M365 Security Engineer

ETHOS - Talent & Advisory

Washington (District of Columbia)

On-site

USD 140,000 - 190,000

Full time

26 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

ETHOS - Talent & Advisory seeks a senior security engineer to own the security and compliance posture of a Microsoft 365 GCC environment supporting a federal agency. You will protect Windows, macOS, and iOS/iPadOS endpoints, keep access to M365 services compliant and reliable, and lead fast engineering responses to vulnerabilities, outages, and risk.

You will lead Defender/Sentinel integration, build SIEM pipelines, write PowerShell remediation scripts, and coordinate enterprise rollout of

Qualifications

  • Bachelor's degree or 8+ years of related experience.
  • Hands-on Defender XDR, Endpoint, and Cloud Apps experience.
  • Cross-platform return telemetry with Sentinel and SIEM.
  • Expert-level Intune engineering across Windows, macOS and iOS/iPadOS.
  • Advanced PowerShell for remediation and automation.
  • Strong Conditional Access architecture and Entra ID integration.
  • Experience producing ATO evidence and audit support.
  • Ability to communicate complex issues clearly during high-severity events.

Responsibilities

  • Engineer, test, and deploy Intune policies across Windows/macOS/iOS, incl. Enrollment Status Pages and OOBE workflows.
  • Design and validate device-based Conditional Access in Entra ID; troubleshoot CAP and identity issues.
  • Lead integration and tuning of Defender and Microsoft Sentinel with rules and connectors.
  • Build SIEM ingestion pipelines for third-party logs using Azure Function Apps and Log Analytics.
  • Write PowerShell remediation scripts to close compliance gaps and enforce baselines.
  • Own data protection governance in Purview: classification, labeling, retention, and DLP.
  • Secure Exchange Online mail flow and anti-malware protections; manage encryption.
  • Support ATO/control assessments by drafting implementation statements and assembling evidence packages.
  • Provide Tier 3 support on device compliance, identity, telemetry, and app protection incidents; coordinate rollouts.
  • Partner with Cyber, Ops, EA, ICAM, and Comms; keep Jira/Confluence and change requests current.

Skills

Intune engineering
PowerShell
Microsoft Defender
Microsoft Sentinel
SIEM
Entra ID
Azure Function Apps
Log Analytics
Conditional Access
Compliance governance

Education

Bachelor's degree
12+ years experience in lieu of degree

Tools

Jamf
Okta connectors
Copilot audit logging
Microsoft Graph API

Job description

Our federal IT client is looking for a senior engineer to own the security and compliance posture of a Microsoft 365 GCC environment supporting a federal agency. This role sits at the center of device, identity, and M365 security: you will protect Windows, macOS, and iOS/iPadOS endpoints, keep access to M365 services compliant and reliable, and lead fast engineering responses to vulnerabilities, outages, and operational risk.

What You Will Do
  • Engineer, test, and deploy Intune configuration and compliance policies across Windows, macOS, and iOS/iPadOS, including Enrollment Status Pages and OOBE workflows
  • Design and validate device compliance based Conditional Access policies in Entra ID, and troubleshoot CAP failures, identity anomalies, and B2B guest access issues
  • Lead integration and tuning of Microsoft Defender (XDR, Endpoint, Cloud Apps) and Microsoft Sentinel, including analytic rules, alert logic, audit retention, and connectors
  • Build SIEM ingestion pipelines for third party log sources using Azure Function Apps and Log Analytics
  • Write PowerShell remediation scripts to close compliance gaps, deploy CVE fixes, and enforce security baselines (for example NTLM disablement)
  • Own data protection governance in Microsoft Purview: classification, sensitivity labeling, retention, and DLP
  • Secure Exchange Online mail flow, encryption (S/MIME and/or MIP), and anti spam, anti phishing, and anti malware protections
  • Support ATO and control assessments by drafting implementation statements and assembling evidence packages
  • Provide Tier 3 support on device compliance, identity, telemetry, and app protection incidents, and coordinate enterprise rollout of urgent vulnerability mitigations
  • Partner with Cyber, Ops, Enterprise Architecture, ICAM, and Comms teams, and keep Jira, Confluence, and change requests current
Required
  • Bachelor's degree and 8+ years of experience, or 12+ years of experience in lieu of a degree
  • US Citizen or US based person able to obtain a Public Trust (Level 5)
  • Deep, hands on experience with Microsoft Defender (XDR, Endpoint, Cloud Apps)
  • Hands on Microsoft Sentinel SIEM experience, including cross platform telemetry pipelines
  • Expert level Intune engineering across Windows, macOS, and iOS/iPadOS
  • Advanced PowerShell for remediation, automation, and OS image manipulation
  • Strong understanding of Conditional Access architecture and identity risk enforcement in Entra ID
  • Experience producing ATO control evidence, compliance mapping, and audit support
  • Clear communicator who can summarize technical issues in terms of user impact and stay steady during high severity events
Preferred
  • Federal, high compliance, or high assurance environment experience (GCC or GCC High a strong plus)
  • Jamf, Okta connectors, Copilot audit logging, and Microsoft Graph API operations
  • macOS security hardening and mSCP baseline engineering
  • Prior ownership of an enterprise wide Conditional Access rollout
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior M365 Security & Compliance Engineer (GCC)
Senior M365 Security & Compliance Engineer (GCC)

ETHOS - Talent & Advisory • Washington

On-site
USD 140,000 - 190,000
Senior Microsoft 365 Specialist
Senior Microsoft 365 Specialist

GCS Technologies • Austin (TX)

On-site
USD 90,000 - 130,000
Competitive compensation and benefits
Professional growth and certification support
Collaborative, customer-focused culture
Senior Microsoft 365 Specialist
Senior Microsoft 365 Specialist

Superior Contracting & Maintenance • Austin (TX)

On-site
USD 80,000 - 120,000
Competitive compensation and benefits package
Professional growth and certification support
Opportunities for diverse projects
M365 Security Engineer
M365 Security Engineer

Cypress Consulting • Northern (KY)

Hybrid
USD 120,000 - 180,000
M365 Security and Compliance Administrator
M365 Security and Compliance Administrator

4A Consulting, LLC • Washington

On-site
USD 120,000 - 180,000
Comprehensive benefits package
Flexible work options
Senior M365 Security & Compliance Architect
Senior M365 Security & Compliance Architect

4A Consulting, LLC • Washington

On-site
USD 120,000 - 180,000
Comprehensive benefits package
Flexible work options
Senior Engineer, O365 & Endpoint Administration
Senior Engineer, O365 & Endpoint Administration

Equabli • United States

Remote
USD 110,000 - 140,000
Microsoft 365 Platform Engineer
Microsoft 365 Platform Engineer

MPW Industrial Services, Inc. • Hebron (OH)

On-site
USD 105,000 - 135,000
Senior Microsoft 365 Specialist
Senior Microsoft 365 Specialist

GCS Technologies, Inc. • Austin (TX)

On-site
USD 100,000 - 130,000
Competitive compensation
Professional growth support
Collaborative culture
Senior M365 Security & Compliance Engineer (GCC)
Senior M365 Security & Compliance Engineer (GCC)

Leidos LLC • United States

Remote
USD 108,000 - 195,000
Health and Wellness programs
Income Protection
Paid Leave and Retirement