Lead Microsoft Security Engineer

Capitol Careers LLC

Washington (District of Columbia)

Hybrid

USD 150,000 - 200,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Capitol Careers LLC in Washington, DC is seeking a Lead Microsoft Security Engineer to drive enterprise Microsoft security deployments, focusing on Defender for Endpoint, Defender for Servers, Defender for Cloud Apps, and Purview data protection.

The role blends hands-on engineering with technical leadership, including policy design, implementation, and coordinating across security, infrastructure, and business teams, with required onsite presence in DC once per week.

Qualifications

  • Strong hands-on experience implementing and managing security capabilities within the Microsoft security ecosystem.
  • Experience with Defender for Endpoint, Defender for Servers, and Defender for Cloud Apps.
  • Experience configuring Intune and Windows Autopilot.
  • Working knowledge of MDM, MAM, device compliance, and Conditional Access.
  • Hands-on experience with Microsoft Purview, including DLP, sensitivity labels, retention policies, and data protection controls.
  • Demonstrated experience applying Zero Trust principles to enterprise security implementations.
  • Ability to troubleshoot policy and integration issues across hybrid environments.
  • Strong technical documentation, stakeholder communication, and cross-functional leadership skills.
  • Ability to work onsite in Washington, DC once per week.
  • Requires an Active Secret or Top-Secret Security Clearance.

Responsibilities

  • Lead implementation and ongoing management of Defender for Endpoint, Defender for Servers, and Defender for Cloud Apps.
  • Assess configurations and identify opportunities to improve protection within the Microsoft G5 ecosystem.
  • Configure and validate security policies, integrations, and workflows across hybrid environments.
  • Troubleshoot implementation issues and coordinate remediation with infrastructure and security teams.
  • Develop implementation plans, configuration documentation, and operational handoff materials.
  • Implement and optimize Microsoft Intune for device management and security policy enforcement.
  • Establish device compliance policies and continuous monitoring processes to identify and address noncompliant endpoints.
  • Automate repeatable provisioning, configuration, and remediation activities.
  • Test deployment changes and validate that security controls operate effectively without unnecessary disruption to users.
  • Design and test BYOD programs and Conditional Access policies; coordinate pilot deployments.
  • Work with identity and endpoint teams to maintain consistent protection across managed and personal devices.

Skills

Leadership
Security engineering
Cross-functional collaboration
Documentation

Tools

Microsoft Defender for Endpoint
Defender for Servers
Defender for Cloud Apps
Microsoft Intune
Windows Autopilot
MDM
MAM
Microsoft Purview
DLP
Sensitivity labels
Retention policies
Conditional Access

Job description

Capitol Careers is currently in search of a Lead Microsoft Security Engineer for a large Federal Consulting Firm.

This is a Hybrid position, requiring working onsite in Washington, DC one day a week.

This position requires an Active Secret or Top-Secret Security Clearance.

About the Opportunity:

In this role, you will help lead the enterprise implementation of the Microsoft G5 security suite, strengthening endpoint protection, device management, cloud application security, and data protection. You will work with security, infrastructure, and business stakeholders to maximize the use of native Microsoft capabilities and translate security requirements into practical, maintainable controls.

This is a hands-on engineering opportunity with technical leadership responsibilities. The work includes deploying and tuning security tools, automating device provisioning, establishing secure personal-device access, and implementing Microsoft Purview data protection policies.

Key Responsibilities:
Microsoft Security Implementation
  • Lead implementation and ongoing management of Microsoft Defender for Endpoint, Defender for Servers, and Defender for Cloud Apps.
  • Assess existing configurations and identify opportunities to improve protection using the Microsoft G5 ecosystem.
  • Configure and validate security policies, integrations, and operational workflows across hybrid environments.
  • Troubleshoot implementation issues and coordinate remediation with infrastructure and security teams.
  • Develop implementation plans, configuration documentation, and operational handoff materials.
Endpoint Management and Automation
  • Implement and optimize Microsoft Intune for device management and security policy enforcement.
  • Establish device compliance policies and continuous monitoring processes to identify and address noncompliant endpoints.
  • Automate repeatable provisioning, configuration, and remediation activities.
  • Test deployment changes and validate that security controls operate effectively without unnecessary disruption to users.
BYOD and Conditional Access
  • Help design and implement a secure Bring Your Own Device (BYOD) program.
  • Configure Mobile Application Management (MAM) and Mobile Device Management (MDM) controls appropriate to device ownership and business requirements.
  • Develop and test Conditional Access policies that connect access decisions with device compliance and other approved security conditions.
  • Coordinate pilot deployments, document exceptions, and refine policies based on testing and user feedback.
  • Work with identity and endpoint teams to maintain consistent protection across managed and personal devices.
Microsoft Purview and Data Protection
  • Support Data Loss Prevention (DLP) implementation across the hybrid enterprise.
  • Author, test, tune, and validate sensitivity labels, retention policies, and automated data protection rules.
  • Work with stakeholders to understand sensitive-data handling requirements and translate them into policy configurations.
  • Investigate policy matches, exceptions, and unintended behavior to improve effectiveness.
  • Document testing results and support the transition of data protection capabilities into ongoing operations.
Technical Leadership and Zero Trust
  • Apply Zero Trust principles to endpoint, application, and data security implementations.
  • Coordinate dependencies across security, identity, infrastructure, and business teams.
  • Provide technical guidance on deployment decisions, policy design, and operational readiness.
  • Communicate implementation progress, risks, and recommendations to project leadership.
  • Identify opportunities to improve security maturity while making effective use of existing Microsoft investments.
Required Qualifications:
  • Strong hands-on experience implementing and managing security capabilities within the Microsoft security ecosystem.
  • Experience with Microsoft Defender for Endpoint, Defender for Servers, and Defender for Cloud Apps.
  • Experience configuring Microsoft Intune and Windows Autopilot.
  • Working knowledge of MDM, MAM, device compliance, and Conditional Access.
  • Hands-on experience with Microsoft Purview, including DLP, sensitivity labels, retention policies, and data protection controls.
  • Demonstrated experience applying Zero Trust principles to enterprise security implementations.
  • Ability to troubleshoot policy and integration issues across hybrid environments.
  • Strong technical documentation, stakeholder communication, and cross-functional leadership skills.
  • Ability to work onsite in Washington, DC once per week.
  • Requires an Active Secret or Top-Secret Security Clearance.
Ideal Background:

The strongest candidates will have led or played a significant engineering role in a Microsoft security rollout, with direct responsibility for configuring, testing, and operationalizing controls.

Experience should include both technical implementation and collaboration with the teams that will manage the tools after deployment.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer (Hybrid)
Security Engineer (Hybrid)

B5 Recruiting • Washington

On-site
USD 120,000 - 180,000
Security Engineer – Microsoft Security
Security Engineer – Microsoft Security

B5 Recruiting • Washington

On-site
USD 140,000 - 180,000
Security solution Architect
Security solution Architect

Digital Minds Global Technologies Inc. • Bellevue (KY)

Remote
USD 171,924,000 - 220,416,000
Senior Microsoft 365 Specialist
Senior Microsoft 365 Specialist

Superior Contracting & Maintenance • Austin (TX)

On-site
USD 80,000 - 120,000
Competitive compensation and benefits package
Professional growth and certification support
Opportunities for diverse projects
Senior Microsoft 365 Specialist
Senior Microsoft 365 Specialist

GCS Technologies • Austin (TX)

On-site
USD 90,000 - 130,000
Competitive compensation and benefits
Professional growth and certification support
Collaborative, customer-focused culture
Senior Microsoft Security Engineer - Defender & Purview
Senior Microsoft Security Engineer - Defender & Purview

Capitol Careers LLC • Washington

Hybrid
USD 150,000 - 200,000
Security Engineer, Identity & Cloud
Security Engineer, Identity & Cloud

District Partners • Washington

Hybrid
USD 132,000 - 165,000
System Admin / Onsite / Mesa
System Admin / Onsite / Mesa

Motion Recruitment Partners LLC • Mesa (AZ)

On-site
USD 120,000 - 160,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Maestro Technologies, Inc. • Santa Monica (CA)

Hybrid
USD 150,000 - 210,000
Senior Data Security Engineer
Senior Data Security Engineer

ZipStaff Inc. • Washington

On-site
USD 165,000 - 248,000