Jobs and Careers
GE

Sr. Staff Technical Program Manager – M365/Endpoint Security

GE Aerospace
Remote, United States, United StatesRemotefull_timeVerifiedPosted 10 Apr 2026
💰 $189,000/yr($131,000/yr$189,000/yr)

About the role

Job Description Summary

GE Aerospace is seeking a Sr. Staff Technical Program Manager to lead strategy, architecture, and cross functional delivery for data centric and endpoint security across our Microsoft 365 multi-tenant environment and broader cloud/on prem footprint. This combines program leadership with deep security architecture expertise to drive Zero Trust alignment, modernize identity and device posture controls, and embed data protection by design. You will partner closely with Endpoint Security, Security Architecture, Cyber Threat & Response, and CIO teams to standardize controls, reduce risk, and improve resilience.

Job Description

Roles and Responsibilities:

In this role, you will:

Strategy & Architecture

  • Define the multi‑tenant Microsoft 365 security roadmap and standards, including Defender, Intune/Microsoft Endpoint Manager, SCCM, Purview, and Identity/Conditional Access.
  • Lead Zero Trust alignment for identity, device, and data, including device posture assessment, CA policies, risk‑based access, and least‑privilege models.
  • Design endpoint security reference architectures and patterns for EDR/XDR modernization (Defender for Endpoint/XDR), telemetry, and response integration.
  • Establish security architecture guardrails and reusable patterns for SaaS, Private Cloud, and On‑Prem environments; advise on SSPM (SaaS Security Posture Management) practices.

Program Leadership & Delivery

  • Build and run the program operating model (KPI/KRI, roadmaps, intake/backlog, governance), ensuring on‑time delivery across multiple tenants and business units.
  • Lead complex, cross‑functional initiatives with clear scope, milestones, funding/budget alignment, and dependency management.
  • Drive risk remediation campaigns at scale with Endpoint, Identity, Data Protection, and Cloud Platform teams; ensure policy adoption and operational handoffs.

Technical SME Guidance & Engineering Oversight

  • Provide hands‑on technical leadership for high‑impact efforts (POCs, control design, tuning, pilot deployments); coach engineering teams on best practices.
  • Define policy and configuration guidance for Intune, SCCM, and Defender; oversee change management and production rollout standards.
  • Guide automation/orchestration using PowerShell, Intune scripting, Defender workflows, and Sentinel (KQL, analytics, playbooks) to improve signal quality and response.

Threat & Response Integration

  • Build processes and logical interfaces with Cyber Threat & Response teams to strengthen detection/prevention across endpoints, identity, and data controls.
  • Support cyber investigations and enterprise initiatives by ensuring telemetry completeness, control efficacy, and rapid containment pathways.

Metrics, Reporting & Governance

  • Define risk‑based metrics (e.g., device posture compliance, CA policy coverage, EDR/XDR signal quality, and executive reporting.
  • Benchmark GE Aerospace capabilities against internal and industry standards; drive continuous improvement via NIST CSF, NIST SP 800-171, CIS Controls, and internal policies.
  • Partner with Aerospace CIO teams to align operating models, integrate with ServiceNow/workflows, and sustain operational stability across lifecycle phases.

Minimum Qualifications:

  • Bachelor’s degree from an accredited university or college with 5+ years of professional experience; OR associate’s degree with 8+ years; OR High School Diploma with 10+ years.
  • 5+ years in Program Management or IT.
  • 3+ years in Cyber Architecture, endpoint management, and/or incident response.
  • Note: Military experience is equivalent to professional experience.

Eligibility Requirement:

  • Legal authorization to work in the U.S. is required.  We will not sponsor individuals for employment visas, now or in the future, for this job.

Desired Qualifications:

Required Technical Experience

  • Deep experience with Microsoft 365 security in multi‑tenant environments: Defender for Endpoint/XDR, Microsoft Endpoint Manager/Intune, SCCM, Azure AD/Entra ID, Conditional Access..
  • Hands‑on leadership in device posture assessment, EDR/XDR tuning, policy baselining, and telemetry integration for Threat/Response operations.
  • Strong grasp of Zero Trust principles across identity, device, network, and data; ability to translate them into practical enterprise controls and operating standards.
  • Automation/orchestration proficiency (e.g., PowerShell, Intune scripting, Defender workflows; familiarity with Microsoft

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

GE Aerospace

View company profile →