Chickasaw Nation Industries

Security Engineer

Chickasaw Nation Industries$100K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience with Microsoft Intune and Endpoint Configuration Manager (MECM).
  • Strong expertise in endpoint hardening and compliance policies.
  • In-depth knowledge of cybersecurity frameworks and incident response.
  • Experience with Microsoft Defender for Endpoint and security configurations.
  • Proficiency in PowerShell scripting for automating tasks and configurations.
  • Familiar with federal cybersecurity regulations (NIST 800-53) and Zero Trust Architecture.

Responsibilities

  • Engineer and maintain endpoint security policies and configurations using Microsoft Intune and MECM.
  • Develop Group Policy and Jamf security configurations to enhance system integrity.
  • Implement various Microsoft security settings to protect against threats.
  • Conduct validation and testing of security baseline deployments before rollout.
  • Assess impact of security updates and propose strategies for implementation.
  • Collaborate with different teams to ensure compliance with security requirements.
  • Create detailed configuration documentation and standard operating procedures for deployments.

Benefits

  • Comprehensive medical, dental, and vision insurance.
  • 401(k) retirement plan with employer matching.
  • Family planning and fertility assistance programs.
  • Short-term and long-term disability insurance, and life insurance.
  • Legal-aid program and employee assistance services.
  • Generous paid time off (PTO) policy.
  • Opportunities for professional training and development.
Full Job Description
CNI seeking an Endpoint Security Baseline Engineer to support the engineering, implementation, and operational management of enterprise endpoint security configurations across Microsoft Intune, Microsoft Endpoint Configuration Manager (MECM), and Jamf Pro environments. This role is responsible for designing, implementing, validating, and maintaining standardized security baselines that improve the organization's cybersecurity posture while ensuring operational stability across Windows and macOS endpoints.

The ideal candidate possesses experience with Microsoft security technologies, endpoint hardening, compliance policies, CIS and Microsoft Security Baselines, and enterprise endpoint management platforms within highly regulated federal environments.

ESSENTIAL REQUIREMENTS

The ability to obtain, maintain and access classified information at the Public Trust level.

Strong understanding of cybersecurity frameworks, access control, endpoint security, and incident response.
  • Experience administering Microsoft Intune and Microsoft Endpoint Manager.
  • Experience with MECM/SCCM administration.
  • Experience implementing Microsoft Security Baselines and CIS Benchmarks.
  • Knowledge of Microsoft Defender for Endpoint.
  • Experience configuring BitLocker, Windows Firewall, ASR rules, Device Control, and endpoint protection policies.
  • Familiarity with Entra ID, Conditional Access, RBAC, and device compliance.
  • Understanding of NIST 800-53, Zero Trust Architecture, and federal cybersecurity requirements.
  • Strong PowerShell scripting experience.
  • Excellent troubleshooting and documentation skills.


Preferred Qualifications
  • Experience with Jamf Pro administration.
  • Experience supporting Azure Virtual Desktop environments.
  • Microsoft Intune Administrator Associate (MD-102).
  • Microsoft Security Administrator (SC-300 or equivalent).
  • CISSP, Security+, or similar security certification.
  • Experience supporting HHS, NIH, or other federal agencies.


ESSENTIAL DUTIES AND RESPONSIBILITIES

Essential Duties and responsibilities include the following. Other duties may be assigned.
  • Engineer and maintain Microsoft Intune Security Baselines, Endpoint Security policies, and Configuration Profiles.
  • Develop and maintain Group Policy, MECM Configuration Baselines, and Jamf security configurations.
  • Implement Microsoft Defender for Endpoint security settings, attack surface reduction (ASR) rules, firewall policies, BitLocker, FileVault, Credential Guard, Application Control, and device encryption policies.
  • Configure compliance policies and Conditional Access dependencies supporting Zero Trust initiatives.
  • Validate security baseline deployments through testing, pilot implementations, and production rollout.
  • Perform impact assessments for Microsoft monthly security baseline updates and recommend adoption strategies.
  • Collaborate with cybersecurity, RMF, ISSO, and engineering teams to ensure endpoint configurations meet organizational security requirements.
  • Develop configuration documentation, implementation guides, rollback procedures, and standard operating procedures.
  • Support vulnerability remediation initiatives through endpoint configuration changes.
  • Troubleshoot policy conflicts between Intune, MECM, Active Directory Group Policy, and Jamf.
  • Participate in change management, CAB reviews, and production implementation activities.
  • Support enterprise modernization initiatives including Autopilot, cloud-native management, and migration from traditional management solutions.


EDUCATION AND EXPERIENCE
  • Bachelors degree and 4+ years supporting enterprise endpoint management environments.


PHYSICAL DEMANDS

Work is primarily performed in an office environment. Regularly required to sit. Regularly required use hands to finger, handle, or feel, reach with hands and arms to handle objects and operate tools, computer, and/or controls. Required to speak and hear. Occasionally required to stand, walk and stoop, kneel, crouch, or crawl. Must frequently lift and/or move up to 10 pounds and occasionally lift and/or move up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision, depth perception, and ability to adjust focus. Exposed to general office noise with computers printers and light traffic.

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this job.

The estimated pay range for this role is $100,000 to $120,000, with the final offer contingent on location, skillset, and experience.

CNI offers a comprehensive benefits package that includes:
  • Medical
  • Dental
  • Vision
  • 401(k)
  • Family Planning/Fertility Assistance
  • STD/LTD/Basic Life/AD&D
  • Legal-Aid Program
  • Employee Assistance Program (EAP)
  • Paid Time Off (PTO)
  • Training and Development Opportunities


Your application submission will be considered for all potential employment opportunities with Chickasaw Nation Industries (CNI).

#INDCNI

Similar Jobs

More Jobs at Chickasaw Nation Industries

  • Chickasaw Nation Industries
    Network Engineer
    $85K — $125K *
    Washington, DC 20011 (District Of Columbia County)
    Telecommunications & Hardware
    In-Person
  • Chickasaw Nation Industries
    UI/UX Developer
    $90K — $125K *
    Washington, DC 20011 (District Of Columbia County)
    Information Technology
    In-Person
  • Chickasaw Nation Industries
    Configuration Manager
    $80K — $95K *
    Ellsworth Afb, SD 57706 (Meade County)
    Aerospace & Defense
    In-Person
  • Chickasaw Nation Industries
    Cyber Security Analyst
    $95K — $115K *
    Ellsworth Afb, SD 57706 (Meade County)
    Aerospace & Defense
    In-Person
  • Chickasaw Nation Industries
    Program Manager
    $100K — $120K *
    Ellsworth Afb, SD 57706 (Meade County)
    Aerospace & Defense
    In-Person

More Information Technology Jobs

Find similar Security Engineer jobs: