1

Microsoft Security Engineer Jobs (NOW HIRING)

Microsoft Cloud Security Engineer

Washington, DC · On-site

$63.25 - $84.50/hr

Description Chevo LLC is seeking a Microsoft Cloud Security Engineer to serve as a Key Personnel on the DOI Office of Wildland Fire (OWF) FireNet Enterprise Business Services contract. FireNet is a ...

New

Experience working with tools such as Microsoft Defender, Microsoft Intune, Okta, SIEM platforms ... The Systems Security Engineer will play a key role in designing, implementing, and maintaining ...

Engineer, operate, and continuously improve the Microsoft Defender security stack (e.g., Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, Defender ...

New

Senior Security Engineer

Austin, TX · On-site

$112K - $209K/yr

... Microsoft Graph, and cloud-native technologies • Implementing and optimize Azure security ... engineers, and providing architecture guidance, standards, and documentation EXPERIENCE & SKILLS ...

New

Engineer, operate, and continuously improve the Microsoft Defender security stack (e.g., Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, Defender ...

This position provides engineering and operational support for Microsoft's enterprise security platform, helping implement and maintain Zero Trust security capabilities across identity, endpoint ...

An engineering mindset, attention to detail, and a preference for pragmatic solutions are essential ... Strengthen Microsoft 365 and Entra ID security through Conditional Access, MFA, PIM, Defender for ...

This position provides engineering and operational support for Microsoft's enterprise security platform, helping implement and maintain Zero Trust security capabilities across identity, endpoint ...

An engineering mindset, attention to detail, and a preference for pragmatic solutions are essential ... Strengthen Microsoft 365 and Entra ID security through Conditional Access, MFA, PIM, Defender for ...

Security Engineer

Chicago, IL · On-site

$100 - $130/hr

An engineering mindset, attention to detail, and a preference for pragmatic solutions are essential ... Maintain and tune security tools across AWS, Microsoft 365, endpoints, and network infrastructure.

New

Showing results 41-60

Microsoft Security Engineer information

See salary details

$61.5K

$152.8K

$205.5K

How much do microsoft security engineer jobs pay per year?

As of Aug 7, 2026, the average yearly pay for microsoft security engineer in the United States is $152,773.00, according to ZipRecruiter salary data. Most workers in this role earn between $143,000.00 and $158,500.00 per year, depending on experience, location, and employer.

What challenges do Microsoft Security Engineers face when securing cloud environments, and how are they addressed?

Microsoft Security Engineers often encounter challenges such as managing complex identity and access controls, monitoring for evolving threats, and ensuring compliance across hybrid or multi-cloud environments. These are typically addressed by implementing robust Azure security best practices, automating security monitoring with tools like Microsoft Defender, and collaborating closely with development and IT teams to maintain secure configurations. Staying updated with the latest security features and regularly participating in security training also helps engineers proactively tackle emerging threats.

What skills and qualifications are needed to be a Microsoft Security Engineer?

To thrive as a Microsoft Security Engineer, you need a strong background in information security principles, experience with Microsoft security solutions (such as Azure Security Center, Microsoft Defender, and Active Directory), and relevant certifications like Microsoft Certified: Security, Compliance, and Identity Fundamentals or Microsoft Certified: Security Operations Analyst Associate. Familiarity with security monitoring tools, SIEM platforms, and scripting languages like PowerShell is typically required. Strong problem-solving abilities, attention to detail, and effective communication are essential soft skills for this role. These skills and qualifications are crucial for identifying vulnerabilities, implementing robust security measures, and ensuring the ongoing protection of organizational data and systems.

What is the difference between Microsoft Security Engineer vs Cybersecurity Analyst?

AspectMicrosoft Security EngineerCybersecurity Analyst
CertificationsMicrosoft Certified: Security, Compliance, and Identity Fundamentals; CompTIA Security+CompTIA Security+; GIAC Security Essentials (GSEC)
Work EnvironmentFocus on Microsoft security tools, cloud security, and enterprise environmentsBroader security monitoring, incident response, and threat analysis across various platforms
Employer & Industry UsagePrimarily in organizations using Microsoft products and cloud servicesAcross diverse industries, including finance, healthcare, and government

The Microsoft Security Engineer specializes in securing Microsoft environments, cloud security, and compliance, often working with Microsoft tools and platforms. In contrast, a Cybersecurity Analyst has a broader focus on monitoring, analyzing, and responding to security threats across multiple systems and platforms. Both roles require security certifications and are vital in protecting organizational assets, but they differ in scope and technical focus.

What is a Microsoft Security Engineer?

Microsoft Security Engineers are IT professionals who specialize in designing, implementing, and managing security solutions within Microsoft environments. They work to protect an organization's data, systems, and networks by configuring security tools, monitoring for threats, and responding to incidents. Their responsibilities often include ensuring compliance with security policies, managing identity and access controls, and staying current with evolving cybersecurity threats. They may work with on-premises, cloud, or hybrid infrastructures, particularly focusing on Microsoft technologies such as Azure, Microsoft 365, and Windows security tools.
More about Microsoft Security Engineer jobs
What cities are hiring for Microsoft Security Engineer jobs? Cities with the most Microsoft Security Engineer job openings:
What states have the most Microsoft Security Engineer jobs? States with the most job openings for Microsoft Security Engineer jobs include:
What job categories do people searching Microsoft Security Engineer jobs look for? The top searched job categories for Microsoft Security Engineer jobs are:
Infographic showing various Microsoft Security Engineer job openings in the United States as of August 2026, with employment types broken down into 84% Full Time, 13% Part Time, and 3% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $152,773 per year, or $73.4 per hour.

Microsoft Cloud Security Engineer

Chevo LLC

Washington, DC • On-site

$63.25 - $84.50/hr

Other

Medical, Dental, Vision, Retirement, PTO

Posted 2 days ago

New


Job description

Description

Chevo LLC is seeking a Microsoft Cloud Security Engineer to serve as a Key Personnel on the DOI Office of Wildland Fire (OWF) FireNet Enterprise Business Services contract. FireNet is a Microsoft 365/Azure-based interagency collaboration platform supporting federal, state, tribal, and local wildland fire operations across DOI, USDA Forest Service, and non-federal partners. This role is essentially an O365 security engineer with experience with Entra ID and Azure system management. Chosen candidate will oversee the hands-on security engineering for the FireNet tenant and is expected to implement all recommendations in the necessary administration portals, including Microsoft Entra, Azure Portal, Microsoft Defender, Microsoft Sentinel, Microsoft Purview, Exchange Online, Intune, and the Microsoft 365 Admin Center.


Duties & Responsibilities:

  • Engineer, implement, and continuously improve the security posture of the FireNet Microsoft 365 and Azure environment. 
  • Configure and maintain Entra ID Conditional Access policies, Multi-Factor Authentication (MFA), and Privileged Identity Management (PIM) to enforce a zero-trust, least-privilege posture across all privileged and high-risk roles. 
  • Manage guest and external identity lifecycle including entitlement management, access packages, and periodic access reviews in coordination with Government ISSOs and program stakeholders.
  • Oversee Microsoft Secure Score and Identity Secure Score improvements, developing and executing a monthly action plan to achieve net-positive score improvements and remediating critical findings within 10 business days or an approved POA&M. 
  • Build administer and maintain Microsoft Defender for Cloud (including anti-phishing, anti-malware, Safe Links, Safe Attachments, and attack surface reduction controls.) and Microsoft Sentinel analytics rules, incident playbooks, KQL workbooks, and queries to detect and respond to threats across the tenant. 
  • Support Purview data loss prevention and sensitivity label implementation as authorized by the Government and ensure all logging and telemetry pipelines are configured for continuous monitoring IAW the DOI Continuous Monitoring Plan and FISMA requirements.
  • Conduct threat hunting, vulnerability management, security assessments, and remediation activities using Microsoft security platforms and industry best practices.
  • Provide on-call coverage for Priority 1 security and platform incidents, with expectations to acknowledge within 30 minutes, begin triage within 1 hour, and restore or implement a workaround within 4 hours. 
  • Lead technical incident response activities including investigation, containment, eradication, recovery, and post-incident reporting in coordination with IT Project Manager and Government stakeholders.
  • Prepare CAB packets for security-scoped changes, coordinate with the Power Platform Lead and Web Development team on security controls and DevOps pipeline guardrails, and contribute to monthly Security Posture Reports and knowledge transfer documentation for Government ISSOs.
  • Review and provide security architecture recommendations for new Azure, Microsoft 365, Power Platform, automation, and application integration initiatives to ensure alignment with Zero Trust and Federal security requirements.
  • Develop and maintain security automation solutions using PowerShell, Microsoft Graph, Azure CLI, Logic Apps, or other approved tools to improve operational efficiency and consistency.

Requirements

Required Qualifications
  • Bachelor's degree in computer science, Information Security, Information Technology, or a related field preferred. 
  • Additional years of directly relevant experience may substitute for degree requirements consistent with the Contractor's MAS pricelist.
  • Demonstrated, hands-on engineering enterprise Microsoft 365 and Azure security environments, including deep proficiency with Entra ID/Azure Active Directory, Conditional Access, PIM, MFA, and zero-trust architecture principles. 
  • Experience with Microsoft Defender for Cloud, Microsoft Sentinel, and KQL for custom analytics rules and threat hunting is required. You should be familiar with Microsoft Purview and data governance control within a government environment.
  • Demonstrated experience with Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Intune, and endpoint security management is strongly preferred.
  • Experience operating in DOI, FISMA, FedRAMP, or NIST 800-53 compliance environments is strongly preferred. Familiarity with DOI or other Federal agency security operations and authorization-to-operate (ATO/A&A) documentation is a plus. 
  • Experience developing administrative and security automation using PowerShell, Microsoft Graph API, Azure CLI, Logic Apps, or similar technologies is desirable. 
  • Must be able to obtain and maintain a Federal Public Trust (NACI) and be comfortable serving in an on-call capacity during national wildland fire preparedness seasons (National Preparedness Level 3-5).
  • Relevant Microsoft certifications such as SC-100 (Cybersecurity Architect), SC-200 (Security Operations Analyst), SC-300 (Identity and Access Administrator), or AZ-500 (Azure Security Engineer) are highly desirable and may substitute for certain experience requirements consistent with the GSA MAS pricelist.

SALARY RANGE: $145K - $170K (subject to change)

ELIGIBLE FOR PERFORMANCE BASE BONUS 


Chevo offers a comprehensive benefits package including medical, dental and vision coverage, paid leave, observes all 11 federal government holidays, 401K plan with matching, monthly SMART card employer contribution for commuting expenses, tuition assistance and more! 


Chevo, a Women-Owned Small Business (WOSB), has made Consulting Magazine's 2023 and 2024 "Best Firms to Work For" list and is a 2023, 2024, 2025, and 2026 Elev8 GovCon honoree. Chevo is a nine-time awardee of the Alliance for Workplace Excellence award; ranked one of the best Small Business Strategy firms by Consulting Magazine; made the Washington Technology Fast 50 list; and has earned multiple Program Management Industry awards. 


Chevo is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, disability, military status, national origin, or any other characteristic protected under federal, state, or applicable local law.