An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Cloudstaff Philippines Inc. is seeking a Level 3 M365 Engineer to lead hands-on Microsoft 365 and Entra ID administration in a remote setup. You will build, migrate, and operate the M365 environment while aligning with IT security and governance practices.
The role emphasizes migration, identity management, device management, and end-user support across multiple tenants, with a focus on automation and cross-functional collaboration.
We’re Hiring: Level 3 M365 Engineer
Looking for a role that fosters collaboration, creativity and career growth in a vibrant office environment? We got you covered!
Role: Level 3 M365 Engineer
Work Arrangement: Work from Home
Location: CS Philippines - Makati/Ortigas/Pampanga/Cebu/Davao
Schedule: Morning Shift
Job description
The Microsoft 365 (M365) Engineer is a hands‑on engineering role that helps build, migrate, and operate the Microsoft 365 and Microsoft Entra ID environment as Nexgen transitions off its incumbent managed service provider into its own dedicated tenant.
Early in the programme, the role builds familiarity with the new tenancy and helps develop the IT operating procedures alongside the Principal M365 Consultant, then delivers the hands‑on migration before moving into business‑as‑usual operation, hardening and support.
Because the team is small, the role is deliberately broad and helps cover the parallel security and platform functions, including administration of the Nexgen Microsoft Dynamics 365 environment, alongside its primary Microsoft discipline.
Key Responsibilities
Support the build and configuration of the greenfield Microsoft 365 and Microsoft Entra ID tenant with the Principal M365 Consultant, covering Exchange Online, SharePoint Online, OneDrive, Microsoft Teams, Microsoft Intune and Microsoft Defender.
Plan and execute the migration of mailboxes, files, collaboration content, Power Platform and Power BI workloads off the incumbent tenant into the Nexgen tenant.
Manage Microsoft Entra ID for identity, single sign‑on (SSO) and Conditional Access, implement phishing resistant multi‑factor authentication (MFA), and run Privileged Identity Management (PIM) using Microsoft Entra ID P2 add‑on licensing.
Manage the fleet as Microsoft Entra ID joined and Microsoft Intune managed, retiring remaining Windows 10 devices and enrolling workstations into the Nexgen tenant, applying Centre for Internet Security (CIS) and ACSC Essentials hardening baselines.
Operate the endpoint protection platform (Microsoft Defender for Endpoint or CrowdStrike) and application control, restoring devices to full reporting coverage.
Onboard remaining non‑single sign‑on applications to Microsoft Entra ID and roll out Microsoft Purview sensitivity labelling and Data Loss Prevention (DLP) across Microsoft 365.
Provide day‑to‑day administration of Microsoft Dynamics 365, including user onboarding and licence assignment, security roles, security groups, and record and field‑level permissions (administrative configuration and access management, not Dynamics development or customisation).
Develop and maintain IT operations runbooks for the new environment, and provide day‑to‑day Microsoft 365 administration and end‑user support after migration.
Parallel and Cross‑Functional Responsibilities
Produce evidenced Essential Eight (Level 1) and Centre for Internet Security (CIS) self‑assessments for the endpoint fleet.
Deliver backup and disaster recovery independence for Microsoft 365, covering tenant configuration through Desired State Configuration (DSC) and immutable data backups.
Administer the Power Platform, applying data loss prevention and tenant isolation to Power Apps, Power Automate and Power BI workspaces.
Provide endpoint and identity telemetry to the Security Operations Engineer and the Security Operations Centre (SOC) to support detection and response.
Technical Environment
Microsoft 365 (E3 licensing with add‑ons), Microsoft Entra ID with P2 for PIM, and Microsoft Intune for device management.
Microsoft Defender for Endpoint or CrowdStrike for endpoint protection, with application control as the incumbent whitelisting tool.
Microsoft Purview for classification, labelling and data loss prevention, and Microsoft 365 Desired State Configuration for tenant configuration management.
Microsoft Dynamics 365 line of business applications, administered through the Power Platform admin centre, with access and permissions managed via Microsoft Entra ID security groups and Dynamics 365 security roles.
Cloud‑only Microsoft Entra ID hardened to the Australian Signals Directorate (ASD) Blueprint for Secure Cloud, feeding endpoint and identity telemetry to the Nexgen Security Information and Event Management (SIEM) platform.
Qualifications and requirements
Four or more years administering Microsoft 365 and Microsoft Entra ID (Azure AD), including Exchange Online, SharePoint Online, OneDrive and Microsoft Teams in a production environment.
Strong Microsoft Entra ID experience covering Conditional Access, Multi‑Factor Authentication (MFA), SSO and Privileged Identity Management.
Practical Microsoft Intune experience enrolling and managing Microsoft Entra ID joined Windows 11 devices with compliance and configuration policies.
Experience operating an endpoint protection platform and application control, and supporting endpoint telemetry.
Scripting and automation with PowerShell and the Microsoft Graph.
Experience administering Microsoft Dynamics 365 from an operational standpoint, covering user onboarding, licensing, security roles, security groups and permissions (rather than as a Dynamics developer or customiser).
Working knowledge of the Essential Eight and CIS baselines, Microsoft 365 backup and migration between tenants.
Highly Desirable
Experience hardening tenants to the ASD Blueprint for Secure Cloud and evidencing Essential Eight maturity.
Tenant‑to‑tenant migration experience, including mail and file migration and the associated tooling.
Power Platform administration experience covering Power Apps, Power Automate and Power BI governance.
Exposure to Amazon Web Services (AWS) and hybrid identity, and ITIL or equivalent service management experience.
Qualifications
Relevant Microsoft certifications such as MS‑102 (Microsoft 365 Administrator), SC‑300 (Identity and Access Administrator) or MD‑102 (Endpoint Administrator), or equivalent experience.
Microsoft certification in Dynamics 365 or Power Platform administration (for example PL‑200 or MB‑910) is an advantage but not essential.
A relevant tertiary qualification or equivalent experience.
Perks & Benefits (Work From Home)
Comprehensive health and life insurance on your 16th day of employment, covering 1 free dependent on the 16th day of employment
Flexible leave credits which may be used for vacation, emergency and sick leaves
Quarterly perks boxes for WFH staff, offering groceries and snacks to keep you fueledSuperb and exciting Mid‑Year Parties – with items to give away and cash prizes!
Endless opportunities for career advancement
Annual Performance Review with Salary Increase
We set you up for success with a company‑provided PC/Laptop and fiber internet connection
Tech‑on‑wheels Support
Participate and join our CS Social Clubs and Special Interest Groups to connect with colleagues
International career growth and connections
Unlimited cash incentives for hired referrals
Mental Wellness Employee Assistance program through Lifeworks
In‑house psychiatrist available to support employees' well‑being
Become part of the Employee Share Units program
Cloudstaff Dream Points - To be used for bidding useful items like appliances, kitchenettes etc.
Established in 2005, Cloudstaff is a leading outsourcing company that empowers businesses to thrive through smarter talent solutions. We're passionate about creating a work environment that fosters your professional growth and overall well‑being.