Systems Engineer - Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC)

Leidos Holding$107K — $195K *
US-AnywhereRemote in United States
Education, Government & Non-Profit
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree with 8+ years of experience, or 12+ years without a degree.
  • US Citizenship or ability to obtain Public Trust level 5 clearance is required.
  • Profound experience with Microsoft Defender (XDR, Endpoint, Cloud Apps).
  • Hands-on proficiency with Sentinel SIEM and telemetry pipelines.
  • Expertise in Intune engineering across multiple platforms: Windows, macOS, iOS/iPadOS.
  • Advanced PowerShell skills for automation and remediation tasks.
  • Strong understanding of compliance mapping and audit support specifics.

Responsibilities

  • Lead security governance and policy implementation for M365 aligned to federal standards.
  • Enforce data protection capabilities and manage Data Loss Prevention (DLP) using Microsoft Purview.
  • Define and enforce email security policies to prevent data breaches.
  • Engineer Conditional Access policies, ensuring device compliance across platforms.
  • Design and deploy Intune policies for various operating systems, addressing compliance gaps.
  • Conduct risk assessment and mitigation for the M365 ecosystem regarding security threats.
  • Oversee the operational management of Microsoft Defender and Sentinel for threat detection.

Benefits

  • Contributing to mission-critical projects within a federal agency.
  • Opportunities for continuous learning and embracing new technologies.
  • Collaborative work environment with cross-functional teams.
  • Engagement in high-impact security governance roles.
  • Involvement in innovative security solutions and practices.
Full Job Description
Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role requires a seasoned professional who can strategically manage and enhance the security and compliance posture of the M365 environment within a GCC (Government Community Cloud) tenant, particularly in a federal agency context. This senior engineering role sits at the center of the organization's device, identity, and M365 security ecosystem. The engineer is responsible for protecting enterprise Windows, macOS, iOS/iPadOS endpoints; ensuring compliant, reliable access to M365 services, and driving rapid engineering responses to vulnerabilities, outages, and operational risks. The successful candidate will apply with deep technical expertise, cross-platform engineering capability, and high operational security judgment.

Role Summary: Responsible for securing and maintaining compliance of the Microsoft 365 (M365) ecosystem and enterprise endpoints. Leads security governance, implements and enforces controls across M365, email, identity, devices, and telemetry, and provides incident response and audit/ATO support to ensure alignment with federal and organizational security requirements.

Must meet the following qualifications:

Bachelors Degree and 8+ years of experience. 4 additional years of experience may be substituted in lieu of degree.

Candidate MUST:

be a US Citizen or US Person with the ability to obtain a Public Trust level 5 clearance.

Required Qualifications

Technical Skills
  • Deep experience with Microsoft Defender (XDR, Endpoint, Cloud Apps).
  • Hands-on with Sentinel SIEM, and cross-platform telemetry pipelines.
  • Expert-level Intune engineering across Windows/macOS/iOS/iPadOS.
  • Advanced PowerShell for remediation, automation, and OS image manipulation.
  • Strong understanding of CAP architecture and identity risk enforcement.
  • Experience with ATO control evidence, compliance mapping, and audit support.


Soft Skills
  • Growth mindset and willingness to learn emerging security domains.
  • Strong cross-team collaboration (Cyber, Ops, EA, ICAM, Comms).
  • Excellent communication-clear summaries, user-impact translation, and documentation.
  • High reliability, ownership, and situational awareness during high-severity events.


Preferred Qualifications
  • Prior experience in federal security, high-compliance, or high-assurance environments.
  • Experience with Jamf, Okta connectors, Copilot audit logging, Graph API operations.
  • Experience with mSCP baseline engineering and macOS security hardening.
  • Prior involvement in enterprise-wide Conditional Access enforcement.

Primary Responsibilities

Strategic security oversight & governance
  • Lead the development, implementation, and ongoing management of M365 security policies, standards, and technical guardrails aligned to federal requirements and organizational controls.
  • Own governance for data protection capabilities including document classification, labeling, retention, and Data Loss Prevention (DLP) using Microsoft Purview.


Email security & compliance management (Exchange Online)
  • Define and enforce email security policies such as encryption, sensitivity labeling, and secure mail flow to reduce unauthorized disclosure.
  • Implement and maintain email encryption solutions (S/MIME and/or Microsoft Information Protection) to protect confidentiality of email communications.
  • Administer and monitor anti-spam, anti-phishing, and anti-malware protections to defend against evolving threats.


Identity, access, and conditional access (Entra ID)
  • Engineer and validate device-compliance-based Conditional Access policies across Windows, macOS, and mobile platforms.
  • Investigate and remediate Conditional Access failures, identity anomalies, and external/guest access issues, including M365 B2B trust and secure partner collaboration requirements.


Endpoint & device security engineering (Intune)
  • Design, test, and deploy Intune configuration and compliance policies for Windows, macOS, and iOS/iPadOS, including Enrollment Status Pages (ESPs) and OOBE workflows.
  • Develop remediation scripts (PowerShell/platform scripts/configuration profiles) to close compliance gaps and enforce security baselines.
  • Coordinate enterprise rollout of urgent vulnerability mitigations and validated vendor fixes; support vulnerability reviews and baseline rebuilds.


Risk management & compliance assurance (ATO / controls)
  • Establish and operate a risk management approach to identify, assess, and mitigate security risks across the M365 ecosystem.
  • Support ATO/control assessment activities by drafting implementation statements, collecting artifacts, and providing evidence aligned to audit/logging requirements.


Security monitoring, SIEM, and telemetry engineering (Defender / Sentinel)
  • Lead integration and operational management of Microsoft Defender and Microsoft Sentinel for threat detection, alerting, and response across M365.
  • Build and maintain SIEM integrations/connectors (e.g., M365, collaboration and identity systems) and develop ingestion pipelines (e.g., Azure Function Apps) for third-party logs.
  • Tune audit retention, analytic rules, and alert logic to improve signal quality and investigation readiness.


Incident response & operational support / collaboration
  • Provide Tier 3 troubleshooting for device compliance failures, identity/access incidents, telemetry gaps, and OS/app protection issues.
  • Partner with cross-functional teams to align security solutions with business objectives, deliver technical leadership, and support enterprise syncs and operational reviews.


Continuous improvement & innovation
  • Stay current on M365 security/compliance updates, industry trends, and emerging capabilities; drive improvements to security posture and operational efficiency (including use of GCC Copilot where appropriate).


Platform Scope / Tooling Microsoft 365 (GCC), Microsoft Purview (DLP/labels/classification/retention), Exchange Online, Entra ID & Conditional Access, Microsoft Intune, Microsoft Defender, Microsoft Sentinel, Azure (Function Apps / Log Analytics), plus integrations with collaboration/IT systems (e.g., ticketing and SaaS log sources).

"Day in the Life"

Morning
  • Review Sentinel incidents, Defender telemetry gaps, and compliance drift.
  • Respond to overnight CAP failures, Slack EMM issues, or OS update regressions.
  • Join device/enterprise standups.


Midday
  • Build/test remediation scripts (CVE fixes, NTLM disablement, compliance corrections).
  • Deploy or test Intune configuration profiles, ESP changes, or app protection updates.
  • Troubleshoot support cases with Microsoft (Purview DSPM, Copilot logs, Okta connector).


Afternoon
  • Conduct cross-team investigations (external-user access anomalies, Teams meeting forensics).
  • Validate CAP behaviors across platforms using test devices.
  • Work on ATO evidence packages and documentation.


End of Day
  • Update Jira tasks, Confluence documentation, and CR submissions.
  • Send status updates on active investigations, mitigations, and test results.


If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

Original Posting:
August 26, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:
Pay Range $107,900.00 - $195,050.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About Leidos Holding

Leidos Holding Careers

Joining Leidos Holding presents an unparalleled opportunity to advance one's career with a leader in innovation and technology. The company offers a plethora of job opportunities aimed at fostering professional growth and development in a diverse and inclusive environment.

Explore Career Opportunities

Leidos Holding is actively seeking skilled professionals who are passionate about leveraging their expertise to drive innovation and leadership in their fields. With a variety of open positions, Leidos Holding provides a platform for individuals to challenge themselves in a dynamic work environment.

Innovation and Professional Growth

At Leidos Holding, innovation is at the core of everything they do. Employees are encouraged to think creatively and push boundaries. The company supports this drive for innovation through comprehensive professional development and diversity training programs that are designed to enhance skills and foster leadership.

Commitment to Diversity and Inclusion

Leidos Holding is committed to creating a workplace where diversity is not only recognized but celebrated. With a culture that values and promotes diversity, Leidos Holding ensures that all team members have the opportunity to contribute, learn, and grow.

Internship Programs

For those starting their career, Leidos Holding offers internship programs that provide a robust foundation in the industry. Internships are a great way to develop essential skills, gain valuable work experience, and build professional networks.

Benefits and Culture

Employees at Leidos Holding enjoy a range of benefits designed to support their professional and personal lives. The company culture is built on a foundation of respect and integrity, providing a supportive and collaborative environment where every team member is valued.

Join the Team

Leidos Holding is hiring! Explore job opportunities that match your skills and interests. Leidos Holding looks for driven, curious, and innovative individuals to join their team. Positions are available across various disciplines and experience levels.

Stay Connected

Stay informed with the latest career tips, industry insights, and company news from Leidos Holding. Subscribe to receive updates and be the first to know about new job opportunities, company developments, and more.

Prepare for Your Interview

To prepare for an interview at Leidos Holding, candidates should familiarize themselves with the company's missions and values, update their resumes, and be ready to discuss how their background and skills align with the position they are applying for.

Networking and Career Advancement

Leidos Holding encourages its employees to engage in networking within the company to discover new opportunities for career advancement. The leadership team at Leidos Holding is dedicated to supporting employees in their career paths with ample opportunities for networking and growth.

Explore Leidos Holding Jobs and Careers

Discover the exciting career opportunities at Leidos Holding today. With a commitment to employee growth, innovation, and diversity, Leidos Holding is the perfect place to advance your career. Check out the latest job listings and find your perfect fit at Leidos Holding.

SEARCH LEIDOS HOLDING JOBS

READ CAREERS BLOG

Job Alert Emails

Customize your subscription to receive job alerts and insider tips tailored to your preferences from Leidos Holding. See what exciting and rewarding opportunities await in your professional journey.
Learn more about Leidos Holding

Similar Jobs

More Jobs at Leidos Holding

More Education, Government & Non-Profit Jobs

Find similar Systems Engineer - Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC) jobs: