Systems Engineer β Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC)
Senior
Azure
Azure Government
Cloud
Cloud Platform
Cloud Platforms
Cybersecurity Tools
Data Security
Device Management
Endpoint Security
Identity and Access Management
Information Security
Information Technology (IT)
InfoSec
Microsoft 365
Microsoft Intune
Mobile Device Management
Office 365
Risk Governance
Risk Management
Security
Security Compliance
Security Information And Event Management
Job Description
Leidos is seeking a Senior Systems Engineer to secure and maintain compliance of Microsoft 365 and enterprise endpoints within a GCC tenant, leading governance, identity and device security, incident response, and risk management.
Responsibilities
- Lead the development, implementation, and ongoing management of M365 security policies, standards, and technical guardrails aligned to federal requirements and organizational controls.
- Own governance for data protection capabilities including document classification, labeling, retention, and Data Loss Prevention using Microsoft Purview.
- Define and enforce email security policies such as encryption, sensitivity labeling, and secure mail flow to reduce unauthorized disclosure.
- Implement and maintain email encryption solutions (S/MIME and/or Microsoft Information Protection) to protect confidentiality of email communications.
- Administer and monitor anti-spam, anti-phishing, and anti-malware protections to defend against evolving threats.
- Engineer and validate device-compliance based Conditional Access policies across Windows, macOS, and mobile platforms.
- Investigate and remediate Conditional Access failures, identity anomalies, and external/guest access issues, including M365 B2B trust and secure partner collaboration requirements.
- Design, test, and deploy Intune configuration and compliance policies for Windows, macOS, and iOS/iPadOS, including Enrollment Status Pages and OOBE workflows.
- Develop remediation scripts (PowerShell and platform scripts) to close compliance gaps and enforce security baselines.
- Coordinate enterprise rollout of urgent vulnerability mitigations and validated vendor fixes.
- Support vulnerability reviews and baseline rebuilds.
- Establish and operate a risk management approach to identify, assess, and mitigate security risks across the M365 ecosystem.
- Support ATO control assessment activities by drafting implementation statements, collecting artifacts, and providing evidence aligned to audit and logging requirements.
- Lead integration and operational management of Microsoft Defender and Microsoft Sentinel for threat detection, alerting, and response across M365.
- Build and maintain SIEM integrations and ingestion pipelines for third-party logs (e.g., M365, collaboration and identity systems), including Azure Function Apps.
- Tune audit retention, analytic rules, and alert logic to improve signal quality and investigation readiness.
- Provide Tier 3 troubleshooting for device compliance failures, identity and access incidents, telemetry gaps, and OS or application protection issues.
- Partner with cross-functional teams to align security solutions with business objectives, deliver technical leadership, and support enterprise syncs and operational reviews.
- Stay current on Microsoft 365 security and compliance updates, industry trends, and emerging capabilities, driving improvements to security posture and operational efficiency, including the use of GCC Copilot where appropriate.
Requirements
- Expert-level Intune engineering across Windows, macOS, iOS, and iPadOS.
- Advanced PowerShell for remediation, automation, and OS image manipulation.
- Deep experience with Microsoft Defender (XDR, Endpoint, Cloud Apps).
- Hands-on with Sentinel SIEM, Function Apps, and cross-platform telemetry pipelines.
- Strong understanding of CAP architecture and identity risk enforcement.
- Experience with ATO control evidence, compliance mapping, and audit support.
- Growth mindset and willingness to learn emerging security domains.
- Strong cross-team collaboration with Cyber, Operations, Enterprise Architecture, ICAM, and Communications.
- Excellent communication including clear summaries, user-impact translation, and documentation.
- High reliability, ownership, and situational awareness during high-severity events.
Technologies
- Microsoft 365 (GCC)
- Microsoft Purview
- Exchange Online
- Entra ID
- Conditional Access
- Microsoft Intune
- Microsoft Defender
- Microsoft Sentinel
- Azure Function Apps
- Azure Log Analytics
- PowerShell
- S/MIME
- Microsoft Information Protection
- Graph API operations
- Okta connectors
- Jamf
Benefits
- Competitive compensation
- Health and Wellness programs
- Income Protection
- Paid Leave
- Retirement
Day in the Life
- Morning: Review Sentinel incidents, Defender telemetry gaps, and compliance drift; respond to overnight CAP failures, Slack EMM issues, or OS update regressions; join device and enterprise standups.
- Midday: Build and test remediation scripts for CVE fixes, NTLM disablement, or compliance corrections; deploy or test Intune configuration profiles, ESP changes, or app protection updates; troubleshoot support cases with Microsoft Purview DSPM, Copilot logs, or Okta connectors.
- Afternoon: Conduct cross-team investigations of external-user access anomalies and Teams forensics; validate CAP behaviors across platforms on test devices; work on ATO evidence packages and documentation.
- End of Day: Update Jira tasks, Confluence documentation, and change requests; provide status updates on active investigations, mitigations, and test results.