LegalSight is a creative and innovative company that develops software for a broad range of legal and business functions. Our team includes veterans of the legal services industry, technology experts, and business operations professionals. We leverage our expertise to maximize opportunities for improved workflows and processes. We bring together our talent and technology to help clients achieve greater operational efficiency, reduce risks, and take advantage of innovative software solutions.
We're looking for a high-energy, hands-on IT Systems Engineer who wants to own things and deploy them. This is an orchestration-first role built for someone with a strong bias for action: you'll spend as much time scripting and automating repetitive administrative work as you will configuring it, and you'll be trusted to take a messy problem and drive it to completion.
You should be comfortable diagnosing a stubborn Windows endpoint, untangling a broken Purview retention or encryption policy, and writing the PowerShell or Graph automation that makes sure the problem never comes back. You'll work across identity, endpoints, collaboration tooling, and data governance. You'll be the person who understands how those Microsoft systems actually fit together, not just how each one works in isolation.
This role rewards initiative. It's a broad, high-ownership mandate in which you'll own systems, not just tickets. We're looking for someone with enough experience to run with it, paired with the energy and drive to keep pushing things forward.
In your first few months you'll take ownership of the M365 governance posture and stand up and properly enable Microsoft Purview (a current priority). You’ll also put automation in place that turns recurring admin tasks and helpdesk patterns into managed, hands-off workflows to make the environment measurably more secure, more consistent, and less manual.
**Candidates who reside within commutable distance to our office in Ocean City, NJ and would be able to work in office two (2) day per week will be given priority.**Responsibilities:
- Administer and harden the Microsoft 365 tenant end to end: Entra ID (Azure AD), Exchange Online, SharePoint Online, OneDrive, Teams, and Intune.
- Own data governance and compliance tooling in Microsoft Purview: sensitivity labels, retention and DLP policies, eDiscovery, and information-protection / RMS encryption configuration and remediation.
- Streamline operations and reduce manual work: automate repetitive administrative tasks, cut down on manual monitoring, and turn one-off fixes into repeatable, hands-off processes using tools like PowerShell, Microsoft Graph, Power Automate, and scheduled runbooks. We leverage AI tooling (including Claude) in our day-to-day, and you're welcome to use it here too.
- Manage Windows systems across the fleet: endpoint configuration, patching, imaging/provisioning, Group Policy / Intune configuration profiles, and troubleshooting at the OS level.
- Investigate and resolve cross-system issues: e.g., encrypted or stuck files spanning SharePoint and external storage, label/policy conflicts, or identity/access edge cases.
- Administer SharePoint Online: site architecture, permissions models, sharing governance, and content lifecycle.
- Build and maintain identity and access workflows: provisioning/deprovisioning, conditional access, MFA, and least-privilege role design.
- Support a company-wide helpdesk: handle employee IT issues and requests, resolve them efficiently, and look for the patterns worth automating so issues don’t recur.
- Monitor tenant and endpoint health, respond to security and compliance alerts, and drive remediation to closure.
- Document configurations, runbooks, and standard procedures so the environment is maintainable by the whole team.
- Partner with engineering, security, and operations to support integrations and keep systems aligned with business needs.
Required Qualifications:
- 4+ years administering Windows and Microsoft 365 environments, with real ownership of the systems you've run.
- Ability to be a player-coach: lead by doing while mentoring less-experienced teammates.
- An efficiency mindset: you dislike repetitive manual work and instinctively look for ways to automate it, streamline it, or make it self-service.
- Comfortable using PowerShell (and, ideally, the Microsoft Graph API) to automate tasks and streamline admin work. You aren’t expected to be a full-time developer, but you should prefer writing a script to avoid repeating the same task manually.
- Working knowledge of Microsoft Purview: information protection, retention/DLP, and encryption/RMS concepts, including cleaning up misconfigured or legacy policies.
- Hands-on SharePoint Online administration (architecture, permissions, sharing governance).
- Solid Entra ID / Azure AD fundamentals: identity, conditional access, MFA, and access governance.
- Windows endpoint and server administration: Intune/MDM, Group Policy, patching, and OS-level troubleshooting.
- High energy, strong ownership, and a bias for action: you take a problem and drive it to completion without needing to be chased.
- Clear written communication and a habit of documenting what you build.
Preferred/Nice-to-Have Qualifications:
- Experience with AI tooling (e.g., Claude) for scripting, troubleshooting, or automation (we use it here, so hands-on experience is a plus).
- Experience managing Mac endpoints and Apple Business Manager (ABM) in a mixed Windows/Mac environment.
- Experience with AWS/S3 or other cloud storage alongside M365 (helpful, not required since the core of this role is Microsoft).
- Familiarity with infrastructure-as-code or configuration-management tooling.
- A relevant Microsoft certification such as MS-102 (Microsoft 365 Administrator) or an equivalent M365/security-compliance credential (nice to see but not required).
- Experience supporting a software engineering organization's developer tooling and environments.