Microsoft Security Engineer

Cornerstone Concilium

Los Angeles (CA)

On-site

USD 170,000 - 230,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Benefits

Job summary

Cornerstone Concilium seeks a Microsoft 365 and Azure Architect to lead design, security, and optimization of an enterprise M365/Azure environment for a major public transportation agency in the United States. The role drives identity, cloud security, and hybrid infrastructure with strong governance and regulatory alignment.

The candidate delivers hands-on authority across M365, Azure, and related tools, balancing security posture with procurement, audit, and compliance constraints of a public

Qualifications

  • At least 8 years designing and operating enterprise Microsoft environments.
  • 5+ years focused on M365 and Azure at scale in regulated settings.
  • Proven experience with tenants exceeding 10,000 accounts.

Responsibilities

  • Own M365 tenant architecture, policy enforcement, and lifecycle management.
  • Lead hybrid identity, Entra ID, and conditional access configurations.
  • Governs licensing and entitlements across E3, E5, and add-ons.
  • Architect Azure subscriptions, management groups, and policy structures.
  • Implement Defender, Sentinel, and Azure Monitor for SOC telemetry.
  • Collaborate with Cybersecurity to translate security requirements into platform controls.

Skills

MS 365 & Azure
Security governance
PowerShell scripting
Communication skills
NIST CIS frameworks

Education

Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or related field

Tools

Microsoft Graph
Exchange Online

Job description

We are seeking a Microsoft 365 and Azure Architect to lead the design, security, and ongoing optimization of an enterprise environment across one of the largest public transportation agencies in the United States. This role will architect identity, azure, cybersecurity, with direct accountability for the integrity, posture and design of the Microsoft 365 tenant, Azure subscriptions, and the hybrid infrastructure that connects these services.

The successful candidate is a hands‑on expert who can translate Microsoft platform capabilities into measurable security, performance, and outcomes for a regulated government environment. This role requires deep technical authority in M365 and Azure, paired with the judgment to operate inside the constraints of public sector procurement, audit, and compliance.

Key Responsibilities
Microsoft 365 Architecture and Operations
  • Own the architecture, configuration baseline, and lifecycle of the M365 tenant supporting active directory accounts, including Exchange Online, SharePoint Online, OneDrive, Teams, etc.
  • Define and enforce tenant‑wide policies for identity, licensing, data loss prevention, retention, eDiscovery, best practices and information protection.
  • Lead remediation of legacy configurations, technical debt, and drift accumulated in the existing M365 environment, with a clear roadmap to a hardened target state.
  • Manage hybrid identity through Entra ID (Azure AD), Entra Connect, Conditional Access, and PIM, including integration with on‑premises Active Directory and downstream applications.
  • Govern Microsoft licensing strategy across E3, E5, and add‑on SKUs to align entitlements with security requirements and budget constraints.
Azure Platform and Virtual Machines
  • Architect and operate Azure subscriptions, management groups, and policy structures aligned to Microsoft Cloud Adoption Framework and Zero Trust principles.
  • Design, harden, and optimize Azure Virtual Machines and supporting services, including VM sizing, availability sets, scale sets, disk encryption, backup, patching, and Just‑in‑Time access.
  • Implement and tune Microsoft Defender for Cloud, Defender for Servers, Microsoft Sentinel, and Azure Monitor to deliver actionable telemetry to the SOC.
Security, Identity, and Compliance
  • Partner directly with the Cybersecurity organization to translate security requirements into enforceable Microsoft platform controls.
  • Implement and continuously improve Conditional Access, MFA, privileged access management, and identity governance across all M365 and Azure workloads.
  • Maintain alignment with NIST 800‑53 where applicable, CIS Microsoft 365 and Azure Benchmarks, and any state and federal mandates relevant to a transit agency.
  • Establish secure configuration baselines for collaboration tooling that account for the operational realities of a 24/7 transit workforce.
Required Qualifications
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field. Equivalent professional experience considered in lieu of a degree.
  • Minimum 8 years of progressive experience designing and operating enterprise Microsoft environments, with at least 5 years focused on M365 and Azure at scale.
  • Expert‑level command of Microsoft 365 administration, including hands‑on experience with tenants of 10,000 accounts or more.
  • Demonstrated expertise in Azure IaaS and PaaS, with deep knowledge of Azure Virtual Machines, networking, storage, identity, and governance.
  • Strong working knowledge of Active Directory, Group Policy, Windows Server, certificate services, and traditional on‑premises Microsoft infrastructure.
  • Proven track record applying NIST, CIS, or equivalent frameworks to Microsoft cloud environments.
  • Proficiency with PowerShell, including Microsoft Graph, Exchange Online, and Azure modules.
  • Excellent written and verbal communication skills, with the ability to brief both engineers and executives.
Preferred Qualifications
  • Prior experience in a government, transit, utility, or other regulated public sector environment.
  • Active Microsoft certifications such as Azure Solutions Architect Expert, Cybersecurity Architect Expert, Identity and Access Administrator, or Microsoft 365 Administrator Expert.
  • Experience with Microsoft Sentinel, Defender XDR, Purview, and Intune at enterprise scale.
  • CISSP, CCSP, or equivalent senior security certification.
  • Hands‑on experience with infrastructure‑as‑code, CI/CD pipelines, and GitHub or Azure DevOps in a controlled‑change environment.

The position is on‑site (Monday – Friday).

Salary Range: $170,000 - $230,000 YR with benefits

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Microsoft 365 & Azure Architect
Microsoft 365 & Azure Architect

Auriga Corporation • Los Angeles (CA)

On-site
USD 120,000 - 160,000
401(k)
Health insurance
Paid time off
+1
Microsoft 365 & Azure Architect
Microsoft 365 & Azure Architect

Auriga Corporation • Los Angeles (CA)

On-site
USD 140,000 - 190,000
401(k)
401(k) matching
Competitive salary
+9
Senior Microsoft Cloud Engineer
Senior Microsoft Cloud Engineer

Sprymethods • Washington

On-site
USD 120,000 - 150,000
Microsoft 365 Architect
Microsoft 365 Architect

Greenstone Partners Global • United States

On-site
USD 140,000 - 190,000
Senior M365 Architect
Senior M365 Architect

MSP Hire, Inc. • Burlington (MA)

On-site
USD 200,000 - 230,000
Comprehensive employee benefits plan
Competitive salary
Senior Microsoft 365/Azure Lead Accepting Applications
Senior Microsoft 365/Azure Lead Accepting Applications

Lumecg • Sacramento (CA)

On-site
USD 140,000 - 210,000
Senior Cloud Engineer
Senior Cloud Engineer

Integra Testing Services • Mentor (OH)

On-site
USD 120,000 - 150,000
Microsoft 365 Platform Administrator
Microsoft 365 Platform Administrator

Vanguard • Charlotte (NC)

On-site
USD 100,000 - 130,000
Comprehensive health coverage
Retirement plans
Paid time off
+2
Senior Cloud Engineer
Senior Cloud Engineer

Integra Testing Services, LLC • Cleveland (OH)

On-site
USD 130,000 - 170,000
M365 & Azure Security Architect
M365 & Azure Security Architect

Cornerstone Concilium • Los Angeles (CA)

On-site
USD 170,000 - 230,000
Benefits