federal Information Processing Standards (FIPS) +0 Information Security Engineer ONSITE In Fort Collins, CO TEKsystems

Fort Collins, CO*Remote

TCP/IP Firewall Equities Phishing Operations Leadership Governance Positivity Communication Investigation Cyber Security Cloud Services Risk Management Problem Solving Customer Service Network Security Threat Detection Security Controls Incident Response Digital Forensics Business Valuation Penetration Testing Security Technology GIAC Certifications Time Off Management Security Engineering Cyber Threat Hunting CompTIA Certification Full Stack Development Business Transformation Vulnerability Management Vulnerability Assessments Cyber Threat Intelligence Microsoft Defender Antivirus Continuous Improvement Process Virtual Private Networks (VPN) Transport Layer Security (TLS) Endpoint Detection And Response Cisco Certified Network Associate CompTIA Cybersecurity Analyst (CySA+) Systems Security Certified Practitioner GIAC Security Essentials Certification (GSEC) Red Hat Certified System Administrator (RHCSA) GIAC Global Industrial Cyber Security Professional +0

Google Cybersecurity Cyber Security Engineer Leidos

Remote

Auditing Equities Hardening Operations Leadership Resilience ServiceNow Market Data Communication Apache Tomcat Cyber Security Cloud Security Ancient History Incident Response CompTIA Security+ Cyber Engineering

Requirements

Bachelors Degree and 8+ years of experience. 4 additional years of experience may be substituted in lieu of degree.

Candidate MUST:

be a US Citizen or US Person with the ability to obtain a Public Trust level 5 clearance., Technical Skills

  • Deep experience with Microsoft Defender (XDR, Endpoint, Cloud Apps).
  • Hands-on with Sentinel SIEM, and cross-platform telemetry pipelines.
  • Expert-level Intune engineering across Windows/macOS/iOS/iPadOS.
  • Advanced PowerShell for remediation, automation, and OS image manipulation.
  • Strong understanding of CAP architecture and identity risk enforcement.
  • Experience with ATO control evidence, compliance mapping, and audit support.

Soft Skills

  • Growth mindset and willingness to learn emerging security domains.
  • Strong cross-team collaboration (Cyber, Ops, EA, ICAM, Comms).
  • Excellent communication-clear summaries, user-impact translation, and documentation.
  • High reliability, ownership, and situational awareness during high-severity events., * Prior experience in federal security, high-compliance, or high-assurance environments.
  • Experience with Jamf, Okta connectors, Copilot audit logging, Graph API operations.
  • Experience with mSCP baseline engineering and macOS security hardening.
  • Prior involvement in enterprise-wide Conditional Access enforcement., Security Clearance Workflow Management Root Cause Analysis GIAC Certifications Enterprise Security Information Assurance Security Configuration Public Trust Clearance Technical Documentation Cyber Incident Response Vulnerability Management Cybersecurity Compliance Software Technical Review Security Requirements Analysis Technical Procedure Compliance Endpoint Detection And Response GIAC Certified Incident Handler GIAC Certified Intrusion Analyst Information Technology Operations Troubleshooting (Problem Solving) CompTIA Cybersecurity Analyst (CySA+) Plan Of Action And Milestones (POA&M)

Benefits & conditions

Pay and benefits are fundamental to any career decision. That’s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits .

About the company

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com .

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careercircle.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all