Infrastructure Engineer, M365 & Identity

PwrQ Holdings LLC

Waconia (MN)

On-site

USD 95,000 - 150,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Forgent Power is seeking an Infra Engineer III, M365 & Identity to own Microsoft's identity and productivity platform across all sites. You will manage Entra ID, Conditional Access, Privileged Identity Management, and the full Microsoft 365 security stack under E5 licensing during a critical migration to a single governed platform.

You will lead governance, SSO integrations, and hybrid identity with Entra Connect, ensuring secure access, device compliance, and policy enforcement while

Qualifications

  • 7–10 years of experience in Microsoft identity and enterprise Microsoft 365 engineering.
  • Hands-on work with Entra ID—user/group management, CA, hybrid identity, B2B collaboration.
  • Experience implementing Privileged Identity Management in production.
  • Strong understanding of hybrid identity—Entra Connect and AD federation.
  • Experience with Purview Data Loss Prevention and compliance reporting.
  • Defender for Identity sensor deployment experience.
  • Intune device compliance and CA integration knowledge.
  • Excellent runbook, policy, and change documentation skills.
  • Experience configuring enterprise SSO (SAML/OAuth/OpenID Connect).
  • SCIM provisioning and de-provisioning for apps.

Responsibilities

  • Own identity and access governance for the entire environment.
  • Design and enforce Conditional Access policies aligned to Zero Trust.
  • Manage Privileged Identity Management and access reviews.
  • Oversee hybrid identity sync health with Entra Connect.
  • Lead SSO and application integration across enterprise apps.
  • Administer M365 licensing, admin center, and tenant configuration.

Skills

Microsoft Identity
Entra ID
Conditional Access
Privileged Identity Management
Hybrid Identity
Intune
Defender for Identity
Data Loss Prevention
SCIM provisioning
SSO integrations

Tools

Entra Connect
Purview
Defender for Identity
Intune
Microsoft 365 Admin Center

Job description

Position Summary:

We are seeking a Infra Engineer III, M365 & Identity to own Forgent's Microsoft identity and productivity platform across all sites. This role is the single point of accountability for Entra ID, Conditional Access, Privileged Identity Management, and the full suite of Microsoft 365 security and compliance capabilities unlocked by our E5 licensing.

You will be joining at a pivotal moment — Forgent is migrating from a fragmented multi-entity Microsoft 365 environment to a single governed platform with a July 1 go-live deadline. This role will be critical to ensuring that deadline is met, and that identity and access are properly governed across the entire organization from day one.

Key Responsibilities:

Identity & Access Governance

  • Own and operate Entra ID (Azure Active Directory) across all Forgent entities — users, groups, roles, and licensing
  • Design and enforce Conditional Access policies aligned to Zero Trust principles — risk-based access, phishing-resistant authentication, and named location controls
  • Implement and manage Privileged Identity Management — just-in-time role activation, access reviews, and least-privilege enforcement for all admin roles
  • Manage Self-Service Password Reset with password writeback in the hybrid Active Directory and Entra ID environment
  • Own Entra Connect and hybrid identity sync health — ensure clean, reliable synchronization between on-premises Active Directory and Entra ID
  • Lead Entra ID Governance — access reviews, entitlement management, and lifecycle workflows across all entities

Security & Threat Protection

  • Deploy and manage Defender for Identity — sensor deployment on all domain controllers, alert triage, and integration with Defender XDR for unified identity threat detection
  • Configure and maintain Microsoft Purview Data Loss Prevention policies — protect sensitive data across Exchange Online, SharePoint, Teams, and endpoints
  • Manage Intune compliance and configuration policies — enforce device compliance requirements for Conditional Access integration
  • Serve as the identity subject matter expert for security incidents involving compromised accounts, privilege escalation, or unauthorized access

Single Sign-On & Application Integration

  • Own and operate enterprise Single Sign-On across all corporate applications using Entra ID as the identity provider
  • Configure and manage SSO integrations — SAML 2.0, OAuth 2.0, and OpenID Connect — for all business-critical applications across all entities
  • Onboard new applications to the Entra ID application gallery and enterprise app catalog, ensuring consistent authentication and access policies
  • Implement and manage application-level Conditional Access policies — enforce multi-factor authentication, device compliance, and risk-based controls per application
  • Manage application provisioning and de-provisioning using SCIM where supported, ensuring users are automatically granted and revoked access based on role
  • Maintain an authoritative inventory of all SSO-integrated applications, their owners, and their access policies
  • Serve as the escalation point for authentication failures, SSO configuration issues, and application access problems across the organization

Microsoft 365 Administration

  • Own M365 licensing administration — seat allocation, license assignment automation, and renewal planning across all entities
  • Manage the M365 Admin Center, including service health monitoring, tenant configuration, and policy enforcement
  • Support the broader Microsoft 365 E5 feature rollout — coordinate with the Messaging & Collaboration Engineer on Teams, Exchange Online, and OneDrive configurations that depend on identity policies
  • Maintain and document tenant configuration standards, Conditional Access runbooks, and identity governance procedures
Qualifications:

Required

  • 7–10 years of experience in Microsoft identity and enterprise Microsoft 365 engineering
  • Deep hands‑on expertise with Entra ID — user and group management, Conditional Access, hybrid identity, and B2B collaboration
  • Proven experience implementing and operating Privileged Identity Management in a production enterprise environment
  • Strong understanding of hybrid identity — Entra Connect, password hash sync, pass‑through authentication, and Active Directory Federation Services
  • Experience with Microsoft Purview, including Data Loss Prevention policy design and compliance reporting
  • Hands‑on experience with Defender for Identity sensor deployment and alert management
  • Solid understanding of Intune device compliance and its integration with Conditional Access
  • Strong documentation skills — ability to produce runbooks, policy guides, and change management documentation
  • Hands‑on experience configuring enterprise Single Sign-On integrations using SAML 2.0, OAuth 2.0, and OpenID Connect
  • Experience managing application provisioning and de‑provisioning via SCIM

Preferred

  • Experience with Entra ID Governance — access reviews, entitlement management, and lifecycle workflows
  • Familiarity with Microsoft Sentinel for identity‑related log ingestion and alerting
  • Experience supporting a Microsoft 365 E5 deployment or licensing transition
  • Knowledge of multi‑entity or post‑acquisition Microsoft 365 consolidation
  • Microsoft certifications — SC-300 (Identity and Access Administrator), MS-102 (Microsoft 365 Administrator)
Core Competencies & Behaviors:
  • Own identity and access governance for an entire NYSE‑listed enterprise from day one — this is a greenfield opportunity, not a maintenance role
  • Work on a high‑visibility Microsoft 365 E5 platform launch with a clear roadmap and leadership support
  • Operate at the intersection of identity, security, and compliance — a role that matters to every person in the company
  • Collaborative team environment with a Sr. Manager who came from an enterprise Microsoft background
  • Competitive compensation, benefits, and the ability to shape how identity is done across a growing multi‑site organization
Working Conditions:

The typical work environment is a standard office setting. Frequently required to sit for extended periods of time at computer.

Disclaimer:

The statements above are intended to describe the general nature and level of work being performed. They are not an exhaustive list of all responsibilities, duties, or skills required. Forgent Power reserves the right to modify, interpret, or apply this job description as needed.

Equal Employment Opportunity Statement:

Forgent Power is an equal opportunity employer. We are committed to creating an inclusive environment for all employees. Employment decisions are made without regard to race, color, religion, sex, national origin, age, disability, veteran status, or any other protected class.

Equal employment opportunity, including veterans and individuals with disabilities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Infrastructure Engineer, M365 & Identity
Infrastructure Engineer, M365 & Identity

PwrQ Holdings LLC • Waco (TX)

On-site
USD 120,000 - 170,000
Infrastructure Engineer, M365 & Identity
Infrastructure Engineer, M365 & Identity

States Manufacturing Corporation • Waco (TX), Northern (KY)

Hybrid
USD 140,000 - 170,000
Infrastructure Engineer, M365 & Identity
Infrastructure Engineer, M365 & Identity

Forgent Power Solutions, Inc. • Waco (TX)

On-site
USD 120,000 - 160,000
Infrastructure Engineer, M365 & Identity
Infrastructure Engineer, M365 & Identity

Socket.dev • Waco (TX)

On-site
USD 120,000 - 180,000
M365 & Entra ID Engineer — Identity & Security Lead
M365 & Entra ID Engineer — Identity & Security Lead

States Manufacturing Corporation • Waco (TX), Northern (KY)

Hybrid
USD 140,000 - 170,000
Azure & Infrastructure Engineer
Azure & Infrastructure Engineer

Forgent Power Solutions, Inc. • Columbus (OH)

Hybrid
USD 130,000 - 180,000
Senior Identity & M365 Platform Engineer
Senior Identity & M365 Platform Engineer

Socket.dev • Waco (TX)

On-site
USD 120,000 - 180,000
Azure & Infrastructure Engineer
Azure & Infrastructure Engineer

States Manufacturing Corporation • Columbus (OH)

Hybrid
USD 130,000 - 170,000
Identity & Access Architect: M365 + Entra ID Governance
Identity & Access Architect: M365 + Entra ID Governance

PwrQ Holdings LLC • Waconia (MN)

On-site
USD 95,000 - 150,000
Azure & Infrastructure Engineer
Azure & Infrastructure Engineer

Socket.dev • Columbus (OH)

Hybrid
USD 140,000 - 190,000