On-site role; current U.S. Government Secret clearance or higher; ITAR-authorized U.S. Person Position Summary SRG Government Services is supporting a growing defense organization seeking a Cyber Security Engineer to help protect sensitive data, systems, and Microsoft 365 environments while supporting cybersecurity compliance, security operations, and secure collaboration across the enterprise. This individual will support the implementation and maintenance of security controls, respond to security incidents, strengthen the organization's security posture, and help ensure compliance with relevant cybersecurity frameworks and regulatory requirements. Ideal Candidate Profile The ideal candidate will have hands-on cybersecurity experience in Microsoft 365, SharePoint, DLP, vulnerability management, compliance, and secure data handling. This person should be comfortable supporting a regulated defense environment, communicating with technical and non-technical stakeholders, and helping strengthen enterprise security controls and compliance posture. This individual needs to be proactive, detail-oriented, and comfortable working independently and collaboratively in a fast-paced, highly regulated environment. Key Responsibilities Develop, implement, and maintain cybersecurity policies, procedures, and standards in alignment with industry best practices and regulatory requirements, including
NIST 800-171
Rev. 3, ISO 27001, GDPR, UK Cyber Essentials, and related frameworks.
Support ongoing compliance with relevant cybersecurity regulations, frameworks, and internal security requirements.
Design, implement, manage, and fine-tune Data Loss Prevention solutions to protect sensitive information and reduce false positives.
Monitor DLP alerts, investigate potential data exposure events, and support remediation activities.
Administer and maintain SharePoint environments across multiple tenants, including user access, permissions, security settings, and policy enforcement.
Assist with planning, implementation, configuration, and security best practices for Microsoft 365 GCC High tenant environments.
Support data tagging, classification, and migration strategies to protect sensitive information and align with compliance requirements.
Automate secure data-sharing processes and workflows for vetted and approved users where possible.
Monitor security alerts, vulnerability scans, and vulnerability reports; prioritize remediation efforts and track corrective actions.
Support timely patching and remediation of identified weaknesses across systems and environments.
Respond to security incidents and breaches, including investigation, documentation, and corrective action support.
Contribute to the development and delivery of security awareness training programs for employees.
Collaborate with IT teams and business stakeholders to ensure cybersecurity is integrated into enterprise systems, processes, and initiatives.
Provide regular updates on security status, risks, remediation activities, and cybersecurity initiatives.
Perform other work as directed by management.
Required QualificationsCurrent U.S. Government Secret clearance or higher required.
ITAR-authorized U.S. Person required; candidates must be U.S. citizens, lawful permanent residents, or otherwise qualifying protected individuals authorized to access ITAR-controlled information.
Bachelor's degree in Computer Science, Cybersecurity, or a related field.1 to 3 years of relevant cybersecurity experience.
Cybersecurity engineering experience, preferably in a regulated industry.
Strong understanding of cybersecurity frameworks and regulations, including
NIST, ISO
27001, HIPAA, and related GRC tools.
Experience with Data Loss Prevention technologies and sensitive-data protection.
Experience with SharePoint administration, including multi-tenant environments.
Hands-on experience with Microsoft 365 security features.
Experience with GCC High implementation and management is highly desirable.
Knowledge of data tagging, classification, and secure migration techniques.
Experience with DoD acquisition processes and DoD contracting requirements preferred.
Ability to build and maintain relationships with government officials, defense organizations, and industry stakeholders.
Excellent communication, negotiation, and presentation skills.
Self-starter with strong analytical, troubleshooting, and problem-solving skills.
Ability to work independently and as part of a team in a fast-paced and dynamic environment.
Willingness to travel domestically as needed.
ISO 9001
2015 training preferred.
Proficiency with Microsoft Office, including Word, Excel, Outlook, PowerPoint, and Project. Preferred Qualifications Relevant cybersecurity certifications, such as Security+, CISSP, CISM, or Microsoft certifications.
Experience with scripting languages such as PowerShell or Python.
Knowledge of cloud security best practices.
Experience with security information and event management systems.
Experience supporting Microsoft 365 GCC High, CMMC/NIST 800-171, ITAR, or other defense cybersecurity compliance environments. Physical Demands & Abilities Ability to walk, stand, use computers, and occasionally lift or exert up to 25 lbs.
Ability to frequently lift or exert up to 10 lbs.
Ability to sit for extended periods while using office equipment and computers.
Ability to move regularly from sitting to standing positions.