Systems Engineer – Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC)

Leidos

United States

On-site

USD 108,000 - 195,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Leidos in the United States seeks a senior security engineer to secure and govern the M365 ecosystem and enterprise endpoints across identity, devices, and telemetry.

You will lead controls, incident response, and audit support, designing Intune and Entra ID policies, and coordinating with cross‑functional teams to meet federal requirements.

Qualifications

  • Bachelor's degree required; 8+ years of security experience; 4 additional years may substitute for degree.
  • Deep experience with M365 Defender, Endpoint, and Cloud Apps.
  • Hands-on with Sentinel SIEM and telemetry pipelines; strong Intune engineering across Windows/macOS/iOS.
  • Advanced PowerShell for remediation, automation, and OS image manipulation.
  • Strong understanding of CAP architecture and identity risk enforcement.
  • Experience with ATO control evidence, compliance mapping, and audit support.

Responsibilities

  • Lead development, implementation, and management of M365 security policies and guardrails.
  • Own governance for data protection: classification, labeling, retention, and DLP with Purview.
  • Define and enforce email security policies for Exchange Online and shield mail flow.
  • Engineer identity/access/conditional access across Entra ID for multiple platforms.
  • Design and deploy Intune policies, ESPs, and remediation scripts to close gaps.
  • Coordinate vulnerability mitigations and vendor fixes across enterprise rollout.
  • Lead security monitoring, SIEM integrations, and telemetry engineering for threat detection and response.
  • Provide Tier 3 incident response support and cross-team collaboration.

Skills

Microsoft Defender
Sentinel SIEM
Intune engineering
PowerShell scripting
Identity risk enforcement
ATO evidence

Education

Bachelor's Degree

Tools

Jamf
Okta connectors
Copilot audit logging
Graph API operations
macOS security hardening

Job description

Role Summary

Responsible for securing and maintaining compliance of the Microsoft 365 (M365) ecosystem and enterprise endpoints. Leads security governance, implements and enforces controls across M365, email, identity, devices, and telemetry, and provides incident response and audit/ATO support to ensure alignment with federal and organizational security requirements.

Must meet the following qualifications

Bachelors Degree and 8+ years of experience. 4 additional years of experience may be substituted in lieu of degree.

Candidate MUST

be a US Citizen or US Person with the ability to obtain a Public Trust level 5 clearance.

Required Qualifications Technical Skills

Deep experience with Microsoft Defender (XDR, Endpoint, Cloud Apps). Hands-on with Sentinel SIEM, and cross-platform telemetry pipelines. Expert-level Intune engineering across Windows/macOS/iOS/iPadOS. Advanced PowerShell for remediation, automation, and OS image manipulation. Strong understanding of CAP architecture and identity risk enforcement. Experience with ATO control evidence, compliance mapping, and audit support.

Soft Skills

Growth mindset and willingness to learn emerging security domains. Strong cross-team collaboration (Cyber, Ops, EA, ICAM, Comms). Excellent communication—clear summaries, user-impact translation, and documentation. High reliability, ownership, and situational awareness during high-severity events.

Preferred Qualifications

Prior experience in federal security, high-compliance, or high‑assurance environments. Experience with Jamf, Okta connectors, Copilot audit logging, Graph API operations. Experience with mSCP baseline engineering and macOS security hardening. Prior involvement in enterprise-wide Conditional Access enforcement.

Primary Responsibilities

Strategic security oversight & governance Lead the development, implementation, and ongoing management of M365 security policies, standards, and technical guardrails aligned to federal requirements and organizational controls. Own governance for data protection capabilities including document classification, labeling, retention, and Data Loss Prevention (DLP) using Microsoft Purview.

Email security & compliance management (Exchange Online) Define and enforce email security policies such as encryption, sensitivity labeling, and secure mail flow to reduce unauthorized disclosure. Implement and maintain email encryption solutions (S/MIME and/or Microsoft Information Protection) to protect confidentiality of email communications. Administer and monitor anti-spam, anti-phishing, and anti-malware protections to defend against evolving threats.

Identity, access, and conditional access (Entra ID) Engineer and validate device-compliance–based Conditional Access policies across Windows, macOS, and mobile platforms. Investigate and remediate Conditional Access failures, identity anomalies, and external/guest access issues, including M365 B2B trust and secure partner collaboration requirements.

Endpoint & device security engineering (Intune) Design, test, and deploy Intune configuration and compliance policies for Windows, macOS, and iOS/iPadOS, including Enrollment Status Pages (ESPs) and OOBE workflows. Develop remediation scripts (PowerShell/platform scripts/configuration profiles) to close compliance gaps and enforce security baselines. Coordinate enterprise rollout of urgent vulnerability mitigations and validated vendor fixes; support vulnerability reviews and baseline rebuilds.

Risk management & compliance assurance (ATO / controls) Establish and operate a risk management approach to identify, assess, and mitigate security risks across the M365 ecosystem. Support ATO/control assessment activities by drafting implementation statements, collecting artifacts, and providing evidence aligned to audit/logging requirements.

Security monitoring, SIEM, and telemetry engineering (Defender / Sentinel) Lead integration and operational management of Microsoft Defender and Microsoft Sentinel for threat detection, alerting, and response across M365. Build and maintain SIEM integrations/connectors (e.g., M365, collaboration and identity systems) and develop ingestion pipelines (e.g., Azure Function Apps) for third-party logs. Tune audit retention, analytic rules, and alert logic to improve signal quality and investigation readiness.

Incident response & operational support / collaboration Provide Tier 3 troubleshooting for device compliance failures, identity/access incidents, telemetry gaps, and OS/app protection issues. Partner with cross-functional teams to align security solutions with business objectives, deliver technical leadership, and support enterprise syncs and operational reviews.

Continuous improvement & innovation Stay current on M365 security/compliance updates, industry trends, and emerging capabilities; drive improvements to security posture and operational efficiency (including use of GCC Copilot where appropriate).

Platform Scope / Tooling

Microsoft 365 (GCC), Microsoft Purview (DLP/labels/classification/retention), Exchange Online, Entra ID & Conditional Access, Microsoft Intune, Microsoft Defender, Microsoft Sentinel, Azure (Function Apps / Log Analytics), plus integrations with collaboration/IT systems (e.g., ticketing and SaaS log sources).

Day in the Life

Morning Review Sentinel incidents, Defender telemetry gaps, and compliance drift. Respond to overnight CAP failures, Slack EMM issues, or OS update regressions. Join device/enterprise standups. Midday Build/test remediation scripts (CVE fixes, NTLM disablement, compliance corrections). Deploy or test Intune configuration profiles, ESP changes, or app protection updates. Troubleshoot support cases with Microsoft (Purview DSPM, Copilot logs, Okta connector). Afternoon Conduct cross-team investigations (external-user access anomalies, Teams meeting forensics). Validate CAP behaviors across platforms using test devices. Work on ATO evidence packages and documentation. End of Day Update Jira tasks, Confluence documentation, and CR submissions. Send status updates on active investigations, mitigations, and test results.

Please Note

Please be advised that if you are moved to the interview stage, during the interview you will be required to keep your camera on, and your interviewer will be taking your picture for identification purposes if an offer letter is extended to you If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

Original Posting

August 26, 2026 For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range

Pay Range $107,900.00 - $195,050.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $17.2 billion for the fiscal year ended January 2, 2026. For more information, visit www.Leidos.com.

Pay and Benefits

Pay and benefits are fundamental to any career decision. That's why we craft employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available here.

Securing Your Data

Leidos will never ask you to provide payment-related information at any part of the employment application process. And Leidos will communicate with you only through emails that are sent from a Leidos.com email address. If you receive an email purporting to be from Leidos that asks for payment-related information or any other personal information, please report the email to spam.leidos@leidos.com.

Commitment and Diversity

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Systems Engineer – Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC)
Systems Engineer – Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC)

Leidos LLC • United States

Remote
USD 108,000 - 195,000
Health and Wellness programs
Income Protection
Paid Leave and Retirement
Endpoint Engineering and Collaboration Services Manager
Endpoint Engineering and Collaboration Services Manager

Leidos LLC • Rockville (MD)

Hybrid
USD 142,000 - 237,000
Junior Security Engineer
Junior Security Engineer

Leidos Inc • Bethesda (MD)

On-site
USD 70,000 - 126,000
DevOps Engineer
DevOps Engineer

Leidos LLC • Washington

On-site
USD 108,000 - 195,000
Health and Wellness programs
Paid Leave
Retirement benefits
Defensive Cybersecurity Analyst
Defensive Cybersecurity Analyst

Leidos LLC • Whitehall (OH)

On-site
USD 70,000 - 126,000
Security Engineer / IT Help Desk Technician
Security Engineer / IT Help Desk Technician

Leidos LLC • Brookmont (MD)

On-site
USD 58,000 - 105,000
DevSecOps Engineer
DevSecOps Engineer

Leidos LLC • Oklahoma City (OK)

On-site
USD 87,000 - 157,000
Competitive compensation
Health and Wellness programs
Income protection
+1
Software Engineer - Mid Level
Software Engineer - Mid Level

Leidos LLC • Clarksburg (WV)

On-site
USD 70,000 - 126,000
Health and Wellness programs
Competitive compensation
Income Protection
+1
Systems Administrator
Systems Administrator

Leidos LLC • Virginia (MN)

On-site
USD 73,000 - 133,000
Cyber Engineer
Cyber Engineer

Leidos LLC • Bath Township (OH)

On-site
USD 87,000 - 157,000
Competitive compensation
Health and Wellness programs
Income protection
+2