Summary
GuidePoint Security provides cybersecurity expertise, solutions, and services that help organizations minimize risk. The Microsoft Security Engineer will deliver hands-on Microsoft-focused security engagements, primarily involving Entra ID, Purview, Intune, and Defender XDR, while independently managing technical delivery and collaborating with architects and consultants.
Responsibilities
- **Identity & Access (Entra ID / AD):** Design and implement identity architecture, hybrid sync (Entra Connect), Conditional Access, MFA/passwordless, and identity governance (PIM, RBAC, access reviews, entitlement management)
- Integrate applications via SSO (SAML/OIDC), enterprise app registrations, and SCIM provisioning
- Investigate and remediate identity risks using Entra ID Protection, sign-in and audit logs; drive hybrid identity hygiene (stale object cleanup, privileged account reduction, tiered admin models)
- **Data Security & Compliance (Purview):** Design and implement sensitivity labels, DLP, and retention policies across M365; support data classification, information protection rollouts, and data security posture assessments
- Support eDiscovery, Insider Risk Management, communication compliance, and AI data security readiness (DSPM for AI) as engagements require
- **Intune & Defender XDR:** Configure device compliance, configuration profiles, and app deployments across platforms; support Defender for Endpoint, Office 365, Identity, and Cloud Apps in cloud and hybrid environments
- Other duties as assigned
- Adhere to GuidePoint Security Core Values
Skills
- * Bachelor's degree preferred
- * 2–5 years in IT administration, identity management, or security operations
- * Hands-on production experience with Microsoft Entra ID and on-premises Active Directory, including Conditional Access, MFA, RBAC, and hybrid identity (Entra Connect)
- * Knowledge of core authentication protocols: SAML, OAuth 2.0/OIDC, Kerberos, LDAP
- * Experience implementing Microsoft Purview (sensitivity labels, DLP, retention, or eDiscovery) and comfort supporting Intune and Defender XDR
- * Basic PowerShell scripting for automation and reporting (e.g., Microsoft Graph PowerShell)
- * Strong troubleshooting skills, attention to detail, and clear written and verbal communication
- * Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
- * This role is 100% remote requiring less than 10% travel for corporate events
- * Sedentary work
- * Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day
- * Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day
- * Advanced AD work: multi-domain/forest design, migrations, tiered administration, legacy auth cleanup
- * Microsoft Sentinel: log onboarding, detection development, or broader SIEM/SOAR experience
- * Azure infrastructure and security (Azure Policy, network security, landing zones, RBAC)
- * SharePoint Online governance, Teams Voice, Power BI/Fabric, or Copilot Studio/Azure AI Foundry experience
Qualifications
Must Haves
- * Bachelor's degree preferred
- * 2–5 years in IT administration, identity management, or security operations
- * Hands-on production experience with Microsoft Entra ID and on-premises Active Directory, including Conditional Access, MFA, RBAC, and hybrid identity (Entra Connect)
- * Knowledge of core authentication protocols: SAML, OAuth 2.0/OIDC, Kerberos, LDAP
- * Experience implementing Microsoft Purview (sensitivity labels, DLP, retention, or eDiscovery) and comfort supporting Intune and Defender XDR
- * Basic PowerShell scripting for automation and reporting (e.g., Microsoft Graph PowerShell)
- * Strong troubleshooting skills, attention to detail, and clear written and verbal communication
- * Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
- * This role is 100% remote requiring less than 10% travel for corporate events
- * Sedentary work
- * Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day
- * Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day
Nice to Haves
- * Advanced AD work: multi-domain/forest design, migrations, tiered administration, legacy auth cleanup
- * Microsoft Sentinel: log onboarding, detection development, or broader SIEM/SOAR experience
- * Azure infrastructure and security (Azure Policy, network security, landing zones, RBAC)
- * SharePoint Online governance, Teams Voice, Power BI/Fabric, or Copilot Studio/Azure AI Foundry experience
Benefits
- Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
- Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
- Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
- 12 corporate holidays and a Flexible Time Off (FTO) program
- Healthy mobile phone and home internet allowance
- Eligibility for retirement plan after 2 months at open enrollment
- Pet Benefit Option