Systems Engineer – Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC)

Leidos

Washington (District of Columbia)

On-site

USD 120,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. The role focuses on securing and maintaining compliance of the Microsoft 365 ecosystem and enterprise endpoints across Windows, macOS, and mobile platforms.

You will lead security governance, implement controls across M365, email, identity, devices, and telemetry, and provide incident response and audit support to ensure alignment with federal requirements.

Qualifications

  • Expert-level Intune engineering across Windows/macOS/iOS/iPadOS.
  • Advanced PowerShell for remediation, automation, and OS image manipulation.
  • Deep experience with Microsoft Defender (XDR, Endpoint, Cloud Apps).
  • Hands-on with Sentinel SIEM, Function Apps, and cross-platform telemetry pipelines.
  • Strong understanding of CAP architecture and identity risk enforcement.
  • Experience with ATO control evidence, compliance mapping, and audit support.

Responsibilities

  • Lead the development, implementation, and ongoing management of M365 security policies, standards, and guardrails aligned to federal requirements and organizational controls.
  • Own governance for data protection capabilities including document classification, labeling, retention, and DLP using Microsoft Purview.
  • Define and enforce email security policies such as encryption, labeling, and secure mail flow to reduce data leakage.
  • Implement and maintain email encryption solutions to protect confidentiality of email communications.
  • Administer and monitor anti-spam, anti-phishing, and anti-malware protections.
  • Engineer and validate device‑compliance‑based Conditional Access policies across Windows, macOS, and mobile platforms.
  • Investigate and remediate Conditional Access failures, identity anomalies, and external/guest access issues.

Skills

Intune engineering
PowerShell scripting
Microsoft Defender
Sentinel SIEM
CAP architecture
ATO evidence & audit support

Tools

Jamf
Okta connectors
Copilot audit logging
Microsoft Graph API
mSCP baseline engineering

Job description

Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role requires a seasoned professional who can strategically manage and enhance the security and compliance posture of the M365 environment within a GCC (Government Community Cloud) tenant, particularly in a federal agency context. The senior engineering role sits at the center of the organization’s device, identity, and M365 security ecosystem. The engineer is responsible for protecting enterprise Windows, macOS, iOS/iPadOS endpoints; ensuring compliant, reliable access to M365 services, and driving rapid engineering responses to vulnerabilities, outages, and operational risks. The successful candidate will possess deep technical expertise, cross‑platform engineering capability, and high operational security judgment.

Role Summary

Responsible for securing and maintaining compliance of the Microsoft 365 (M365) ecosystem and enterprise endpoints. Leads security governance, implements and enforces controls across M365, email, identity, devices, and telemetry, and provides incident response and audit/ATO support to ensure alignment with federal and organizational security requirements.

Primary Responsibilities
  • Lead the development, implementation, and ongoing management of M365 security policies, standards, and technical guardrails aligned to federal requirements and organizational controls.
  • Own governance for data protection capabilities including document classification, labeling, retention, and Data Loss Prevention (DLP) using Microsoft Purview.
  • Define and enforce email security policies such as encryption, sensitivity labeling, and secure mail flow to reduce unauthorized disclosure.
  • Implement and maintain email encryption solutions (S/MIME and/or Microsoft Information Protection) to protect confidentiality of email communications.
  • Administer and monitor anti‑spam, anti‑phishing, and anti‑malware protections to defend against evolving threats.
  • Engineer and validate device‑compliance‑based Conditional Access policies across Windows, macOS, and mobile platforms.
  • Investigate and remediate Conditional Access failures, identity anomalies, and external/guest access issues, including M365 B2B trust and secure partner collaboration requirements.
  • Design, test, and deploy Intune configuration and compliance policies for Windows, macOS, and iOS/iPadOS, including Enrollment Status Pages (ESPs) and OOBE workflows.
  • Develop remediation scripts (PowerShell/platform scripts/configuration profiles) to close compliance gaps and enforce security baselines.
  • Coordinate enterprise rollout of urgent vulnerability mitigations and validated vendor fixes; support vulnerability reviews and baseline rebuilds.
  • Establish and operate a risk management approach to identify, assess, and mitigate security risks across the M365 ecosystem.
  • Support ATO/control assessment activities by drafting implementation statements, collecting artifacts, and providing evidence aligned to audit/logging requirements.
  • Lead integration and operational management of Microsoft Defender and Microsoft Sentinel for threat detection, alerting, and response across M365.
  • Build and maintain SIEM integrations/connectors and develop ingestion pipelines for third‑party logs.
  • Tune audit retention, analytic rules, and alert logic to improve signal quality and investigation readiness.
  • Provide Tier 3 troubleshooting for device compliance failures, identity/access incidents, telemetry gaps, and OS/app protection issues.
  • Partner with cross‑functional teams to align security solutions with business objectives, deliver technical leadership, and support enterprise syncs and operational reviews.
  • Stay current on M365 security/compliance updates, industry trends, and emerging capabilities; drive improvements to security posture and operational efficiency.
Day in the Life
Morning
  • Review Sentinel incidents, Defender telemetry gaps, and compliance drift.
  • Respond to overnight CAP failures, Slack EMM issues, or OS update regressions.
  • Join device/enterprise standups.
Midday
  • Build/test remediation scripts (CVE fixes, NTLM disablement, compliance corrections).
  • Deploy or test Intune configuration profiles, ESP changes, or app protection updates.
  • Troubleshoot support cases with Microsoft (Purview DSPM, Copilot logs, Okta connector).
Afternoon
  • Conduct cross‑team investigations (external‑user access anomalies, Teams meeting forensics).
  • Validate CAP behaviors across platforms using test devices.
  • Work on ATO evidence packages and documentation.
End of Day
  • Update Jira tasks, Confluence documentation, and CR submissions.
  • Send status updates on active investigations, mitigations, and test results.
Required Qualifications
Technical Skills
  • Expert‑level Intune engineering across Windows/macOS/iOS/iPadOS.
  • Advanced PowerShell for remediation, automation, and OS image manipulation.
  • Deep experience with Microsoft Defender (XDR, Endpoint, Cloud Apps).
  • Hands‑on with Sentinel SIEM, Function Apps, and cross‑platform telemetry pipelines.
  • Strong understanding of CAP architecture and identity risk enforcement.
  • Experience with ATO control evidence, compliance mapping, and audit support.
Soft Skills
  • Growth mindset and willingness to learn emerging security domains.
  • Strong cross‑team collaboration (Cyber, Ops, EA, ICAM, Comms).
  • Excellent communication—clear summaries, user‑impact translation, and documentation.
  • High reliability, ownership, and situational awareness during high‑severity events.
Preferred Qualifications
  • Prior experience in federal security, high‑compliance, or high‑assurance environments.
  • Experience with Jamf, Okta connectors, Copilot audit logging, Graph API operations.
  • Experience with mSCP baseline engineering and macOS security hardening.
  • Prior involvement in enterprise‑wide Conditional Access enforcement.
Commitment to Non‑Discrimination

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Systems Engineer - Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC)
Systems Engineer - Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC)

Leidos • Washington

On-site
USD 107,000 - 196,000
Systems Engineer - Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC)
Systems Engineer - Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC)

Stryker Corporation • Washington

On-site
Confidential
Health insurance
Endpoint Engineering and Collaboration Services Manager
Endpoint Engineering and Collaboration Services Manager

Leidos • Maryland

On-site
USD 140,000 - 190,000
Endpoint Engineering and Collaboration Services Manager
Endpoint Engineering and Collaboration Services Manager

Leidos LLC • Rockville (MD)

On-site
USD 150,000 - 190,000
Senior M365 Security & Compliance Engineer
Senior M365 Security & Compliance Engineer

Leidos • Washington

On-site
USD 120,000 - 170,000
Endpoint Engineering and Collaboration Services Manager
Endpoint Engineering and Collaboration Services Manager

Leidos Inc • Rockville (MD)

Hybrid
USD 131,000 - 238,000
Senior M365 Security & Endpoint Engineer (GCC)
Senior M365 Security & Endpoint Engineer (GCC)

Leidos • Washington

On-site
USD 107,000 - 196,000
Endpoint Engineering and Collaboration Services Manager
Endpoint Engineering and Collaboration Services Manager

COMFORT SYSTEMS • Rockville (MD)

On-site
USD 131,000 - 238,000
M365 Power Platform Developer
M365 Power Platform Developer

Leidos • Virginia (IL)

Hybrid
USD 87,000 - 157,000
M365 Power Platform Developer
M365 Power Platform Developer

Leidos • United States

Remote
USD 87,000 - 157,000