Systems Engineer – Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC)
Compensation
$108k – $195k /yr
Employment type
Full-time
Work setting
On-site
Location
College Park, MD
Schedule
Day shift
Posted
You'll be redirected to the employer's application page.
Job overview
Systems Engineer – Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC) in College Park, MD. This is an onsite role. The pay range is $107,900.00 - $195,050.00 per year. Leidos is seeking an experienced M365 Security and Compliance Administrator to join their Information Technology team. This senior engineering role is responsible for securing and maintaining compliance of the Microsoft 365 (M365) ecosystem and enterprise endpoints, leading security governance, and implementing controls across M365, email, identity, devices, and telemetry.
What you'll do
- Lead the development, implementation, and ongoing management of M365 security policies, standards, and technical guardrails aligned to federal requirements and organizational controls. Own governance for data protection capabilities including document classification, labeling, retention, and Data Loss Prevention (DLP) using Microsoft Purview. Define and enforce email security policies such as encryption, sensitivity labeling, and secure mail flow to reduce unauthorized disclosure. Implement and maintain email encryption solutions (S/MIME and/or Microsoft Information Protection) to protect confidentiality of email communications. Administer and monitor anti-spam, anti-phishing, and anti-malware protections to defend against evolving threats. Engineer and validate device-compliance–based Conditional Access policies across Windows, macOS, and mobile platforms. Investigate and remediate Conditional Access failures, identity anomalies, and external/guest access issues, including M365 B2B trust and secure partner collaboration requirements. Design, test, and deploy Intune configuration and compliance policies for Windows, macOS, and iOS/iPadOS, including Enrollment Status Pages (ESPs) and OOBE workflows. Develop remediation scripts (PowerShell/platform scripts/configuration profiles) to close compliance gaps and enforce security baselines. Coordinate enterprise rollout of urgent vulnerability mitigations and validated vendor fixes
- support vulnerability reviews and baseline rebuilds. Establish and operate a risk management approach to identify, assess, and mitigate security risks across the M365 ecosystem. Support ATO/control assessment activities by drafting implementation statements, collecting artifacts, and providing evidence aligned to audit/logging requirements. Lead integration and operational management of Microsoft Defender and Microsoft Sentinel for threat detection, alerting, and response across M365. Build and maintain SIEM integrations/connectors (e.g., M365, collaboration and identity systems) and develop ingestion pipelines (e.g., Azure Function Apps) for third-party logs. Tune audit retention, analytic rules, and alert logic to improve signal quality and investigation readiness. Provide Tier 3 troubleshooting for device compliance failures, identity/access incidents, telemetry gaps, and OS/app protection issues. Partner with cross-functional teams to align security solutions with business objectives, deliver technical leadership, and support enterprise syncs and operational reviews. Stay current on M365 security/compliance updates, industry trends, and emerging capabilities
- drive improvements to security posture and operational efficiency (including use of GCC Copilot where appropriate).
What we're looking for
- Education
- Bachelor’s degree in computer science, Information Systems, or equivalent. Six (6) years of additional experience is considered equivalent in lieu of a Bachelors degree. With a Master’s degree, six (6) years of general experience is acceptable. With a PhD, four (4) years of general experience is required.
- Experience
- Expert-level Intune engineering across Windows/macOS/iOS/iPadOS. Advanced PowerShell for remediation, automation, and OS image manipulation. Deep experience with Microsoft Defender (XDR, Endpoint, Cloud Apps). Hands-on with Sentinel SIEM, Function Apps, and cross-platform telemetry pipelines. Strong understanding of CAP architecture and identity risk enforcement. Experience with ATO control evidence, compliance mapping, and audit support.
- Skills & competencies
- systems engineermicrosoft 365m365gccsecuritycomplianceendpoint securityintunemicrosoft defendermicrosoft sentinelentra idconditional accesscollege park mdinformation technologyfull-timeonsitepublic trust clearance
Benefits & perks
- competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement
About the employer
Leidos is hiring for this role. Industry: Computer Systems Design Services. Sector: 54.
Additional details
- Industry sector
- 54
- Industry
- Computer Systems Design Services
- Occupation code
- 15-1299.05
You'll be redirected to the employer's application page.
Listing ID: 6306240c-a199-4979-9be1-8f501db4c5de