M365 Security Engineer
ethos talent advisoryWashington (DC)
About the role
Our federal IT client is looking for a senior engineer to own the security and compliance posture of a Microsoft 365 GCC environment supporting a federal agency. This role sits at the center of device, identity, and M365 security: you will protect Windows, macOS, and iOS/iPadOS endpoints, keep access to M365 services compliant and reliable, and lead fast engineering responses to vulnerabilities, outages, and operational risk.
What You Will Do:
Engineer, test, and deploy Intune configuration and compliance policies across Windows, macOS, and iOS/iPadOS, including Enrollment Status Pages and OOBE workflows Design and validate device compliance based Conditional Access policies in Entra ID, and troubleshoot CAP failures, identity anomalies, and B2B guest access issues Lead integration and tuning of Microsoft Defender (XDR, Endpoint, Cloud Apps) and Microsoft Sentinel, including analytic rules, alert logic, audit retention, and connectors Build SIEM ingestion pipelines for third party log sources using Azure Function Apps and Log Analytics Write Power Shell remediation scripts to close compliance gaps, deploy CVE fixes, and enforce security baselines (for example NTLM disablement)Own data protection governance in Microsoft Purview: classification, sensitivity labeling, retention, and DLPSecure Exchange Online mail flow, encryption (S/MIME and/or MIP), and anti spam, anti phishing, and anti malware protections Support ATO and control assessments by drafting implementation statements and assembling evidence packages Provide Tier 3 support on device compliance, identity, telemetry, and app protection incidents, and coordinate enterprise rollout of urgent vulnerability mitigations Partner with Cyber, Ops, Enterprise Architecture, ICAM, and Comms teams, and keep Jira, Confluence, and change requests current Required Bachelor's degree and 8+ years of experience, or 12+ years of experience in lieu of a degreeUS Citizen or US based person able to obtain a Public Trust (Level 5)Deep, hands on experience with Microsoft Defender (XDR, Endpoint, Cloud Apps)Hands on Microsoft Sentinel SIEM experience, including cross platform telemetry pipelines Expert level Intune engineering across Windows, macOS, and iOS/iPadOSAdvanced Power Shell for remediation, automation, and OS image manipulation Strong understanding of Conditional Access architecture and identity risk enforcement in Entra IDExperience producing ATO control evidence, compliance mapping, and audit support Clear communicator who can summarize technical issues in terms of user impact and stay steady during high severity events Preferred Federal, high compliance, or high assurance environment experience (GCC or GCC High a strong plus)Jamf, Okta connectors, Copilot audit logging, and Microsoft Graph API operationsmacOS security hardening and mSCP baseline engineering Prior ownership of an enterprise wide Conditional Access rollout
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
