Systems Engineer – Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC)
Leidos
- Location
- 6314 Remote/Teleworker US
- Work model
- Remote
- Level
- Senior
- H-1B history
- 26 approvals (FY2023)
- Posted
- Aug 27, 2026
Skills
About this role
Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role requires a seasoned professional who can strategically manage and enhance the security and compliance posture of the M365 environment within a GCC (Government Community Cloud) tenant, particularly in a federal agency context. This senior engineering role sits at the center of the organization’s device, identity, and M365 security ecosystem. The engineer is responsible for protecting enterprise Windows, macOS, iOS/iPadOS endpoints; ensuring compliant, reliable access to M365 services, and driving rapid engineering responses to vulnerabilities, outages, and operational risks. The successful candidate will apply with deep technical expertise, cross-platform engineering capability, and high operational security judgment.
Role
Summary: Responsible for securing and maintaining compliance of the Microsoft 365 (M365) ecosystem and enterprise endpoints. Leads security governance, implements and enforces controls across M365, email, identity, devices, and telemetry, and provides incident response and audit/ATO support to ensure alignment with federal and organizational security requirements. Must meet the following qualifications: Bachelors Degree and 8+ years of experience. 4 additional years of experience may be substituted in lieu of degree. Candidate MUST: be a US Citizen or US Person with the ability to obtain a Public Trust level 5 clearance.
Required Qualifications
Technical Skills Deep experience with Microsoft Defender (XDR, Endpoint, Cloud Apps). Hands-on with Sentinel SIEM, and cross-platform telemetry pipelines. Expert-level Intune engineering across Windows/macOS/iOS/iPadOS. Advanced PowerShell for remediation, automation, and OS image manipulation. Strong understanding of CAP architecture and identity risk enforcement. Experience with ATO control evidence, compliance mapping, and audit support. Soft Skills Growth mindset and willingness to learn emerging security domains. Strong cross-team collaboration (Cyber, Ops, EA, ICAM, Comms). Excellent communication—clear summaries, user-impact translation, and documentation. High reliability, ownership, and situational awareness during high-severity events.
Preferred Qualifications
Prior experience in federal security, high-compliance, or high‑assurance environments. Experience with Jamf, Okta connectors, Copilot audit logging, Graph API operations. Experience with mSCP baseline engineering and macOS security hardening. Prior involvement in enterprise-wide Conditional Access enforcement.
Primary Responsibilities
Strategic security oversight & governance Lead the development, implementation, and ongoing management of M365 security policies, standards, and technical guardrails aligned to federal requirements and organizational controls. Own governance for data protection capabilities including document classification, labeling, retention, and Data Loss Prevention (DLP) using Microsoft Purview. Email security & compliance management (Exchange Online) Define and enforce email security policies such as encryption, sensitivity labeling, and secure mail flow to reduce unauthorized disclosure. Implement and maintain email encryption solutions (S/MIME and/or Microsoft Information Protection) to protect confidentiality of email communications. Administer and monitor anti-spam, anti-phishing, and anti-malware protections to defend against evolving threats. Identity, access, and conditional access (Entra ID) Engineer and validate device-compliance–based Conditional Access policies across Windows, macOS, and mobile platforms. Investigate and remediate Conditional Access failures, identity anomalies, and external/guest access issues, including M365 B2B trust and secure partner collaboration requirements. Endpoint & device security engineering (Intune) Design, test, and deploy Intune configuration and compliance policies for Windows, macOS, and iOS/iPadOS,