Security Engineer – Microsoft Security

B5 Recruiting

Washington (District of Columbia)

On-site

USD 140,000 - 180,000

Full time

44 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

B5 Recruiting is partnering with a client in Washington, DC to hire an experienced Security Engineer to mature the Microsoft security ecosystem across endpoints, cloud, identities, and email. You will configure Defender XDR, Purview, and Cloud security controls while aligning with governance, compliance, and audit teams.

The role emphasizes hands-on Defender for Endpoint, Defender for Cloud, and Sentinel integrations, telemetry-driven security, and operational readiness.

Qualifications

  • Hands-on experience with Microsoft Defender XDR and the Microsoft security ecosystem.
  • Experience implementing or administering Microsoft Defender for Endpoint, including ASR policies.
  • Practical knowledge of Microsoft Purview and Data Loss Prevention controls.
  • Experience with Microsoft Defender for Cloud and Azure security/compliance controls.

Responsibilities

  • Configure and expand Microsoft Purview Data Loss Prevention controls across endpoints, Microsoft 365 environments, email, and cloud apps.
  • Review policy coverage and identify gaps that could create compliance or data protection risks.
  • Translate organizational requirements into practical DLP controls with governance and compliance stakeholders.
  • Support ongoing policy tuning, monitoring, and audit preparation.
  • Configure and implement Defender for Endpoint security controls, including ASR policies.
  • Evaluate security controls against prioritized threat scenarios and cybersecurity frameworks.
  • Tune endpoint policies to balance security with business operations.
  • Integrate endpoint telemetry with Microsoft Sentinel for improved investigations.
  • Modernize Azure security and compliance monitoring using telemetry-driven controls.
  • Configure Defender for Cloud across IaaS and PaaS environments.
  • Maintain cloud security policies aligned with standards and regulatory frameworks (FedRAMP-related controls).
  • Use Azure governance tools like Azure Policy, Secure Score, and automated remediation.
  • Help design and maintain an integrated Microsoft security environment across Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, Defender for Servers, and Sentinel.
  • Improve visibility and correlation of security events across endpoints, identities, cloud, and collaboration environments.
  • Support the use and configuration of Copilot for Security to enhance SOC investigations and responses.
  • Assist with testing, troubleshooting, and optimization of integrations across the Microsoft security stack.
  • Develop documentation, procedures, and operational playbooks for newly implemented security capabilities.
  • Partner with SOC and cybersecurity teams to transition solutions into steady-state operations.
  • Provide knowledge transfer and training on new controls, dashboards, and investigation workflows.
  • Support audit, compliance, and security teams with evidence collection and control validation.

Skills

Microsoft Defender XDR
Microsoft Purview
Defender for Endpoint
Defender for Cloud
Azure security
Microsoft Sentinel
Governance & Compliance collaboration
Audit readiness

Tools

Azure Policy
Secure Score
Copilot for Security
Microsoft Defender for Cloud Apps
SIEM integrations

Job description

Overview

B5 Recruiting is partnering with a client seeking an experienced Security Engineer to support the implementation and maturation of its Microsoft security ecosystem.

This position will play a key role in strengthening enterprise security controls across endpoints, cloud infrastructure, identities, email, and business applications. The engineer will be responsible for configuring and integrating Microsoft security technologies, improving compliance visibility, and helping transition newly implemented controls into day-to-day security operations.

The ideal candidate brings strong hands‑on experience with Microsoft Defender XDR, Microsoft Purview, Defender for Endpoint, Defender for Cloud, Azure security, and Microsoft Sentinel, along with the ability to work cross‑functionally with security operations, governance, compliance, and audit teams.

Key Responsibilities:
Microsoft Purview & Data Protection:
  • Configure and expand Microsoft Purview Data Loss Prevention controls across endpoints, Microsoft 365 environments, email, and supported cloud applications.
  • Review policy coverage and identify potential gaps that could create compliance or data protection risks.
  • Partner with governance and compliance stakeholders to translate organizational requirements into practical DLP controls.
  • Support ongoing policy tuning, monitoring, and audit preparation.
Endpoint Security & Threat Prevention:
  • Configure and implement Microsoft Defender for Endpoint security controls, including Attack Surface Reduction (ASR) rules.
  • Evaluate security controls against prioritized threat scenarios and established cybersecurity frameworks.
  • Tune endpoint policies to balance security effectiveness with business operations and minimize unnecessary alerts or disruptions.
  • Connect endpoint telemetry and alerts with Microsoft Sentinel to improve investigation and incident‑response workflows.
Azure & Cloud Security:
  • Support the modernization of Azure security and compliance monitoring using telemetry‑driven controls and reporting.
  • Configure Microsoft Defender for Cloud across IaaS and PaaS environments.
  • Maintain cloud security policies aligned with organizational security standards and applicable regulatory frameworks, including FedRAMP‑related controls.
  • Use Azure governance capabilities such as Azure Policy, Secure Score, and automated remediation to improve security posture and reduce manual intervention.
Microsoft Defender XDR Integration:
  • Help design and maintain an integrated Microsoft security environment across technologies such as:

    • Microsoft Defender for Endpoint
    • Microsoft Defender for Identity
    • Microsoft Defender for Office 365
    • Microsoft Defender for Cloud Apps
    • Microsoft Defender for Servers
    • Microsoft Sentinel
  • Improve visibility and correlation of security events across endpoint, identity, cloud, and collaboration environments.
  • Support the use and configuration of Microsoft Copilot for Security to improve SOC investigation and response workflows.
  • Assist with testing, troubleshooting, and optimization of integrations across the Microsoft security stack.
Operational Readiness & Knowledge Transfer:
  • Develop documentation, procedures, and operational playbooks for newly implemented security capabilities.
  • Partner with SOC and cybersecurity teams to transition solutions from implementation into steady‑state operations.
  • Provide knowledge transfer and training to security personnel on new controls, features, dashboards, and investigation workflows.
  • Support audit, compliance, and security teams with evidence collection and control validation when required.
What We’re Looking For:
  • U.S. Citizenship required.
  • Must reside within reasonable commuting distance of Washington, DC.
  • Strong hands‑on experience with Microsoft Defender XDR and the Microsoft security ecosystem.
  • Experience implementing or administering Microsoft Defender for Endpoint, including ASR policies.
  • Practical knowledge of Microsoft Purview and Data Loss Prevention controls.
  • Experience with Microsoft Defender for Cloud and Azure security/compliance controls.
  • Familiarity with Microsoft Sentinel, SIEM integrations, security monitoring, and incident response.
  • Understanding of Azure governance and security technologies such as Azure Policy and Secure Score.
  • Experience working in environments with formal security, regulatory, or audit requirements.
  • Ability to document technical processes and collaborate with SOC, cybersecurity, compliance, governance, and audit stakeholders.

Experience with FedRAMP, FERC‑related security requirements, Microsoft Copilot for Security, or large enterprise Microsoft security deployments would be highly valuable.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer, Data
Security Engineer, Data

Applied Systems • Indiana (PA)

On-site
USD 120,000 - 170,000
Snr Cybersecurity Consultant Engineer (Architecture, Infrastructure and Remediation)
Snr Cybersecurity Consultant Engineer (Architecture, Infrastructure and Remediation)

LevelBlue • United States

On-site
USD 120,000 - 160,000
Senior Microsoft Security Administrator
Senior Microsoft Security Administrator

Accelera Solutions • Virginia (MN)

Hybrid
USD 110,000 - 140,000
Azure Security Engineer
Azure Security Engineer

Zeektek • Sacramento (CA)

On-site
USD 140,000 - 170,000
Snr Cybersecurity Consultant Engineer (Architecture, Infrastructure and Remediation)
Snr Cybersecurity Consultant Engineer (Architecture, Infrastructure and Remediation)

LevelBlue, LLC. • Northern (KY)

Hybrid
USD 120,000 - 180,000
Security Engineer
Security Engineer

Govserviceshub • Atlanta (GA)

On-site
USD 110,000 - 150,000
Sr. Cybersecurity Engineering Consultant - SIEM/Microsoft (AIR)
Sr. Cybersecurity Engineering Consultant - SIEM/Microsoft (AIR)

Trustwave • United States

On-site
USD 140,000 - 190,000
Sr. Cybersecurity Engineering Consultant - SIEM/Microsoft (AIR)
Sr. Cybersecurity Engineering Consultant - SIEM/Microsoft (AIR)

LevelBlue, LLC. • Northern (KY)

Hybrid
USD 120,000 - 190,000
Senior Security Engineer
Senior Security Engineer

KYZEN Corporation • Nashville (TN)

On-site
USD 90,000 - 130,000
Principal Engineer/Microsoft Endpoint for Defender Enterprise
Principal Engineer/Microsoft Endpoint for Defender Enterprise

Fuse Engineering • Fort Meade (MD)

On-site
USD 150,000 - 200,000