Capitol Careers is currently in search of a Lead Microsoft Security Engineer for a large Federal Consulting Firm.
This is a Hybrid position, requiring working onsite in Washington, DC one day a week.
This position requires an Active Secret or Top-Secret Security Clearance.
About the Opportunity:
In this role, you will help lead the enterprise implementation of the Microsoft G5 security suite, strengthening endpoint protection, device management, cloud application security, and data protection. You will work with security, infrastructure, and business stakeholders to maximize the use of native Microsoft capabilities and translate security requirements into practical, maintainable controls.
This is a hands-on engineering opportunity with technical leadership responsibilities. The work includes deploying and tuning security tools, automating device provisioning, establishing secure personal-device access, and implementing Microsoft Purview data protection policies.
Key Responsibilities:
Microsoft Security Implementation
- Lead implementation and ongoing management of Microsoft Defender for Endpoint, Defender for Servers, and Defender for Cloud Apps.
- Assess existing configurations and identify opportunities to improve protection using the Microsoft G5 ecosystem.
- Configure and validate security policies, integrations, and operational workflows across hybrid environments.
- Troubleshoot implementation issues and coordinate remediation with infrastructure and security teams.
- Develop implementation plans, configuration documentation, and operational handoff materials.
Endpoint Management and Automation
- Implement and optimize Microsoft Intune for device management and security policy enforcement.
- Establish device compliance policies and continuous monitoring processes to identify and address noncompliant endpoints.
- Automate repeatable provisioning, configuration, and remediation activities.
- Test deployment changes and validate that security controls operate effectively without unnecessary disruption to users.
BYOD and Conditional Access
- Help design and implement a secure Bring Your Own Device (BYOD) program.
- Configure Mobile Application Management (MAM) and Mobile Device Management (MDM) controls appropriate to device ownership and business requirements.
- Develop and test Conditional Access policies that connect access decisions with device compliance and other approved security conditions.
- Coordinate pilot deployments, document exceptions, and refine policies based on testing and user feedback.
- Work with identity and endpoint teams to maintain consistent protection across managed and personal devices.
Microsoft Purview and Data Protection
- Support Data Loss Prevention (DLP) implementation across the hybrid enterprise.
- Author, test, tune, and validate sensitivity labels, retention policies, and automated data protection rules.
- Work with stakeholders to understand sensitive-data handling requirements and translate them into policy configurations.
- Investigate policy matches, exceptions, and unintended behavior to improve effectiveness.
- Document testing results and support the transition of data protection capabilities into ongoing operations.
Technical Leadership and Zero Trust
- Apply Zero Trust principles to endpoint, application, and data security implementations.
- Coordinate dependencies across security, identity, infrastructure, and business teams.
- Provide technical guidance on deployment decisions, policy design, and operational readiness.
- Communicate implementation progress, risks, and recommendations to project leadership.
- Identify opportunities to improve security maturity while making effective use of existing Microsoft investments.
Required Qualifications:
- Strong hands-on experience implementing and managing security capabilities within the Microsoft security ecosystem.
- Experience with Microsoft Defender for Endpoint, Defender for Servers, and Defender for Cloud Apps.
- Experience configuring Microsoft Intune and Windows Autopilot.
- Working knowledge of MDM, MAM, device compliance, and Conditional Access.
- Hands-on experience with Microsoft Purview, including DLP, sensitivity labels, retention policies, and data protection controls.
- Demonstrated experience applying Zero Trust principles to enterprise security implementations.
- Ability to troubleshoot policy and integration issues across hybrid environments.
- Strong technical documentation, stakeholder communication, and cross-functional leadership skills.
- Ability to work onsite in Washington, DC once per week.
- Requires an Active Secret or Top-Secret Security Clearance.
Ideal Background:
The strongest candidates will have led or played a significant engineering role in a Microsoft security rollout, with direct responsibility for configuring, testing, and operationalizing controls.
Experience should include both technical implementation and collaboration with the teams that will manage the tools after deployment.