@Winston M. Gonzalez, Thanks for posting in Q&A.
For the built-in Endpoint Security Manager Role, it manages security and compliance features, such as security baselines, device compliance, conditional access, and Microsoft Defender for Endpoint.
Could you confirm if you are modifying device configuration policy? Based on my checking, for device configuration policy, it only has Read permission.
If you want to manage policy, maybe you can consider the built in Role "Policy and Profile Manager"
Hope the above information can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.