Security Engineer

Chickasaw Nation Industries

Bethesda (MD)

On-site

USD 100,000 - 120,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, vision insurance
401(k) Immediate Vesting
Life Insurance
Short-Term and Long-Term Disability
Professional Development Assistance
Paid Time Off
Federal holidays observe

Job summary

Chickasaw Nation Industries in Bethesda, MD seeks an Endpoint Security Baseline Engineer to design, implement, and maintain standardized security baselines across Windows and macOS endpoints using Intune, MECM, and Jamf Pro. You will validate deployments, support Zero Trust initiatives, and ensure compliance with federal cybersecurity requirements.

The role requires expertise in Microsoft security technologies, CIS/Microsoft baselines, and enterprise endpoint management within regulated

Qualifications

  • Experience administering Microsoft Intune and Microsoft Endpoint Manager.
  • Experience implementing Microsoft Security Baselines and CIS Benchmarks.
  • Knowledge of Microsoft Defender for Endpoint and endpoint protection policies.
  • Strong PowerShell scripting experience for automation.
  • Familiarity with Entra ID, Conditional Access and RBAC.
  • Understanding of NIST 800-53 and Zero Trust in federal environments.

Responsibilities

  • Engineer and maintain Microsoft Intune Security Baselines, Endpoint Security policies, and Configuration Profiles.
  • Develop and maintain Group Policy, MECM Configuration Baselines, and Jamf security configurations.
  • Configure Defender for Endpoint, ASR rules, firewall policies, BitLocker, and device encryption settings.
  • Define compliance policies and Conditional Access dependencies to support Zero Trust.
  • Collaborate with cybersecurity, RMF, ISSO, and engineering teams to meet security requirements.
  • Document configurations, procedures, and rollback steps; support vulnerability remediation.

Skills

Microsoft Intune
MECM/SCCM
Jamf Pro
PowerShell scripting
Endpoint security
Zero Trust
NIST 800-53
Conditional Access
Defender for Endpoint
ASR rules

Education

Bachelor's degree

Tools

Jamf Pro
Microsoft Intune
MECM/SCCM
Microsoft Defender for Endpoint
Azure Virtual Desktop
Entra ID

Job description

CNI seeking an Endpoint Security Baseline Engineer to support the engineering, implementation, and operational management of enterprise endpoint security configurations across Microsoft Intune, Microsoft Endpoint Configuration Manager (MECM), and Jamf Pro environments. This role is responsible for designing, implementing, validating, and maintaining standardized security baselines that improve the organization's cybersecurity posture while ensuring operational stability across Windows and macOS endpoints.The ideal candidate possesses experience with Microsoft security technologies, endpoint hardening, compliance policies, CIS and Microsoft Security Baselines, and enterprise endpoint management platforms within highly regulated federal environments.Chickasaw Nation Industries, Inc. serves as a holding company with multiple subsidiaries engaged in several lines of business (Business Services, Health, Infrastructure and Engineering, Mission Optimization, Technology and Transportation) for the federal government and commercial enterprises. A portion of our profits is used to support Chickasaw citizens. We are proud to support the economic development and long-term viability of the Chickasaw Nation and its people. CNI offers premium benefits eligible on the first day of hire to full time employees; (Medical - Dental – Vision), Company Life Insurance, Short-Term and Long-Term Disability Insurance, 401(K) Immediate Vesting, Professional Development Assistance, Legal Aid Assistance Program, Family Planning / Fertility Assistance, Personal Time Off, and Observance of Federal Holidays.As a federal contractor, CNI is a drug-free workplace and adheres to the Federal Controlled Substance Act.ESSENTIAL REQUIREMENTSThe ability to obtain, maintain and access classified information at the Public Trust level.Strong understanding of cybersecurity frameworks, access control, endpoint security, and incident response.Experience administering Microsoft Intune and Microsoft Endpoint Manager.Experience with MECM/SCCM administration.Experience implementing Microsoft Security Baselines and CIS Benchmarks.Knowledge of Microsoft Defender for Endpoint.Experience configuring BitLocker, Windows Firewall, ASR rules, Device Control, and endpoint protection policies.Familiarity with Entra ID, Conditional Access, RBAC, and device compliance.Understanding of NIST 800-53, Zero Trust Architecture, and federal cybersecurity requirements.Strong PowerShell scripting experience.Excellent troubleshooting and documentation skills.Preferred QualificationsExperience with Jamf Pro administration.Experience supporting Azure Virtual Desktop environments.Microsoft Intune Administrator Associate (MD-102).Microsoft Security Administrator (SC-300 or equivalent).CISSP, Security+, or similar security certification.Experience supporting HHS, NIH, or other federal agencies.ESSENTIAL DUTIES AND RESPONSIBILITIESEssential Duties and responsibilities include the following. Other duties may be assigned.Engineer and maintain Microsoft Intune Security Baselines, Endpoint Security policies, and Configuration Profiles.Develop and maintain Group Policy, MECM Configuration Baselines, and Jamf security configurations.Implement Microsoft Defender for Endpoint security settings, attack surface reduction (ASR) rules, firewall policies, BitLocker, FileVault, Credential Guard, Application Control, and device encryption policies.Configure compliance policies and Conditional Access dependencies supporting Zero Trust initiatives.Validate security baseline deployments through testing, pilot implementations, and production rollout.Perform impact assessments for Microsoft monthly security baseline updates and recommend adoption strategies.Collaborate with cybersecurity, RMF, ISSO, and engineering teams to ensure endpoint configurations meet organizational security requirements.Develop configuration documentation, implementation guides, rollback procedures, and standard operating procedures.Support vulnerability remediation initiatives through endpoint configuration changes.Troubleshoot policy conflicts between Intune, MECM, Active Directory Group Policy, and Jamf.Participate in change management, CAB reviews, and production implementation activities.Support enterprise modernization initiatives including Autopilot, cloud-native management, and migration from traditional management solutions.EDUCATION AND EXPERIENCEBachelors degree and 4+ years supporting enterprise endpoint management environments.PHYSICAL DEMANDSWork is primarily performed in an office environment. Regularly required to sit. Regularly required use hands to finger, handle, or feel, reach with hands and arms to handle objects and operate tools, computer, and/or controls. Required to speak and hear. Occasionally required to stand, walk and stoop, kneel, crouch, or crawl. Must frequently lift and/or move up to 10 pounds and occasionally lift and/or move up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision, depth perception, and ability to adjust focus. Exposed to general office noise with computers printers and light traffic.The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this job.EOE including Disability/VetThe estimated pay range for this role is $100,000 to $120,000, with the final offer contingent on location, skillset, and experience.CNI offers a comprehensive benefits package that includes:MedicalDentalVision401(k)Family Planning/Fertility AssistanceSTD/LTD/Basic Life/AD&DLegal-Aid ProgramEmployee Assistance Program (EAP)Paid Time Off (PTO)Training and Development OpportunitiesYour application submission will be considered for all potential employment opportunities with Chickasaw Nation Industries (CNI).#INDCNI
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

789 Chickasaw Service Solutions, LLC • Bethesda (MD)

On-site
USD 100,000 - 120,000
Medical Dental Vision
401(k) with vesting
Life Insurance
+2
IT Systems Analyst II
IT Systems Analyst II

Chickasaw Nation Industries • Bethesda (MD)

On-site
USD 95,000 - 120,000
Medical insurance
Dental insurance
Vision insurance
+5
System Administrator
System Administrator

Chickasaw Nation Industries • South Dakota

On-site
USD 70,000 - 100,000
Medical
Dental
Vision
+6
Senior RMF/Information System Security Officer
Senior RMF/Information System Security Officer

Chickasaw Nation Industries • Huntsville (AL)

On-site
USD 120,000 - 160,000
Health benefits (Medical/Dental/Vision
401(k) with immediate vesting
Life Insurance
+5
IT Systems Administrator
IT Systems Administrator

Chickasaw Nation Industries • Huntsville (AL)

On-site
USD 85,000 - 120,000
Medical
Dental
Vision
+4
Information System Security Manager
Information System Security Manager

Chickasaw Nation Industries • South Dakota

On-site
USD 120,000 - 150,000
Medical, Dental, Vision
401(k) Immediate Vesting
Short-Term Disability Insurance
+6
Cyber Security Analyst
Cyber Security Analyst

Chickasaw Nation Industries • South Dakota

On-site
USD 120,000 - 160,000
Medical
Dental
Vision
+2
IT Systems Analyst II
IT Systems Analyst II

789 Chickasaw Service Solutions, LLC • Bethesda (MD)

On-site
USD 95,000 - 120,000
Medical–Dental–Vision
Life Insurance
STD/LTD Insurance
+4
Network Engineer
Network Engineer

Chickasaw Nation Industries • Washington

On-site
USD 85,000 - 125,000
Medical
Dental
Vision
+3
IT Systems Administrator
IT Systems Administrator

Chickasaw Nation Industries, Inc. • Aberdeen (MD)

On-site
USD 90,000 - 120,000
Medical
Dental
Vision
+7