Security Engineer

Posted 15 Days Ago
Be an Early Applicant
Rock Springs, MD, USA
In-Office
100K-120K Annually
Mid level
Logistics • Transportation • Industrial
The Role
Design, implement, validate, and maintain standardized endpoint security baselines across Intune, MECM, and Jamf Pro for Windows and macOS. Configure Defender, BitLocker/FileVault, ASR rules, Conditional Access, and compliance policies; test and rollout baselines, perform impact assessments, troubleshoot policy conflicts, document procedures, and collaborate with cybersecurity, RMF/ISSO, and engineering teams to meet federal security requirements.
Summary Generated by Built In

CNI seeking an Endpoint Security Baseline Engineer to support the engineering, implementation, and operational management of enterprise endpoint security configurations across Microsoft Intune, Microsoft Endpoint Configuration Manager (MECM), and Jamf Pro environments. This role is responsible for designing, implementing, validating, and maintaining standardized security baselines that improve the organization's cybersecurity posture while ensuring operational stability across Windows and macOS endpoints.

The ideal candidate possesses experience with Microsoft security technologies, endpoint hardening, compliance policies, CIS and Microsoft Security Baselines, and enterprise endpoint management platforms within highly regulated federal environments.

Chickasaw Nation Industries, Inc. serves as a holding company with multiple subsidiaries engaged in several lines of business (Business Services, Health, Infrastructure and Engineering, Mission Optimization, Technology and Transportation) for the federal government and commercial enterprises. A portion of our profits is used to support Chickasaw citizens. We are proud to support the economic development and long-term viability of the Chickasaw Nation and its people. CNI offers premium benefits eligible on the first day of hire to full time employees; (Medical - Dental – Vision), Company Life Insurance, Short-Term and Long-Term Disability Insurance, 401(K) Immediate Vesting, Professional Development Assistance, Legal Aid Assistance Program, Family Planning / Fertility Assistance, Personal Time Off, and Observance of Federal Holidays.

As a federal contractor, CNI is a drug-free workplace and adheres to the Federal Controlled Substance Act.    

ESSENTIAL REQUIREMENTS  

The ability to obtain, maintain and access classified information at the Public Trust level. 

Strong understanding of cybersecurity frameworks, access control, endpoint security, and incident response. 

  • Experience administering Microsoft Intune and Microsoft Endpoint Manager. 
  • Experience with MECM/SCCM administration. 
  • Experience implementing Microsoft Security Baselines and CIS Benchmarks. 
  • Knowledge of Microsoft Defender for Endpoint. 
  • Experience configuring BitLocker, Windows Firewall, ASR rules, Device Control, and endpoint protection policies. 
  • Familiarity with Entra ID, Conditional Access, RBAC, and device compliance. 
  • Understanding of NIST 800-53, Zero Trust Architecture, and federal cybersecurity requirements. 
  • Strong PowerShell scripting experience. 
  • Excellent troubleshooting and documentation skills. 

Preferred Qualifications

  • Experience with Jamf Pro administration. 
  • Experience supporting Azure Virtual Desktop environments. 
  • Microsoft Intune Administrator Associate (MD-102). 
  • Microsoft Security Administrator (SC-300 or equivalent). 
  • CISSP, Security+, or similar security certification. 
  • Experience supporting HHS, NIH, or other federal agencies. 

ESSENTIAL DUTIES AND RESPONSIBILITIES  

Essential Duties and responsibilities include the following.  Other duties may be assigned. 

  • Engineer and maintain Microsoft Intune Security Baselines, Endpoint Security policies, and Configuration Profiles. 
  • Develop and maintain Group Policy, MECM Configuration Baselines, and Jamf security configurations. 
  • Implement Microsoft Defender for Endpoint security settings, attack surface reduction (ASR) rules, firewall policies, BitLocker, FileVault, Credential Guard, Application Control, and device encryption policies. 
  • Configure compliance policies and Conditional Access dependencies supporting Zero Trust initiatives. 
  • Validate security baseline deployments through testing, pilot implementations, and production rollout.
  • Perform impact assessments for Microsoft monthly security baseline updates and recommend adoption strategies. 
  • Collaborate with cybersecurity, RMF, ISSO, and engineering teams to ensure endpoint configurations meet organizational security requirements. 
  • Develop configuration documentation, implementation guides, rollback procedures, and standard operating procedures. 
  • Support vulnerability remediation initiatives through endpoint configuration changes. 
  • Troubleshoot policy conflicts between Intune, MECM, Active Directory Group Policy, and Jamf. 
  • Participate in change management, CAB reviews, and production implementation activities. 
  • Support enterprise modernization initiatives including Autopilot, cloud-native management, and migration from traditional management solutions. 

EDUCATION AND EXPERIENCE 

  • Bachelors degree and 4+ years supporting enterprise endpoint management environments. 

  

PHYSICAL DEMANDS  

Work is primarily performed in an office environment. Regularly required to sit. Regularly required use hands to finger, handle, or feel, reach with hands and arms to handle objects and operate tools, computer, and/or controls. Required to speak and hear. Occasionally required to stand, walk and stoop, kneel, crouch, or crawl. Must frequently lift and/or move up to 10 pounds and occasionally lift and/or move up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision, depth perception, and ability to adjust focus. Exposed to general office noise with computers printers and light traffic.   

  

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job.  Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this job.  

 

EOE including Disability/Vet   

The estimated pay range for this role is $100,000 to $120,000, with the final offer contingent on location, skillset, and experience.  

CNI offers a comprehensive benefits package that includes:

  • Medical
  • Dental
  • Vision
  • 401(k)
  • Family Planning/Fertility Assistance
  • STD/LTD/Basic Life/AD&D
  • Legal-Aid Program
  • Employee Assistance Program (EAP)
  • Paid Time Off (PTO) 
  • Training and Development Opportunities

Your application submission will be considered for all potential employment opportunities with Chickasaw Nation Industries (CNI).

#INDCNI

Skills Required

  • Ability to obtain, maintain, and access classified information at the Public Trust level.
  • Bachelors degree and 4+ years supporting enterprise endpoint management environments.
  • Experience administering Microsoft Intune and Microsoft Endpoint Manager (MEM).
  • Experience with MECM/SCCM administration and MECM configuration baselines.
  • Experience implementing Microsoft Security Baselines and CIS Benchmarks.
  • Knowledge of Microsoft Defender for Endpoint and attack surface reduction (ASR) rules.
  • Experience configuring BitLocker, Windows Firewall, Device Control, endpoint protection policies, FileVault, Credential Guard, and Application Control.
  • Familiarity with Entra ID, Conditional Access, RBAC, and device compliance.
  • Understanding of NIST 800-53, Zero Trust Architecture, and federal cybersecurity requirements.
  • Strong PowerShell scripting experience.
  • Excellent troubleshooting and documentation skills.
  • Experience validating and piloting security baseline deployments and performing impact assessments.
  • Experience with Jamf Pro administration.
  • Experience supporting Azure Virtual Desktop environments.
  • Relevant certifications (Microsoft Intune Administrator MD-102, Microsoft Security Administrator SC-300, CISSP, Security+).
  • Experience supporting HHS, NIH, or other federal agencies.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Montreal

What We Do

Canadian National Railway Co. engages in rail and related transportation business. Its services include rail, intermodal, trucking, supply chain services, business development, and maps & network. Its offers their services in automotive, coal, fertilizer, food & beverages, forest products, dimensional loads, grain, metals & minerals, and petroleum & chemicals industries.

Similar Jobs

CrowdStrike Logo CrowdStrike

Security Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
120K-180K Annually

Applied Systems Logo Applied Systems

Security Engineer

Cloud • Insurance • Payments • Software • Business Intelligence • App development • Big Data Analytics
Remote or Hybrid
United States
3116 Employees
80K-120K Annually

Citizens Logo Citizens

Security Engineer

Digital Media • Fintech • Information Technology • Machine Learning • Financial Services • Cybersecurity • Automation
In-Office or Remote
2 Locations
17000 Employees
150K-190K Annually

Beyond Finance Logo Beyond Finance

Security Engineer

Fintech • Financial Services
Easy Apply
Remote or Hybrid
United States
2200 Employees
160K-195K Annually

Similar Companies Hiring

Toro TMS Thumbnail
Cloud • Enterprise Web • Sales • Software • Transportation
Chicago, IL
80 Employees
Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account