Senior Microsoft Cloud Security Engineer

CACIArlington, VA
$131,800 - $290,000

About The Position

CACI has an exciting position for a Senior Microsoft Cloud Security Engineer as we deploy, manage, and hardening our Microsoft cloud environment, including Azure, Office 365 and Microsoft 365. The Senior Microsoft Cloud Security Engineer should thrive on complexity, possess an analytical mindset, and bring deep expertise on managing and securing Microsoft's cloud platform. You'll collaborate across teams, collaborating with security engineers, cloud architects, identity teams, and incident response analysts to ensure our tenant is resilient, compliant, and always mission ready.

Requirements

  • Ability to Obtain DHS EOD Public Trust Clearance
  • Master’s Degree + 10 years’ experience OR Bachelor’s degree + 13 years OR 19 years total experience
  • Expert-level hands-on experience deploying, managing, and securing Azure, Entra, Defender, Purview, Office 365, and Microsoft 365 in large enterprises.
  • Deep understanding of Conditional Access Policies (CAPs), Azure AD/Entra, and Zero Trust principles.
  • Proven Track record implementing and managing the full suite of the Microsoft Defender ecosystem and Microsoft Purview (DLP, sensitivity labels, eDiscovery)
  • Advanced proficiency writing KQL for detection, investigation, response, and reporting
  • Active, expert-level certification such as Microsoft Certified Solutions Expert (MSCE), Microsoft 365 Admin Expert, Microsoft Cybersecurity Architect Expert, AZ-900, AZ-500, SC-900, SC-100, SC-200, SC-300, SC-400, SC-401
  • Cybersecurity certifications: Security+
  • Strong networking, firewall, VPN, and segmentation knowledge as it relates to cloud deployments
  • Exceptional time management, written and communication skills.
  • Participate in rotating on-call schedule across the team, to provide incident response or support during outages.

Nice To Haves

  • CISSP, OSCP, GCIH
  • ITIL, Agile, or PMP familiarity/certification
  • Experience with SOAR platforms (e.g. Splunk, Microsoft Sentinel)
  • Hands-on exposure to third-party cloud security tooling (CASBs, CNAAPs, SD-WANs)
  • Previous consulting or client-facing delivery experience

Responsibilities

  • Serve as the go-to, subject matter expert (SME) for securing the Microsoft cloud tenant, advising on architecture, design, and implementation of secure solutions across Azure, O365, and M365.
  • Lead the development and enforcement of Conditional Access Policies, aligned with best practices for managing access control for personas, groups, and applications.
  • Act as the primary SME in optimizing the Microsoft Defender suite of components (Defender for Endpoint, Defender for Cloud, Defender for Identity, and Defender for Office 365)
  • Implement Microsoft Purview, including data classification and sensitivity labels, Data Loss Prevent (DLP), and eDiscovery workflows.
  • Design, run and optimize Kusto Query Language (KQL) queries for Azure Sentinel, Defender, and log analytics.
  • Review and remediate security controls through vulnerability assessments, penetration tests, and red/blue team engagements.
  • Guide cross-functional teams on security controls, compliance requirements, policy, and governance best practices

Benefits

  • healthcare
  • wellness
  • financial
  • retirement
  • family support
  • continuing education
  • time off benefits
  • flexible time off benefit
  • robust learning resources
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service