Systems Engineer - Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC)
$107.9k - $195.05kLeidos
Description
Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role requires a seasoned professional who can strategically manage and enhance the security and compliance posture of the M365 environment within a GCC (Government Community Cloud) tenant, particularly in a federal agency context. This senior engineering role sits at the center of the organization’s device, identity, and M365 security ecosystem. The engineer is responsible for protecting enterprise Windows, macOS, iOS/iPadOS endpoints; ensuring compliant, reliable access to M365 services, and driving rapid engineering responses to vulnerabilities, outages, and operational risks. The successful candidate will apply with deep technical expertise, cross-platform engineering capability, and high operational security judgment.
Role Summary: Responsible for securing and maintaining compliance of the Microsoft 365 (M365) ecosystem and enterprise endpoints. Leads security governance, implements and enforces controls across M365, email, identity, devices, and telemetry, and provides incident response and audit/ATO support to ensure alignment with federal and organizational security requirements.
Primary Responsibilities
Strategic security oversight & governance
Lead the development, implementation, and ongoing management of M365 security policies, standards, and technical guardrails aligned to federal requirements and organizational controls.
Own governance for data protection capabilities including document classification, labeling, retention, and Data Loss Prevention (DLP) using Microsoft Purview.
Email security & compliance management (Exchange Online)
Define and enforce email security policies such as encryption, sensitivity labeling, and secure mail flow to reduce unauthorized disclosure.
Implement and maintain email encryption solutions (S/MIME and/or Microsoft Information Protection) to protect confidentiality of email communications.
Administer and monitor anti-spam, anti-phishing, and anti-malware protections to defend against evolving threats.
Identity, access, and conditional access (Entra ID)
Engineer and validate device-compliance–based Conditional Access policies across Windows, macOS, and mobile platforms.
Investigate and remediate Conditional Access failures, identity anomalies, and external/guest access issues, including M365 B2B trust and secure partner collaboration requirements.
Endpoint & device security engineering (Intune)
Design, test, and deploy Intune configuration and compliance policies for Windows, macOS, and iOS/iPadOS, including Enrollment Status Pages (ESPs) and OOBE workflows.
Develop remediation scripts (PowerShell/platform scripts/configuration profiles) to close compliance gaps and enforce security baselines.
Coordinate enterprise rollout of urgent vulnerability mitigations and validated vendor fixes; support vulnerability reviews and baseline rebuilds.
Risk management & compliance assurance (ATO / controls)
Establish and operate a risk management approach to identify, assess, and mitigate security risks across the M365 ecosystem.
Support ATO/control assessment activities by drafting implementation statements, collecting artifacts, and providing evidence aligned to audit/logging requirements.
Security monitoring, SIEM, and telemetry engineering (Defender / Sentinel)
Lead integration and operational management of Microsoft Defender and Microsoft Sentinel for threat detection, alerting, and response across M365.
Build and maintain SIEM integrations/connectors (e.g., M365, collaboration and identity systems) and develop ingestion pipelines (e.g., Azure Function Apps) for third-party logs.
Tune audit retention, analytic rules, and alert logic to improve signal quality and investigation readiness.
Incident response & operational support / collaboration
Provide Tier 3 troubleshooting for device compliance failures, identity/access incidents, telemetry gaps, and OS/app protection issues.
Partner with cross-functional teams to align security solutions with business objectives, deliver technical leadership, and support enterprise syncs and operational reviews.
Continuous improvement & innovation
Stay current on M365 security/compliance updates, industry trends, and emerging capabilities; drive improvements to security posture and operational efficiency (including use of GCC Copilot where appropriate).
Platform Scope / Tooling Microsoft 365 (GCC), Microsoft Purview (DLP/labels/classification/retention), Exchange Online, Entra ID & Conditional Access, Microsoft Intune, Microsoft Defender, Microsoft Sentinel, Azure (Function Apps / Log Analytics), plus integrations with collaboration/IT systems (e.g., ticketing and SaaS log sources).
“Day in the Life"
Morning
Review Sentinel incidents, Defender telemetry gaps, and compliance drift.
Respond to overnight CAP failures, Slack EMM issues, or OS update regressions.
Join device/enterprise standups.
Midday
Build/test remediation scripts (CVE fixes, NTLM disablement, compliance corrections).
Deploy or test Intune configuration profiles, ESP changes, or app protection updates.
Troubleshoot support cases with Microsoft (Purview DSPM, Copilot logs, Okta connector).
Afternoon
Conduct cross-team investigations (external-user access anomalies, Teams meeting forensics).
Validate CAP behaviors across platforms using test devices.
Work on ATO evidence packages and documentation.
End of Day
Update Jira tasks, Confluence documentation, and CR submissions.
Send status updates on active investigations, mitigations, and test results.
Required Qualifications
Technical Skills
Expert-level Intune engineering across Windows/macOS/iOS/iPadOS.
Advanced PowerShell for remediation, automation, and OS image manipulation.
Deep experience with Microsoft Defender (XDR, Endpoint, Cloud Apps).
Hands-on with Sentinel SIEM, Function Apps, and cross-platform telemetry pipelines.
Strong understanding of CAP architecture and identity risk enforcement.
Experience with ATO control evidence, compliance mapping, and audit support.
Soft Skills
Growth mindset and willingness to learn emerging security domains.
Strong cross-team collaboration (Cyber, Ops, EA, ICAM, Comms).
Excellent communication—clear summaries, user-impact translation, and documentation.
High reliability, ownership, and situational awareness during high-severity events.
Preferred Qualifications
Prior experience in federal security, high-compliance, or high‑assurance environments.
Experience with Jamf, Okta connectors, Copilot audit logging, Graph API operations.
Experience with mSCP baseline engineering and macOS security hardening.
Prior involvement in enterprise-wide Conditional Access enforcement.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
Original Posting:
May 29, 2026For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $107,900.00 - $195,050.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit .
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at .
Securing Your Data
Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at View email address on apply.j-vers.com .
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission .
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.
$107.9k - $195.05k
...experienced M365 Security and Compliance Administrator to... ...within a GCC (Government Community... ...context. This senior engineering role sits at the... ..., iOS/iPadOS endpoints; ensuring... ...compliance of the Microsoft 365 (M365) ecosystem... ...collaboration and identity systems) and develop...MicrosoftLocal areaImmediate startNight shiftDay shift- ...RiVidium Inc. is seeking an Endpoint Security Solutions (ESS) Systems Engineer - Level 1 to provide senior-level... ...security solutions while ensuring compliance with DoD cybersecurity requirements... ...programs. Expert knowledge of Microsoft Windows and Linux operating systems...MicrosoftFull timeContract workPart time
- ...is seeking a Senior Enterprise Security Engineer in support of our government... ...support for a large enterprise’s Microsoft 365 environment and integrated identity, endpoint, and messaging services. This... ...incident response and compliance activities; and partnering with...MicrosoftFull timeRemote work
- ...Endpoint Security Engineer Abile Group has an exciting and challenging opportunity for an Endpoint... ...Establishes computing environment by designing system configuration, directing system... ..., Carbon Black Response/Protection, Microsoft ATA, Tanium Strong working...MicrosoftContract workFor contractorsImmediate startWorldwide
$101.38k - $152.06k
...Information System Security Engineer (ISSE) / Cybersecurity Systems Engineer (TS Cleared)... ...and recovery strategies, ensuring compliance with security and regulatory standards... ...Viewer, NMAP, Nipper, Wireshark, Microsoft Defender for Endpoint, RSA Authentication Manager,...MicrosoftTemporary workFlexible hours$101.38k - $152.06k
...Information System Security Engineer (ISSE) / Cybersecurity Systems Engineer (TS Cleared)... ...and recovery strategies. Ensure compliance with security and regulatory standards... ...Viewer, NMAP, Nipper, Wireshark, Microsoft Defender for Endpoint, RSA Authentication Manager,...MicrosoftTemporary workFlexible hours- Information System Security Engineer (ISSE) / Cybersecurity Systems Engineer (TS Cleared) Location... ...and recovery strategies. Ensure compliance with security and regulatory... ...Viewer, NMAP, Nipper, Wireshark, Microsoft Defender for Endpoint, RSA Authentication Manager,...Microsoft
- A leading defense and engineering firm in Lorton, Virginia, is seeking an experienced Information Systems Security Engineer to manage the information security system and optimize... ...security documentation, and conduct compliance monitoring. Required qualifications include...
- ...organizations see, understand, and secure their hybrid digital... ...and continuously validates compliance with internal policies and industry... ...team as a Network Security Engineering Consultant and directly... ...in AWS/Azure plus Splunk or Microsoft Sentinel content (dashboards...MicrosoftRemote work
- ...documentation and compliance platform designed... ..., internal engineering teams, and executive... ...assessment logistics, and secure evidence transfer... ...understanding of Microsoft Azure, Microsoft... ..., Microsoft 365 GCC/GCC High, and... ...management, and endpoint protection technologies...MicrosoftFor contractorsRemote work
$148.85k - $269.08k
...has an opening for a Senior System Engineer supporting the HEITS Contract... ...the Department of Homeland Security (DHS) Insider Threat Program... ...hardening systems Familiarity with endpoint protection, SIEM integration... ...Experience with Oracle, Microsoft SQL Server, or PostgreSQL...MicrosoftContract work- ...System Security Engineer We are seeking a highly motivated and detail-oriented System Security Engineer to design, implement, and maintain... ...vulnerabilities, develop robust security solutions, and ensure compliance with industry standards and regulations. The ideal...Temporary workFor contractorsImmediate startFlexible hours
$70k - $85k
...Platform Engineer - Security Focus Location: Springfield... ...Windows Server, Microsoft 365, Azure, and line-of-business systems while also... ...threat analysis, endpoint protection, and identity... ...Knowledge of compliance frameworks such as... ...365 Government (GCC High). Relevant...MicrosoftContract workWork at officeRemote work$75.2k - $158.1k
Job Title: Endpoint Security Engineer III Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: TS/SCI Employee... ...(EDR). • Establish computing environment by designing system configuration, directing system installation, and defining,...Long term contractFull timeContract workWork experience placementLocal areaFlexible hours$121.4k - $182k
...opportunities to work on revolutionary systems that impact people's lives... .... In rapidly changing global security environments, Northrop... ...as a Principal Cyber Systems Engineer or Sr. Principal Cyber Systems... ...computer skills (e.g., Microsoft Office) Ability to provide detailed...MicrosoftFor contractorsWork at officeLocal areaWorldwideRelocation packageShift work- 4272 Senior Security Engineer 4272 | Top Secret Job Description: OVERVIEW: We are... ...to include network and software system. GENERAL DUTIES: Develop technical... ...and operate a hybrid SIEM stack spanning Microsoft Sentinel and Splunk Enterprise across on...Microsoft
$105k - $125k
...Requirement: Up to 10% Security Clearance: Must be able... ...'s internal information systems and ensuring compliance with applicable cybersecurity... ..., audit log review, endpoint security, and data protection... ...configurations across Microsoft 365, endpoint, and identity...Microsoft$60k - $73k
...Analyst, you support Security Engineers by executing approved... ...completion in the ticketing system Escalate unclear... ...access controls, and compliance requirements in... ...tasks across servers, endpoints, and network devices... ...maintenance and updates of Microsoft Sentinel data...MicrosoftContract workTemporary workRemote workMonday to Friday- ...in Cybersecurity, Cloud, and Systems Engineering to support the development and sustainment of secure enclaves at the edge. You'll... ...to identify vulnerabilities, compliance gaps, and recommend mitigations... ...Technical certifications in Microsoft Azure or related cloud technologies...Microsoft
- ...Methods is seeking a Systems Engineer to support a federal... ...environment delivering secure, high-performing... ...implementation Ensure compliance with security, regulatory... ...tools such as AWS, Microsoft, Windows Server,... ...Atlassian, Microsoft Endpoint Configuration Manager...Microsoft
$140k - $180k
...Cleared Information Systems Security Engineer (ISSE) L3 Lorton, VA ( Description Are you looking... ...complex mission systems and ensure compliance with DoD cybersecurity standards.... ...field. ~ Technical certifications in Microsoft Azure or related cloud technologies....MicrosoftContract workRelocationFlexible hours$90k - $115k
...Microsoft Azure/365 Infrastructure Engineer – Northern Virginia Who is Ardalyst? Ardalyst’s primary... ...Description This role provides Systems Engineering support for the... ...2 years of deploying and managing security capabilities to include firewalls...MicrosoftTemporary workWork at office- ...C2 Systems Engineer VI Quantico, VA ( Job Type Full-time Description... ...of high-performance, secure, and repeatable network... ...SharePoint, MS Teams, and Microsoft 365 environments used across the... ...management, cybersecurity compliance, and network standardization...MicrosoftFull timeContract workWork experience placementCurrently hiringWork at officeImmediate startFlexible hours
- ...mission-critical facilities, secure environments, complex infrastructure... ..., audiovisual, and IT systems. Headquarters in Tysons, Virginia... ...technology solutions through engineering expertise and smart systems... ...VMware ESXi and vSphere Microsoft Windows Server 2016 and 2019...MicrosoftWork at officeLocal areaFlexible hours
- ...roadmap. Candidates must possess ten years of IT experience and demonstrate strong hands-on experience with Microsoft 365 GCC-High. Beyond managing compliance, the role includes responsibilities in IT hardware and software solutions, ensuring effective service provider...Microsoft
$134.1k - $241.4k
...amazingly talented Missile Defense System Architecture Engineer to join our team! In this role you will... ...and solve problems Proficient in Microsoft Office Suite What Desired Skills... ...access to Special Access Programs (SAP) Security Clearance Requirement: An active...MicrosoftWork at officeLocal areaWorldwideFlexible hours- ...with continuous compliance tooling and automated... ...architecture, security, and resilience standards... ..., Windows Office 365 Enterprise, and... ...-on ownership of Microsoft 365 GCC-High alongside a... ...as production systems with real... ...modern identity, endpoint, collaboration, and...MicrosoftTemporary workWork at officeRemote work
- ...Belvoir, VA, to join the I3TS team supporting DTRA. This role involves securing IT systems through endpoint security tools like Trellix and Microsoft Defender, managing patches, ensuring compliance with federal cybersecurity standards, and documenting processes. Candidates...Microsoft
- ...Responsibilities include managing endpoint security using Trellix and Microsoft Defender, applying Security Technical... ...Guides (STIGs), and ensuring compliance with DoD cybersecurity standards.... ...management. Join us to help secure IT systems and support federal clients...Microsoft
$157k - $205k
Cleared Senior Information Systems Security Engineer (ISSE) L4 M-F, 5 days in the SCIF/onsite, 7-4,... ...environments to identify vulnerabilities, compliance gaps, and recommend mitigations.... ...cybersecurity area. Technical certifications in Microsoft Azure or related cloud technologies....MicrosoftContract workFor contractorsRelocationFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Systems Engineer - Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC). Be the first to apply!



