Role overview
The M365 Security Engineer designs, implements, and migrates Microsoft cloud infrastructure for organizations across public-sector, education, healthcare, utilities, nonprofit, and commercial environments.
This senior role spans Microsoft Entra ID, Microsoft 365, Microsoft Intune, Microsoft Purview, Microsoft Defender, and Azure infrastructure. The engineer works across concurrent client engagements, contributes to solution scoping and estimation, and serves as a trusted technical point of contact.
Successful candidates can work through incomplete information, make and document defensible assumptions, and keep complex engagements moving.
Responsibilities
- Assess client environments and design Microsoft cloud solutions that meet business and technical requirements.
- Lead Microsoft tenant migrations, including tenant-to-tenant, on-premises-to-cloud, hybrid coexistence, and third-party platforms.
- Configure and remediate Microsoft Entra ID capabilities, including Conditional Access, MFA, Privileged Identity Management, hybrid identity, cross-tenant synchronization, and federation modernization.
- Deploy passwordless authentication with Windows Hello for Business, cloud Kerberos trust, and FIDO2 security keys.
- Modernize endpoint management with Microsoft Intune, Windows Autopilot, Configuration Manager, compliance policies, application packaging, update rings, and OneDrive Known Folder Move.
- Implement Microsoft Purview data protection, including sensitivity labels, data loss prevention, retention, records management, and eDiscovery.
- Deploy and migrate Microsoft Defender for Endpoint, Defender for Cloud, and Defender for Identity.
- Plan and deliver Azure workload migrations, networking, backup, disaster recovery, compute, storage, Azure Virtual Desktop, and Windows 365 solutions.
- Create design documents, as-built documentation, runbooks, migration plans, and administrator training materials.
- Manage concurrent client engagements, communicate risks and effort changes early, and provide independent technical guidance to client stakeholders.
Required qualifications
- Five or more years delivering Microsoft cloud infrastructure in consulting, managed services, or enterprise engineering environments.
- Ownership of at least three end-to-end Microsoft 365 or Azure migration projects, including planning, execution, and cutover.
- Deep hands-on experience with Microsoft Entra ID and Microsoft 365 workloads, including Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams.
- Deep hands-on experience with Microsoft Intune and Windows endpoint management.
- Working knowledge of Azure infrastructure, including virtual machine sizing, storage, core networking, and backup.
- Practical experience with Microsoft Purview and the Microsoft Defender suite.
- Proficiency with PowerShell and Microsoft Graph for automation, reporting, and bulk operations.
- Ability to manage competing priorities across multiple client engagements.
- Strong written and verbal communication skills, with the ability to lead client-facing technical discussions.
Preferred qualifications
- Hypervisor migration experience, such as VMware to Hyper-V or Azure.
- Experience with migration tools such as AvePoint Fly, Quest, BitTitan, or ShareGate.
- Experience managing macOS, iOS, and Android devices.
- Delivery experience in regulated or public-sector environments, including HIPAA, CJIS, FERPA, SOC 2, or NERC CIP.
- Exposure to Microsoft Sentinel, Copilot, Power Platform, or AI governance.
- Relevant Microsoft certifications such as SC-300, MD-102, MS-102, AZ-104, SC-400, AZ-305, or AZ-140.
Work conditions
- Remote-first and based in the United States, with a preference for Eastern or Central time zones.
- Periodic evening or weekend work is required for migration cutovers and client maintenance windows.