B5 Recruiting

Security Engineer – Microsoft Security

Washington, District of ColumbiaFull-time
$150,000+ annually
About the Job
Overview
B5 Recruiting is partnering with a client seeking an experienced Security Engineer to support the implementation and maturation of its Microsoft security ecosystem.

This position will play a key role in strengthening enterprise security controls across endpoints, cloud infrastructure, identities, email, and business applications. The engineer will be responsible for configuring and integrating Microsoft security technologies, improving compliance visibility, and helping transition newly implemented controls into day-to-day security operations.

The ideal candidate brings strong hands-on experience with Microsoft Defender XDR, Microsoft Purview, Defender for Endpoint, Defender for Cloud, Azure security, and Microsoft Sentinel, along with the ability to work cross-functionally with security operations, governance, compliance, and audit teams.

Key Responsibilities:
Microsoft Purview & Data Protection:
  • Configure and expand Microsoft Purview Data Loss Prevention controls across endpoints, Microsoft 365 environments, email, and supported cloud applications.
  • Review policy coverage and identify potential gaps that could create compliance or data protection risks.
  • Partner with governance and compliance stakeholders to translate organizational requirements into practical DLP controls.
  • Support ongoing policy tuning, monitoring, and audit preparation.
Endpoint Security & Threat Prevention:
  • Configure and implement Microsoft Defender for Endpoint security controls, including Attack Surface Reduction (ASR) rules.
  • Evaluate security controls against prioritized threat scenarios and established cybersecurity frameworks.
  • Tune endpoint policies to balance security effectiveness with business operations and minimize unnecessary alerts or disruptions.
  • Connect endpoint telemetry and alerts with Microsoft Sentinel to improve investigation and incident-response workflows.

Azure & Cloud Security:
  • Support the modernization of Azure security and compliance monitoring using telemetry-driven controls and reporting.
  • Configure Microsoft Defender for Cloud across IaaS and PaaS environments.
  • Maintain cloud security policies aligned with organizational security standards and applicable regulatory frameworks, including FedRAMP-related controls.
  • Use Azure governance capabilities such as Azure Policy, Secure Score, and automated remediation to improve security posture and reduce manual intervention.

Microsoft Defender XDR Integration:
  • Help design and maintain an integrated Microsoft security environment across technologies such as:
    • Microsoft Defender for Endpoint
    • Microsoft Defender for Identity
    • Microsoft Defender for Office 365
    • Microsoft Defender for Cloud Apps
    • Microsoft Defender for Servers
    • Microsoft Sentinel
  • Improve visibility and correlation of security events across endpoint, identity, cloud, and collaboration environments.
  • Support the use and configuration of Microsoft Copilot for Security to improve SOC investigation and response workflows.
  • Assist with testing, troubleshooting, and optimization of integrations across the Microsoft security stack.

Operational Readiness & Knowledge Transfer:
  • Develop documentation, procedures, and operational playbooks for newly implemented security capabilities.
  • Partner with SOC and cybersecurity teams to transition solutions from implementation into steady-state operations.
  • Provide knowledge transfer and training to security personnel on new controls, features, dashboards, and investigation workflows.
  • Support audit, compliance, and security teams with evidence collection and control validation when required.

What We’re Looking For:
  • U.S. Citizenship required.
  • Must reside within reasonable commuting distance of Washington, DC.
  • Strong hands-on experience with Microsoft Defender XDR and the Microsoft security ecosystem.
  • Experience implementing or administering Microsoft Defender for Endpoint, including ASR policies.
  • Practical knowledge of Microsoft Purview and Data Loss Prevention controls.
  • Experience with Microsoft Defender for Cloud and Azure security/compliance controls.
  • Familiarity with Microsoft Sentinel, SIEM integrations, security monitoring, and incident response.
  • Understanding of Azure governance and security technologies such as Azure Policy and Secure Score.
  • Experience working in environments with formal security, regulatory, or audit requirements.
  • Ability to document technical processes and collaborate with SOC, cybersecurity, compliance, governance, and audit stakeholders.

Experience with FedRAMP, FERC-related security requirements, Microsoft Copilot for Security, or large enterprise Microsoft security deployments would be highly valuable.