Microsoft Security Engineer

Job Locations US-MD-Frederick
ID
2026-4835
Category
Information Technology
Type
Full Time

Overview

The Microsoft Security Engineer supports the organization’s cybersecurity operations through the administration, monitoring, and maintenance of Microsoft security technologies. Working under the direction of the Director of IT, this role assists with identity security, security monitoring, vulnerability remediation, incident response, and security compliance initiatives across Microsoft 365, Microsoft Azure, Microsoft Entra ID, and hybrid environments.


This is a hands-on operational role. The position helps implement and maintain established security controls, investigates and escalates security events, documents procedures, and collaborates with IT teams to reduce risk. Security strategy, architecture, program governance, risk acceptance, and final policy decisions remain with the Director of IT and other designated leadership stakeholders.

 

The ideal candidate can work remotely but may be needed on-site at the Frederick MD or Reston VA offices for special operations.  Candidates that live in the MD/DC/VA area are strongly preferred. 

Responsibilities

Identity and Access Security

  • Administer Microsoft Entra ID security controls in accordance with approved standards and direction.
  • Support implementation and ongoing maintenance of Conditional Access policies.
  • Assist with multifactor authentication, passwordless authentication, authentication methods, and Identity Protection investigations.
  • Support Privileged Identity Management, access reviews, and least-privilege access practices.
  • Escalate identity risks, policy exceptions, and proposed design changes to the Director of IT.

Microsoft 365 and Endpoint Security

  • Administer and maintain Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and applicable Microsoft Defender XDR capabilities.
  • Monitor endpoint, email, identity, and cloud security alerts and perform initial investigation and response.
  • Maintain approved email security controls, including anti-phishing policies, Safe Links, Safe Attachments, SPF, DKIM, and DMARC.
  • Support security controls for Microsoft Teams, SharePoint Online, OneDrive, and other Microsoft 365 services.
  • implement approved Microsoft Secure Score and security posture recommendations and document completed improvements.

Security Monitoring and Incident Support

  • Monitor, analyze, and respond to security alerts and incidents using Microsoft Sentinel, Microsoft Defender, and related security tools.
  • Maintain Sentinel data connectors, analytics rules, workbooks, dashboards, incident workflows, and approved automation.
  • Perform initial root-cause analysis, document findings, and coordinate assigned remediation activities.
  • Escalate significant or complex incidents in accordance with approved incident response procedures.
  • Assist the Director of IT and external specialists during major incidents, forensic investigations, and post-incident reviews.

Vulnerability Management and Remediation

Review vulnerability findings and Microsoft security recommendations.

  • Coordinate assigned remediation activities with infrastructure, cloud, network, application, and endpoint owners.
  • Validate remediation where practical and maintain status documentation and supporting evidence.
  • Support implementation of approved security baselines and hardening standards.
  • Escalate overdue, high-risk, or exception requests to the Director of IT for prioritization and risk decisions.

Governance, Compliance, and Documentation

  • Assist with Microsoft Purview and other approved data protection controls, including Data Loss Prevention, sensitivity labels, information protection, and retention capabilities.
  • Support audits, compliance reviews, and risk assessments by collecting evidence and maintaining documentation.
  • Develop and maintain security procedures, configuration records, operational runbooks, and incident response documentation.
  • Assist with security awareness initiatives and provide technical guidance to internal IT teams within established standards.

Automation and Continuous Improvement

  • Use PowerShell, Kusto Query Language, Logic Apps, or similar tools to improve repeatable security administration and reporting.
  • Recommend operational improvements and assist with approved implementation.
  • Stay current with Microsoft security technologies, emerging threats, vulnerabilities, and relevant industry practices.

Qualifications

Required Qualifications

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, a related field, or equivalent practical experience.
  • Three or more years of cybersecurity, information security, systems administration, or security operations experience.
  • Hands-on experience administering security controls in Microsoft 365, Microsoft Entra ID, or Microsoft Azure.
  • Experience investigating alerts in Microsoft Defender and/or Microsoft Sentinel.
  • Working knowledge of Conditional Access, multifactor authentication, endpoint protection, email security, and identity security concepts.
  • Familiarity with vulnerability management, incident response, security monitoring, and cloud security practices.
  • Working knowledge of PowerShell and basic Kusto Query Language.
  • Ability to follow established standards, document work clearly, recognize when escalation is required, and manage multiple priorities.
  • Strong analytical, troubleshooting, communication, customer service, and collaboration skills.

Preferred Qualifications

  • Microsoft Certified: Security Operations Analyst Associate (SC-200).
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300).
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500).
  • CompTIA Security+ or a comparable foundational security certification.
  • Experience with Microsoft Defender for Endpoint, Defender for Office 365, Microsoft Purview, Logic Apps, or security automation.
  • Experience supporting audit evidence collection or regulatory compliance activities.

Technical Skills

  • Microsoft Security Platforms
  • Microsoft Sentinel
  • Microsoft Defender XDR
  • Microsoft Defender for Endpoint
  • Microsoft Defender for Office 365
  • Microsoft Defender for Identity
  • Microsoft Entra ID
  • Microsoft Purview

Identity, Cloud, and Security Operations

  • Conditional Access and multifactor authentication
  • Microsoft Azure and Microsoft 365
  • Identity Protection and Privileged Identity Management
  • Incident investigation and security monitoring
  • Vulnerability remediation coordination
  • Data Loss Prevention and information protection

Scripting and Automation

  • PowerShell
  • Kusto Query Language
  • Logic Apps
  • Familiarity with Python or Bash is beneficial but not required

Success Factors

  • Consistently administers Microsoft security technologies in accordance with approved standards.
  • Investigates alerts promptly, documents findings clearly, and escalates significant issues appropriately.
  • Completes assigned vulnerability and posture-improvement work and maintains reliable status information.
  • Builds effective working relationships across IT and balances security requirements with operational needs.
  • Demonstrates sound judgment, attention to detail, accountability, and a commitment to continuous learning.
  • Identifies practical automation and process improvements without assuming unassigned program or strategic ownership.

Position Level
Intermediate. This role is designed for a technically capable security professional who can independently perform assigned operational work while receiving strategic direction, architectural guidance, and final decision-making support from the Director of IT.

 

Compensation
The anticipated base salary range for this position is $90,000 to $100,000. Final compensation will be based on relevant experience, qualifications, work location, internal equity, and the organization’s approved compensation practices. Benefits and other total rewards should be added before publication, as applicable.

 

Why Join Us?
This role offers the opportunity to work across Microsoft’s modern security ecosystem and make a visible contribution to the protection of a growing organization. The Microsoft Security Engineer will gain broad experience across identity, endpoint, email, cloud, security monitoring, vulnerability remediation, and compliance support while working closely with experienced IT leadership.

 

Additional benefits include: 

  • Paid Time Off & Holiday Pay
  • Medical Insurance
  • Dental Insurance
  • Vision Insurance
  • Disability, Life Insurance, and AD&D
  • Flexible Spending Accounts
  • Pre-Tax 401K and/or After-Tax Roth IRA (with employer matching contribution)
  • Tuition and Technical Training Reimbursement
  • Exercise Reimbursement
  • Computer Reimbursement
  • Employee Assistance Program

Physical Demands: The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

  • While performing the duties of this job, the employee is regularly required to talk or hear.
  • Possess the ability to fulfill any and all office activities normally expected in an office setting, to include, but not limited to:  remaining seated for periods of time to perform computer entry, participating in filing activity, lifting and carrying office supplies.
  • The employee must occasionally lift and/or move up to fifteen (15) pounds.
  • Fine hand manipulation (keyboarding).

Work Environment:  The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job.  Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

  • May work prolonged or irregular hours.
  • The noise level in the work environment is usually moderate.
  • Exposure to general office conditions while conducting office duties.

Working at Edgewater Federal Solutions:

Edgewater Federal Solutions is a privately held government contracting firm located in Frederick, MD. The company was founded in 2002 with the vision of being highly recognized and admired for supporting customer missions through employee empowerment, exceptional services, and timely delivery. Edgewater Federal Solutions is ISO 9001, 20000-1, 270001 certified, appraised at CMMI Level 3 Maturity for Development and Services, and has been named in the Top Workplaces in the Greater Washington Area Companies since 2018.

 

Edgewater Federal Solutions is an Equal Opportunity Employer. It has been and continues to be our policy to provide equal employment to all employees and applicants for employment without regard to race, color, religion, gender, national origin, age, disability, marital status, veteran status and/or other status protected by applicable law. #LI-KC1

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed