Senior Microsoft 365 Engineer

Jobtailor

Deutschland

Hybrid

EUR 90.000 - 120.000

Vollzeit

Vor 2 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Eine komplette Bewerbung in einer Minute — maßgeschneiderter Lebenslauf und Anschreiben, versandbereit.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

WellStreet is seeking a senior M365/ IAM security engineer to own and evolve the Microsoft 365 stack across Exchange, SharePoint, and Teams. You will implement advanced DLP, labeling, and retention policies, configure Entra ID and Intune, and drive secure access reviews using Graph automation.

You will also manage Defender, Purview, and BI-friendly runbooks while integrating Terraform and Azure DevOps for version-controlled workflows.

Qualifikationen

  • Five or more years in M365, identity, or security engineering.
  • Tenant-level depth in Entra ID and Intune.
  • Purview configuration experience including DLP, labeling, retention and eDiscovery.
  • Fluency with Microsoft Graph and PowerShell; API automation experience.
  • Python is a plus.
  • Version control with branches and pull requests.
  • Experience in regulated frameworks such as HIPAA, HITRUST, SOC 2 or PCI.
  • Ability to explain controls rather than merely naming them.
  • Daily AI usage and judgement on PHI-related tenant reviews.
  • Nice to have: Terraform, Azure DevOps pipelines, Graph/Terraform M365 provider.

Aufgaben

  • Own the Microsoft 365 platform at WellStreet.
  • Design sensitivity label taxonomies and DLP policies across Exchange, SharePoint, and Teams.
  • Set up SSO and SCIM for clinical vendors and identify deprovisioning issues.
  • Close quarterly access reviews on privileged groups using Microsoft Graph automation.
  • Triage critical CVEs from SecOps, own remediation timing, and track remediation.
  • Move Intune configuration from admin centers into a version-controlled repository.
  • Architect and manage Entra ID tenant configuration, Conditional Access, hybrid identity, privileged access, password protection, SSPR, and access reviews.
  • Manage Intune across Windows, macOS, iOS, and Android, including compliance and configuration profiles, security baselines, Autopilot, update rings, and app packaging.
  • Configure Exchange Online, Teams, and SharePoint, including mail flow and transport rules.
  • Configure Purview DLP, sensitivity labeling, retention, audit, eDiscovery, and HIPAA/HITRUST control mapping.
  • Manage enterprise application SSO and SCIM and ensure PHI-handling apps do not use standalone credentials.
  • Manage Defender endpoints, Defender for Office 365 anti-phishing and threat investigations, and unified M365 alerting.
  • Maintain an accurate application portfolio catalog and effective runbooks.
  • Hold vendors accountable to SLAs and BAAs.
  • Build toward version-controlled, API-driven M365 management using Azure DevOps, Microsoft Graph, PowerShell, app-only authentication, and Key Vault.
  • Use AI across engineering, administration, and documentation with appropriate PHI review controls.
  • Collaborate with infrastructure on shared Entra ID responsibilities and Defender workload-security boundaries.

Kenntnisse

M365 security engineering
Entra ID
Intune
Purview DLP & labeling
Microsoft Graph
PowerShell
API automation
Python
HIPAA/HITRUST/PCI/regulatory
Version control (Git)
Terraform/Azure DevOps pipelines
Security policy & access reviews
Explain controls effectively
AI-assisted security review
FreshService ITSM

Tools

Terraform
Azure DevOps
PowerShell
Microsoft Graph
Git
FreshService

Jobbeschreibung

  • Own the Microsoft 365 platform at WellStreet
  • Design sensitivity label taxonomies and DLP policies across Exchange, SharePoint, and Teams
  • Set up SSO and SCIM for clinical vendors and identify deprovisioning issues
  • Close quarterly access reviews on privileged groups using Microsoft Graph automation
  • Triage critical CVEs from SecOps, own remediation timing, and track remediation
  • Move Intune configuration from admin centers into a version-controlled repository
  • Architect and manage Entra ID tenant configuration, Conditional Access, hybrid identity, privileged access, password protection, SSPR, and access reviews
  • Manage Intune across Windows, macOS, iOS, and Android, including compliance and configuration profiles, security baselines, Autopilot, update rings, and app packaging
  • Configure Exchange Online, Teams, and SharePoint, including mail flow and transport rules
  • Configure Purview DLP, sensitivity labeling, retention, audit, eDiscovery, and HIPAA/HITRUST control mapping
  • Manage enterprise application SSO and SCIM and ensure applications handling PHI do not use standalone credentials
  • Manage Defender endpoint detection and response, Defender for Office 365 anti-phishing and threat investigation, and unified M365 alerting
  • Maintain an accurate application portfolio catalog and effective runbooks
  • Hold vendors accountable to SLAs and BAAs
  • Build toward version-controlled, API-driven M365 management using Azure DevOps, Microsoft Graph, PowerShell, app-only authentication, and Key Vault
  • Use AI across engineering, administration, and documentation while applying appropriate PHI review controls
  • Collaborate with infrastructure on shared Entra ID responsibilities and Defender workload-security boundaries
Requirements
  • Five or more years in M365, identity, or security engineering
  • Tenant-level depth in Entra ID and Intune
  • Real Purview configuration experience, including DLP policies, labeling, retention, and eDiscovery
  • Fluency with Microsoft Graph and PowerShell; automation by default and experience building against the API
  • Python is a plus
  • Version control experience; branches and pull requests are normal practice
  • Experience working against a regulated framework such as HIPAA, HITRUST, SOC 2, or PCI
  • Ability to explain controls rather than merely name them
  • Daily AI use and judgment about what requires review before touching a tenant holding PHI
  • Nice to have: Terraform, Bicep, or Azure DevOps pipelines
  • Nice to have: declarative M365 management exposure, including Microsoft365DSC, a Terraform M365 provider, or Graph Tenant Configuration Management APIs
  • Nice to have: healthcare IT experience
  • Nice to have: vulnerability or patch compliance program ownership
  • Nice to have: FreshService or comparable ITSM
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

AI/M365 Security and Identity Governance Engineer
AI/M365 Security and Identity Governance Engineer

Jobtailor • Deutschland

Remote
EUR 90.000 - 130.000
Senior Cyber Security, Microsoft Ecosystem Engineer
Senior Cyber Security, Microsoft Ecosystem Engineer

Jobtailor • Deutschland

Remote
EUR 90.000 - 120.000
Manager, Platform – Identity Administration
Manager, Platform – Identity Administration

Jobtailor • Deutschland

Vor Ort
EUR 90.000 - 140.000
Azure Infra Support Engineer
Azure Infra Support Engineer

Bridgenext • Deutschland

Hybrid
EUR 65.000 - 85.000
Flexible work culture
Career growth opportunities
Autonomy and resources to succeed
Senior IT – Corporate Engineering
Senior IT – Corporate Engineering

Jobtailor • Deutschland

Hybrid
EUR 110.000 - 150.000
Senior Endpoint Engineer – Intune Migration, Automation for iOS
Senior Endpoint Engineer – Intune Migration, Automation for iOS

Jobtailor • Deutschland

Remote
EUR 90.000 - 120.000
Cloud Engineer II
Cloud Engineer II

Jobtailor • Deutschland

Remote
EUR 85.000 - 110.000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Jobtailor • Deutschland

Remote
EUR 90.000 - 130.000
Identity Engineer – Tier 2
Identity Engineer – Tier 2

Jobtailor • Deutschland

Hybrid
EUR 55.000 - 75.000
Principal Identity Engineer
Principal Identity Engineer

Hard Rock Digital • Deutschland

Hybrid
EUR 140.000 - 190.000
Competitive compensation
Flexible vacation
Hybrid or remote environment
+1