Job Description
Design, implement, maintain, and support MPW’s Microsoft cloud, identity, endpoint, security, and compliance platforms. This position provides engineering ownership for the Microsoft technologies that secure and manage MPW’s users, devices, applications, and data. The role partners with the helpdesk, systems engineering, security, and business teams to deliver reliable services, automate routine work, and resolve complex technical issues.
Essential Functions
Microsoft Platform Engineering
- Own the design, configuration, administration, and continuous improvement of MPW’s Microsoft cloud and endpoint platforms, including Intune, Entra ID, Microsoft 365, and related security capabilities.
- Administer Intune policies, application deployments, remediations, Windows update controls, Autopilot, Entra join, endpoint baselines, and compliance configurations.
- Develop standards, documentation, automation, and operational processes that improve security, reliability, compliance, and supportability.
- Identity Access & Application Integration
- Administer Entra ID, Conditional Access, Privileged Identity Management, administrative roles, groups, authentication methods, and access governance.
- Lead SSO integration for Microsoft and third-party applications, including enterprise applications, app registrations, service principals, SAML, OpenID Connect, OAuth, claims, certificates, and provisioning.
- Engineer and support Microsoft App Proxy integrations for secure access to internal and published applications.
Cloud Security & Trust Services
- Design, implement, and support Cloud PKI, SCEP, device certificates, certificate-based authentication, and related certificate lifecycle processes.
- Implement and support Cloud Kerberos Trust (CKT) for secure access to on-premises resources from Entra-joined devices.
- Troubleshoot identity, authentication, authorization, federation, certificate, token, provisioning, and access-policy issues.
Compliance, Messaging Security & Operations
- Administer Microsoft Purview capabilities supporting retention, litigation holds, eDiscovery-related requests, data governance, and compliance operations.
- Administer Abnormal Security email protection and phishing simulations, including policy maintenance, investigation, tuning, and escalation.
- Provide advanced support, incident investigation, root-cause analysis, change management, and technical documentation for Microsoft cloud, endpoint, identity, and security services.
- Lead or participate in Microsoft platform projects, migrations, tenant changes, security initiatives, and service rollouts from design through operational handoff.
- Coordinate testing, communications, rollback planning, and vendor or application-owner collaboration for production changes.
- Work with the helpdesk and infrastructure teams to transfer knowledge and maintain clear technical escalation paths.
Additional Responsibilities
- Provide technical guidance, documentation, and training to helpdesk personnel, systems engineers, application owners, and other stakeholders.
- Participate in an on-call or after-hours escalation process for business-critical identity, endpoint, cloud, security, or compliance services, as required.
Required Skills
- Bachelor’s degree in information technology, computer science, cybersecurity, or a related field; equivalent professional experience may be considered.
- Minimum 3–5 years of experience administering or engineering Microsoft cloud, endpoint, identity, and security platforms.
- Strong analytical, troubleshooting, documentation, communication, and project-management skills with a methodical diagnostic approach.
- Microsoft Intune, Windows endpoint management, Autopilot, compliance policies, configuration profiles, application deployment, and proactive remediations.
- Entra ID, Conditional Access, Privileged Identity Management, enterprise applications, app registrations, service principals, and access governance.
- Single sign-on, Microsoft App Proxy, using SAML, OpenID Connect, OAuth, Microsoft Graph, claims, and provisioning workflows.
- Cloud PKI, SCEP, device certificates, certificate-based authentication, and Cloud Kerberos Trust (CKT).
- Microsoft 365 security and compliance capabilities, including Microsoft Purview, retention, litigation holds, eDiscovery, Abnormal Security, and phishing simulations.
- PowerShell scripting, automation, change management, technical documentation, testing, incident response, and root-cause analysis.