Summary
Edgewater Federal Solutions, Inc. is a government contracting firm supporting customer missions through technology and professional services. The Microsoft Security Engineer performs hands-on administration, monitoring, investigation, remediation, and documentation across Microsoft security technologies, including Microsoft 365, Azure, Entra ID, Defender, and Sentinel. The role supports identity security, incident response, vulnerability management, compliance, and security automation under the direction of the Director of IT.
Responsibilities
- Administer Microsoft Entra ID security controls in accordance with approved standards and direction
- Support implementation and ongoing maintenance of Conditional Access policies
- Assist with multifactor authentication, passwordless authentication, authentication methods, and Identity Protection investigations
- Support Privileged Identity Management, access reviews, and least-privilege access practices
- Escalate identity risks, policy exceptions, and proposed design changes to the Director of IT
- Administer and maintain Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and applicable Microsoft Defender XDR capabilities
- Monitor endpoint, email, identity, and cloud security alerts and perform initial investigation and response
- Maintain approved email security controls, including anti-phishing policies, Safe Links, Safe Attachments, SPF, DKIM, and DMARC
- Support security controls for Microsoft Teams, SharePoint Online, OneDrive, and other Microsoft 365 services
- Implement approved Microsoft Secure Score and security posture recommendations and document completed improvements
- Monitor, analyze, and respond to security alerts and incidents using Microsoft Sentinel, Microsoft Defender, and related security tools
- Maintain Sentinel data connectors, analytics rules, workbooks, dashboards, incident workflows, and approved automation
- Perform initial root-cause analysis, document findings, and coordinate assigned remediation activities
- Escalate significant or complex incidents in accordance with approved incident response procedures
- Assist the Director of IT and external specialists during major incidents, forensic investigations, and post-incident reviews
- Review vulnerability findings and Microsoft security recommendations
- Coordinate assigned remediation activities with infrastructure, cloud, network, application, and endpoint owners
- Validate remediation where practical and maintain status documentation and supporting evidence
- Support implementation of approved security baselines and hardening standards
- Escalate overdue, high-risk, or exception requests to the Director of IT for prioritization and risk decisions
- Assist with Microsoft Purview and other approved data protection controls, including Data Loss Prevention, sensitivity labels, information protection, and retention capabilities
- Support audits, compliance reviews, and risk assessments by collecting evidence and maintaining documentation
- Develop and maintain security procedures, configuration records, operational runbooks, and incident response documentation
- Assist with security awareness initiatives and provide technical guidance to internal IT teams within established standards
- Use PowerShell, Kusto Query Language, Logic Apps, or similar tools to improve repeatable security administration and reporting
- Recommend operational improvements and assist with approved implementation
- Stay current with Microsoft security technologies, emerging threats, vulnerabilities, and relevant industry practices
Skills
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, a related field, or equivalent practical experience
- Three or more years of cybersecurity, information security, systems administration, or security operations experience
- Hands-on experience administering security controls in Microsoft 365, Microsoft Entra ID, or Microsoft Azure
- Experience investigating alerts in Microsoft Defender and/or Microsoft Sentinel
- Working knowledge of Conditional Access, multifactor authentication, endpoint protection, email security, and identity security concepts
- Familiarity with vulnerability management, incident response, security monitoring, and cloud security practices
- Working knowledge of PowerShell and basic Kusto Query Language
- Ability to follow established standards, document work clearly, recognize when escalation is required, and manage multiple priorities
- Strong analytical, troubleshooting, communication, customer service, and collaboration skills
- Microsoft Security Platforms
- Microsoft Sentinel
- Microsoft Defender XDR
- Microsoft Defender for Endpoint
- Microsoft Defender for Office 365
- Microsoft Defender for Identity
- Microsoft Entra ID
- Microsoft Purview
- Conditional Access and multifactor authentication
- Microsoft Azure and Microsoft 365
- Identity Protection and Privileged Identity Management
- Incident investigation and security monitoring
- Vulnerability remediation coordination
- Data Loss Prevention and information protection
- PowerShell
- Kusto Query Language
- Logic Apps
- While performing the duties of this job, the employee is regularly required to talk or hear
- Possess the ability to fulfill any and all office activities normally expected in an office setting, to include, but not limited to: remaining seated for periods of time to perform computer entry, participating in filing activity, lifting and carrying office supplies
- The employee must occasionally lift and/or move up to fifteen (15) pounds
- Fine hand manipulation (keyboarding)
- May work prolonged or irregular hours
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- CompTIA Security+ or a comparable foundational security certification
- Experience with Microsoft Defender for Endpoint, Defender for Office 365, Microsoft Purview, Logic Apps, or security automation
- Experience supporting audit evidence collection or regulatory compliance activities
- Familiarity with Python or Bash is beneficial but not required
- The ideal candidate can work remotely but may be needed on-site at the Frederick MD or Reston VA offices for special operations. Candidates that live in the MD/DC/VA area are strongly preferred
Qualifications
Must Haves
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, a related field, or equivalent practical experience
- Three or more years of cybersecurity, information security, systems administration, or security operations experience
- Hands-on experience administering security controls in Microsoft 365, Microsoft Entra ID, or Microsoft Azure
- Experience investigating alerts in Microsoft Defender and/or Microsoft Sentinel
- Working knowledge of Conditional Access, multifactor authentication, endpoint protection, email security, and identity security concepts
- Familiarity with vulnerability management, incident response, security monitoring, and cloud security practices
- Working knowledge of PowerShell and basic Kusto Query Language
- Ability to follow established standards, document work clearly, recognize when escalation is required, and manage multiple priorities
- Strong analytical, troubleshooting, communication, customer service, and collaboration skills
- Microsoft Security Platforms
- Microsoft Sentinel
- Microsoft Defender XDR
- Microsoft Defender for Endpoint
- Microsoft Defender for Office 365
- Microsoft Defender for Identity
- Microsoft Entra ID
- Microsoft Purview
- Conditional Access and multifactor authentication
- Microsoft Azure and Microsoft 365
- Identity Protection and Privileged Identity Management
- Incident investigation and security monitoring
- Vulnerability remediation coordination
- Data Loss Prevention and information protection
- PowerShell
- Kusto Query Language
- Logic Apps
- While performing the duties of this job, the employee is regularly required to talk or hear
- Possess the ability to fulfill any and all office activities normally expected in an office setting, to include, but not limited to: remaining seated for periods of time to perform computer entry, participating in filing activity, lifting and carrying office supplies
- The employee must occasionally lift and/or move up to fifteen (15) pounds
- Fine hand manipulation (keyboarding)
- May work prolonged or irregular hours
Nice to Haves
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- CompTIA Security+ or a comparable foundational security certification
- Experience with Microsoft Defender for Endpoint, Defender for Office 365, Microsoft Purview, Logic Apps, or security automation
- Experience supporting audit evidence collection or regulatory compliance activities
- Familiarity with Python or Bash is beneficial but not required
- The ideal candidate can work remotely but may be needed on-site at the Frederick MD or Reston VA offices for special operations. Candidates that live in the MD/DC/VA area are strongly preferred
Benefits
- Paid Time Off & Holiday Pay
- Medical Insurance
- Dental Insurance
- Vision Insurance
- Disability, Life Insurance, and AD&D
- Flexible Spending Accounts
- Pre-Tax 401K and/or After-Tax Roth IRA (with employer matching contribution)
- Tuition and Technical Training Reimbursement
- Exercise Reimbursement
- Computer Reimbursement
- Employee Assistance Program
- The ideal candidate can work remotely but may be needed on-site at the Frederick MD or Reston VA offices for special operations.