Job Title: Senior Microsoft Cloud Security Engineer
Job Category: Information Technology
Time Type: Full time
Minimum Clearance Required to Start: None
Employee Type: Regular
Percentage of Travel Required: None
Type of Travel: None
* * *
Responsibilities:
- Serve as the go-to, subject matter expert (SME) for securing the Microsoft cloud tenant, advising on architecture, design, and implementation of secure solutions across Azure, O365, and M365.
- Lead the development and enforcement of Conditional Access Policies, aligned with best practices for managing access control for personas, groups, and applications.
- Act as the primary SME in optimizing the Microsoft Defender suite of components (Defender for Endpoint, Defender for Cloud, Defender for Identity, and Defender for Office 365)
- Implement Microsoft Purview, including data classification and sensitivity labels, Data Loss Prevent (DLP), and eDiscovery workflows.
- Design, run and optimize Kusto Query Language (KQL) queries for Azure Sentinel, Defender, and log analytics.
- Review and remediate security controls through vulnerability assessments, penetration tests, and red/blue team engagements.
- Guide cross-functional teams on security controls, compliance requirements, policy, and governance best practices
Qualifications:
Required:
- Ability to Obtain DHS EOD Public Trust Clearance
- Master's Degree + 10 years' experience OR Bachelor's degree + 13 years OR 19 years total experience
- Expert-level hands-on experience deploying, managing, and securing Azure, Entra, Defender, Purview, Office 365, and Microsoft 365 in large enterprises.
- Deep understanding of Conditional Access Policies (CAPs), Azure AD/Entra, and Zero Trust principles.
- Proven Track Record implementing and managing the full suite of the Microsoft Defender ecosystem and Microsoft Purview (DLP, sensitivity labels, eDiscovery)
- Advanced proficiency writing KQL for detection, investigation, response, and reporting
- Active, expert-level certification such as Microsoft Certified Solutions Expert (MSCE), Microsoft 365 Admin Expert, Microsoft Cybersecurity Architect Expert, AZ-900, AZ-500, SC-900, SC-100, SC-200, SC-300, SC-400, SC-401
- Cybersecurity certifications: Security+
- Strong networking, firewall, VPN, and segmentation knowledge as it relates to cloud deployments
- Exceptional time management, written and communication skills.
Desired:
- CISSP, OSCP, GCIH
- ITIL, Agile, or PMP familiarity/certification
- Experience with SOAR platforms (e.g. Splunk, Microsoft Sentinel)
- Hands-on exposure to third-party cloud security tooling (CASBs, CNAAPs, SD-WANs)
- Previous consulting or client-facing delivery experience
Pay Range:
There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.
The proposed salary range for this position is:
$131,800 - $290,000