Endpoint & Microsoft 365 Security Engineer (Ghent)
D-ploy
| Company | D-ploy |
| Category | Engineering |
| Location | Ghent |
| Remote | On-site (inferred) |
| Employment | Full-time |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 27 Jul 2026 |
| Last verified | 9 Aug 2026 |
| Source | Employer ATS (workable) |
Description
D-ploy is an IT and Engineering Solutions company delivering services to organisations across the EMEA region and the United States. We work closely with our clients to provide reliable, secure and practical technology solutions, supported by collaborative teams and a people-focused working environment. We are looking for an experienced Security Engineer specialising in endpoint, Microsoft 365 and email security. This is a hands-on role focused on protecting user devices, collaboration platforms and communication technologies by ensuring that security controls are correctly configured, effectively monitored and continuously improved. The role combines technical engineering with operational security ownership. You will review security configurations, identify weaknesses and risky exceptions, coordinate remediation activities and provide clear visibility into the organisation’s endpoint, Microsoft 365 and email security posture. This is a remote-first position, with occasional travel to company offices when required. You will collaborate with Workplace Technology, IT Operations, Security Operations, business stakeholders, external vendors and specialist service providers. Your responsibilities will include: Protecting corporate laptops, desktops, supported mobile devices and other managed endpoints throughout their lifecycle, ensuring they remain securely configured, monitored and compliant. Maintaining and improving endpoint security baselines, including endpoint protection, EDR/XDR health, vulnerability scanning, device telemetry, patching and update compliance. Investigating and coordinating the remediation of devices that are degraded, non-compliant or no longer reporting correctly. Managing or supporting organisational controls for permitted and prohibited applications. Operating and enhancing Microsoft 365 and Entra ID security controls, particularly Conditional Access, device compliance, privileged access and local administrator protection. Supporting Microsoft Purview security and compliance capabilities, including information protection, Data Loss Prevention, audit, eDiscovery and retention-related controls. Working with privacy and compliance stakeholders to ensure that relevant Purview controls are appropriately implemented and maintained. Managing or providing strong operational support for Microsoft 365 and Mimecast email security controls. Reviewing and improving anti-spoofing, spam, phishing, attachment handling, impersonation and Business Email Compromise protections. Maintaining email authentication and reporting controls, including DMARC, DKIM, SPF and user phishing-reporting processes. Identifying and resolving email security assessment findings, configuration gaps and inappropriate exceptions in collaboration with internal teams and external specialists. Establishing practical operating procedures, dashboards, control evidence, KPIs and continuous improvement actions for endpoint, Microsoft 365 and email security. Using security incidents, phishing trends, audit observations, assessment results and user experience issues to develop sustainable improvements to security controls. Documenting remediation activities, assigning clear ownership and ensuring that actions are supported by appropriate evidence. Requirements At least five years of relevant security engineering or operational security experience within enterprise environments. Practical experience configuring, governing, reviewing or assessing endpoint and Microsoft 365 security controls. Strong hands-on knowledge of endpoint security, endpoint hardening, EDR/XDR, endpoint telemetry and patch or update compliance. Experience working with Microsoft Defender for Endpoint and Microsoft Intune, including device compliance and the monitoring of endpoint security health. Strong knowledge of Microsoft 365 and Microsoft Entra ID security, particularly Conditional Access, Multi-Factor Authentication, device posture, privileged acce