The Microsoft Security Engineer supports the organization’s cybersecurity operations through the administration, monitoring, and maintenance of Microsoft security technologies. Working under the direction of the Director of IT, this role assists with identity security, security monitoring, vulnerability remediation, incident response, and security compliance initiatives across Microsoft 365, Microsoft Azure, Microsoft Entra ID, and hybrid environments.
This is a hands-on operational role. The position helps implement and maintain established security controls, investigates and escalates security events, documents procedures, and collaborates with IT teams to reduce risk. Security strategy, architecture, program governance, risk acceptance, and final policy decisions remain with the Director of IT and other designated leadership stakeholders.
The ideal candidate can work remotely but may be needed on-site at the Frederick MD or Reston VA offices for special operations. Candidates that live in the MD/DC/VA area are strongly preferred.
Identity and Access Security
Microsoft 365 and Endpoint Security
Security Monitoring and Incident Support
Vulnerability Management and Remediation
Review vulnerability findings and Microsoft security recommendations.
Governance, Compliance, and Documentation
Automation and Continuous Improvement
Required Qualifications
Preferred Qualifications
Technical Skills
Identity, Cloud, and Security Operations
Scripting and Automation
Success Factors
Position LevelIntermediate. This role is designed for a technically capable security professional who can independently perform assigned operational work while receiving strategic direction, architectural guidance, and final decision-making support from the Director of IT.
CompensationThe anticipated base salary range for this position is $90,000 to $100,000. Final compensation will be based on relevant experience, qualifications, work location, internal equity, and the organization’s approved compensation practices. Benefits and other total rewards should be added before publication, as applicable.
Why Join Us?This role offers the opportunity to work across Microsoft’s modern security ecosystem and make a visible contribution to the protection of a growing organization. The Microsoft Security Engineer will gain broad experience across identity, endpoint, email, cloud, security monitoring, vulnerability remediation, and compliance support while working closely with experienced IT leadership.
Additional benefits include:
Physical Demands: The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Work Environment: The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Working at Edgewater Federal Solutions:
Edgewater Federal Solutions is a privately held government contracting firm located in Frederick, MD. The company was founded in 2002 with the vision of being highly recognized and admired for supporting customer missions through employee empowerment, exceptional services, and timely delivery. Edgewater Federal Solutions is ISO 9001, 20000-1, 270001 certified, appraised at CMMI Level 3 Maturity for Development and Services, and has been named in the Top Workplaces in the Greater Washington Area Companies since 2018.
Edgewater Federal Solutions is an Equal Opportunity Employer. It has been and continues to be our policy to provide equal employment to all employees and applicants for employment without regard to race, color, religion, gender, national origin, age, disability, marital status, veteran status and/or other status protected by applicable law. #LI-KC1
Identity and Access Security - Administer Microsoft Entra ID security controls in accordance with approved standards and direction. - Support implementation and ongoing maintenance of Conditional Access policies. - Assist with multifactor authentication, passwordless authentication, authentication methods, and Identity Protection investigations. - Support Privileged Identity Management, access reviews, and least-privilege access practices. - Escalate identity risks, policy exceptions, and proposed design changes to the Director of IT. Microsoft 365 and Endpoint Security - Administer and maintain Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and applicable Microsoft Defender XDR capabilities. - Monitor endpoint, email, identity, and cloud security alerts and perform initial investigation and response. - Maintain approved email security controls, including anti-phishing policies, Safe Links, Safe Attachments, SPF, DKIM, and DMARC. - Support security controls for Microsoft Teams, SharePoint Online, OneDrive, and other Microsoft 365 services. - implement approved Microsoft Secure Score and security posture recommendations and document completed improvements. Security Monitoring and Incident Support - Monitor, analyze, and respond to security alerts and incidents using Microsoft Sentinel, Microsoft Defender, and related security tools. - Maintain Sentinel data connectors, analytics rules, workbooks, dashboards, incident workflows, and approved automation. - Perform initial root-cause analysis, document findings, and coordinate assigned remediation activities. - Escalate significant or complex incidents in accordance with approved incident response procedures. - Assist the Director of IT and external specialists during major incidents, forensic investigations, and post-incident reviews. Vulnerability Management and Remediation Review vulnerability findings and Microsoft security recommendations. - Coordinate assigned remediation activities with infrastructure, cloud, network, application, and endpoint owners. - Validate remediation where practical and maintain status documentation and supporting evidence. - Support implementation of approved security baselines and hardening standards. - Escalate overdue, high-risk, or exception requests to the Director of IT for prioritization and risk decisions. Governance, Compliance, and Documentation - Assist with Microsoft Purview and other approved data protection controls, including Data Loss Prevention, sensitivity labels, information protection, and retention capabilities. - Support audits, compliance reviews, and risk assessments by collecting evidence and maintaining documentation. - Develop and maintain security procedures, configuration records, operational runbooks, and incident response documentation. - Assist with security awareness initiatives and provide technical guidance to internal IT teams within established standards. Automation and Continuous Improvement - Use PowerShell, Kusto Query Language, Logic Apps, or similar tools to improve repeatable security administration and reporting. - Recommend operational improvements and assist with approved implementation. - Stay current with Microsoft security technologies, emerging threats, vulnerabilities, and relevant industry practices.Job details are sourced from the employer's original posting.
Open job postingAbout the company
Edgewater Federal Solutions provides IT services and solutions to government agencies.