Systems Engineer – Microsoft 365 Security & Compliance / Endpoint Security Engineer @Leidos
Information Technology
Salary usd 107,900 - 1..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted YDay

[Hiring] Systems Engineer – Microsoft 365 Security & Compliance / Endpoint Security Engineer @Leidos

YDay - Leidos is hiring a remote Systems Engineer – Microsoft 365 Security & Compliance / Endpoint Security Engineer. 💸 Salary: usd 107,900 - 195,050 per year 📍Location: USA

Role Description

Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role requires a seasoned professional who can strategically manage and enhance the security and compliance posture of the M365 environment within a GCC (Government Community Cloud) tenant, particularly in a federal agency context. This senior engineering role sits at the center of the organization’s device, identity, and M365 security ecosystem. The engineer is responsible for protecting enterprise Windows, macOS, iOS/iPadOS endpoints; ensuring compliant, reliable access to M365 services, and driving rapid engineering responses to vulnerabilities, outages, and operational risks. The successful candidate will apply deep technical expertise, cross-platform engineering capability, and high operational security judgment.

Role Summary: Responsible for securing and maintaining compliance of the Microsoft 365 (M365) ecosystem and enterprise endpoints. Leads security governance, implements and enforces controls across M365, email, identity, devices, and telemetry, and provides incident response and audit/ATO support to ensure alignment with federal and organizational security requirements.

Qualifications

  • Bachelors Degree and 8+ years of experience. 4 additional years of experience may be substituted in lieu of degree.
  • Candidate MUST be a US Citizen or US Person with the ability to obtain a Public Trust level 5 clearance.

Requirements

  • Deep experience with Microsoft Defender (XDR, Endpoint, Cloud Apps).
  • Hands-on with Sentinel SIEM, and cross-platform telemetry pipelines.
  • Expert-level Intune engineering across Windows/macOS/iOS/iPadOS.
  • Advanced PowerShell for remediation, automation, and OS image manipulation.
  • Strong understanding of CAP architecture and identity risk enforcement.
  • Experience with ATO control evidence, compliance mapping, and audit support.

Preferred Qualifications

  • Prior experience in federal security, high-compliance, or high‑assurance environments.
  • Experience with Jamf, Okta connectors, Copilot audit logging, Graph API operations.
  • Experience with mSCP baseline engineering and macOS security hardening.
  • Prior involvement in enterprise-wide Conditional Access enforcement.

Primary Responsibilities

  • Lead the development, implementation, and ongoing management of M365 security policies, standards, and technical guardrails aligned to federal requirements and organizational controls.
  • Own governance for data protection capabilities including document classification, labeling, retention, and Data Loss Prevention (DLP) using Microsoft Purview.
  • Define and enforce email security policies such as encryption, sensitivity labeling, and secure mail flow to reduce unauthorized disclosure.
  • Implement and maintain email encryption solutions (S/MIME and/or Microsoft Information Protection) to protect confidentiality of email communications.
  • Administer and monitor anti-spam, anti-phishing, and anti-malware protections to defend against evolving threats.
  • Engineer and validate device-compliance–based Conditional Access policies across Windows, macOS, and mobile platforms.
  • Investigate and remediate Conditional Access failures, identity anomalies, and external/guest access issues, including M365 B2B trust and secure partner collaboration requirements.
  • Design, test, and deploy Intune configuration and compliance policies for Windows, macOS, and iOS/iPadOS, including Enrollment Status Pages (ESPs) and OOBE workflows.
  • Develop remediation scripts (PowerShell/platform scripts/configuration profiles) to close compliance gaps and enforce security baselines.
  • Coordinate enterprise rollout of urgent vulnerability mitigations and validated vendor fixes; support vulnerability reviews and baseline rebuilds.
  • Establish and operate a risk management approach to identify, assess, and mitigate security risks across the M365 ecosystem.
  • Support ATO/control assessment activities by drafting implementation statements, collecting artifacts, and providing evidence aligned to audit/logging requirements.
  • Lead integration and operational management of Microsoft Defender and Microsoft Sentinel for threat detection, alerting, and response across M365.
  • Build and maintain SIEM integrations/connectors (e.g., M365, collaboration and identity systems) and develop ingestion pipelines (e.g., Azure Function Apps) for third-party logs.
  • Tune audit retention, analytic rules, and alert logic to improve signal quality and investigation readiness.
  • Provide Tier 3 troubleshooting for device compliance failures, identity/access incidents, telemetry gaps, and OS/app protection issues.
  • Partner with cross-functional teams to align security solutions with business objectives, deliver technical leadership, and support enterprise syncs and operational reviews.
  • Stay current on M365 security/compliance updates, industry trends, and emerging capabilities; drive improvements to security posture and operational efficiency (including use of GCC Copilot where appropriate).

Pay Range

Pay Range $107,900.00 - $195,050.00. The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Before You Apply
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Systems Engineer – Microsoft 365 Security & Compliance / Endpoint Security Engineer @Leidos
Information Technology
Salary usd 107,900 - 1..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted YDay
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 126,886+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later