CybersecurityJobs.io
← Back to all jobs

Job Description

Leidos is seeking a Senior Systems Engineer to safeguard Microsoft 365 and enterprise endpoints within a GCC tenant, based in Washington, DC. The role centers on governance, identity and device security, incident response, and risk management to uphold compliance and protect critical government IT assets. The compensation range for this position is USD 107,900 to 195,050 per year.

Responsibilities

  • Own the planning, rollout, and ongoing governance of M365 security policies, standards, and guardrails that reflect federal requirements and internal controls.
  • Oversee data protection governance, including document classification, labeling, retention, and Data Loss Prevention configurations using Microsoft Purview.
  • Define and enforce email security policies covering encryption, sensitivity labeling, and secure mail flow to minimize data leakage.
  • Implement and maintain email encryption solutions such as S/MIME or Microsoft Information Protection to protect email confidentiality.
  • Administer and monitor protections against spam, phishing, and malware to defend the ecosystem against evolving threats.
  • Engineer and validate device-compliance driven Conditional Access policies across Windows, macOS, and mobile platforms.
  • Investigate and remediate Conditional Access failures, identity anomalies, and external/guest access issues, including M365 B2B trust and secure partner collaboration needs.
  • Design, test, and deploy Intune configurations and compliance policies for Windows, macOS, and iOS/iPadOS, including Enrollment Status Pages and OOBE workflows.
  • Develop remediation scripts and configuration profiles to close compliance gaps and enforce security baselines.
  • Coordinate enterprise-wide rollout of urgent vulnerability mitigations and verified vendor fixes.
  • Support vulnerability reviews and baseline rebuild efforts.
  • Establish and operate a risk management approach to identify, assess, and mitigate security risks across the M365 environment.
  • Support ATO/control assessment activities by drafting implementation statements, gathering artifacts, and providing audit-ready evidence.
  • Lead the integration and operational management of Microsoft Defender and Microsoft Sentinel for threat detection, alerting, and response across M365.
  • Build and maintain SIEM integrations and connectors, and develop ingestion pipelines for third-party logs using tools like Azure Function Apps.
  • Tune audit retention, analytic rules, and alert logic to improve signal quality and investigation readiness.
  • Provide Tier 3 troubleshooting for device compliance failures, identity and access incidents, telemetry gaps, and OS/app protection issues.
  • Collaborate with cross-functional teams to align security solutions with business goals, deliver technical leadership, and support enterprise reviews.
  • Stay current on M365 security and compliance updates, industry trends, and emerging capabilities; drive improvements to security posture and operational efficiency, leveraging GCC Copilot where appropriate.

Requirements

  • Expert-level Intune engineering across Windows, macOS, iOS, and iPadOS.
  • Advanced PowerShell skills for remediation, automation, and OS image manipulation.
  • Deep experience with Microsoft Defender spanning XDR, Endpoint, and Cloud Apps.
  • Hands-on work with Sentinel SIEM, Function Apps, and cross-platform telemetry pipelines.
  • Strong understanding of CAP architecture and identity risk enforcement.
  • Experience with ATO control evidence, compliance mapping, and audit support.
  • Growth mindset and willingness to learn new security domains.
  • Excellent cross-team collaboration across Cyber, Ops, EA, ICAM, and Communications.
  • Clear and effective communication, with the ability to translate technical details into user-focused outcomes and maintain thorough documentation.
  • High reliability, ownership, and situational awareness during high-severity events.

Technologies

  • Microsoft 365 (GCC)
  • Microsoft Purview
  • Exchange Online
  • Entra ID
  • Conditional Access
  • Microsoft Intune
  • Microsoft Defender
  • Microsoft Sentinel
  • Azure Function Apps
  • Azure Log Analytics
  • PowerShell
  • S/MIME
  • Microsoft Information Protection
  • Graph API operations
  • Okta connectors
  • Jamf

Benefits

  • Competitive compensation
  • Health and Wellness programs
  • Income protection
  • Paid leave
  • Retirement plan

Day in the Life

  • Morning: Review Sentinel incidents, Defender telemetry gaps, and any compliance drift; respond to overnight CAP failures and device management issues; participate in device and enterprise standups.
  • Midday: Build and test remediation scripts for CVE fixes and compliance corrections; deploy or validate Intune profiles, ESP updates, and app protection changes; troubleshoot with Microsoft on Purview DSPM and related logs.
  • Afternoon: Lead cross-team investigations of external-user access anomalies; validate CAP behaviors across platforms with testing devices; work on ATO evidence packages and documentation.
  • End of day: Update Jira tasks, update Confluence documentation, submit change requests; share status updates on active investigations, mitigations, and test results.

Similar Jobs