This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are seeking a Systems Engineer to own, architect, and maintain our Microsoft security stack (O365 Sentinel, Defender, Purview) and overall electronic communications and file sharing technology infrastructure. This role will be critical in ensuring our environment remains secure, NIST 800-171 compliant, observable, and scalable. The ideal candidate blends hands-on engineering, strong security operations experience, and the ability to design and maintain dashboards, reporting, and automation to support security governance, risk, and compliance.
Job Responsibility:
Administer and maintain security tooling across the Microsoft environment. Microsoft Sentinel, Microsoft Defender, and Microsoft Purview (or equivalent Microsoft 365 / Purview data governance tools)
In conjunction with MSP, manage and optimize security dashboards, alerts, and reporting for threat detection, incident response, and risk metrics. Own vendor response management and success metrics
Build and maintain compliance reporting to support NIST 800-171 controls, working with compliance lead and vendors to align technical controls with policy
Implement and maintain security tooling (automation, playbooks) to reduce manual work, improve reaction times, and ensure consistency
Own change management documentation for all security-related system changes across our Microsoft cloud environment, including SIEM, endpoint security, identity, and data governance controls
Monitor security events, triage alerts, investigate potential incidents, and support remediation efforts in coordination with other MSP. Escalate to Compliance and Ops leads for org messaging and alerts
Conduct regular tuning of detection rules, logs, and telemetry to reduce noise and improve coverage
Assist MSP in threat hunting, threat modeling, and proactive security assessments
Manage data governance and classification via Purview (or equivalent): define and enforce data classification, labeling, retention, and access policies
Provide technical oversight for user and endpoint security posture
integrate Defender with identity, endpoint, and cloud infrastructure
Maintain and test incident response procedures and playbooks with regards to Covered Unclassified Information (CUI)
Support security best practices for cloud infrastructure, identity management, access control, and data protection
Provide training and mentorship to other IT staff on Sentinel, Defender, Purview, and security processes
Collaborate with auditors, compliance leads, and external assessors to prepare for assessments (e.g., NIST, CMMC ISO, etc.)
Stay current on Microsoft security offerings, emerging threats, and best practices, and make recommendations for improvements
Requirements:
Bachelor’s degree in computer science, information technology, cybersecurity, or related field (or equivalent experience)
Minimum 2–4 years of experience in security operations, systems engineering, or cloud security
Hands-on experience deploying, operating, and maintaining Microsoft Sentinel, Microsoft Defender (endpoint, identity, etc.), and Purview (or similar Microsoft security/GRC tools)
Understanding of SIEM, security alerts, log aggregation, and incident response
Experience building dashboards, reports, and alerts to drive visibility and compliance
Scripting, automation, or orchestration experience (PowerShell, Azure Automation, Logic Apps, or similar)
Nice to have:
Familiarity with NIST 800-171 (or other government / federal security compliance frameworks) and how technical controls map to its requirements
Certifications such as CISSP, CCSP, Microsoft SC-200 / SC-300 / SC-400, or Azure Security Engineer Associate
Familiarity with Azure cloud infrastructure Azure and identity management (Azure AD, conditional access, etc.)
Experience in federal contracting environments or regulated industries (with NIST, FedRAMP, or similar)
Prior work in a small or mid-size business environment
tribal organization experience is a plus but not required
Strong problem-solving skills, with the ability to triage security events and lead investigations
Excellent communication skills—able to translate technical security metrics into meaningful reports for leadership, auditors, and compliance teams
Self-starter with a growth mindset
comfortable working in a smaller, evolving organization of about 200-250 users