Senior Microsoft 365 Engineer

Piedmont Urgent Care by Wellstreet

Atlanta (GA)

On-site

USD 120,000 - 150,000

Full time

11 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

WellStreet Urgent Care is seeking a seasoned engineer to own the Microsoft 365 platform, focusing on identity governance and data protection in a HIPAA-regulated environment. You’ll design and implement Entra ID, Intune, Exchange Online, Teams and Purview configurations, with an emphasis on automation and secure, compliant workflows.

You’ll work hands-on across Graph, PowerShell and code-managed configurations, shape the governance model, and mentor others as you build an auditable,

Qualifications

  • Five+ years in M365, identity or security engineering.
  • Experience with Purview DLP, labeling, retention and eDiscovery.
  • Proficiency with Graph and PowerShell; automation is a must.
  • Familiarity with regulated frameworks (HIPAA, HITRUST, SOC 2, PCI).
  • Experience with AI tools and governance.

Responsibilities

  • Design sensitivity label taxonomy and DLP policies across Exchange, SharePoint and Teams.
  • Implement SSO and SCIM for external vendors and ensure deprovisioning hooks.
  • Perform quarterly access reviews for privileged groups using Graph scripts.
  • Respond to security CVEs and coordinate triage with SecOps.
  • Manage Intune configuration across multiple OS platforms and maintain baselines.

Skills

Entra ID
Intune
Exchange Online
Teams
SharePoint
Purview
PowerShell
Graph API
Automation
AI fluency

Tools

Azure DevOps
Terraform
Microsoft365DSC
Graph Tenant APIs

Job description

We’re hiring the engineer who’ll own the Microsoft 365 platform at WellStreet, in an environment where identity and data governance are HIPAA obligations and not checkboxes. The governance you put in place is what we’ll run on, and how it gets managed is yours to define.

A week in this job:

Monday you’re designing the sensitivity label taxonomy and the DLP policies that enforce it across Exchange, SharePoint and Teams. Tuesday a clinical vendor needs SSO and SCIM, so you stand it up, and you’re the one who catches that their deprovisioning webhook never fires. Wednesday you close quarterly access reviews on privileged groups, driven off a Graph script you wrote instead of a spreadsheet somebody emails around. Thursday a Critical CVE lands from SecOps and you own the triage and the clock. Friday you take the Intune configuration that has only ever existed in an admin center and get it into the repo.

What you’ll own:
  • Entra ID: tenant architecture, Conditional Access, hybrid identity, privileged access, password protection and SSPR, access reviews
  • Intune: tenant configuration across Windows, macOS, iOS and Android. Compliance and configuration profiles, security baselines, Autopilot, update rings, app packaging.
  • Exchange Online, Teams and SharePoint: tenant configuration, mail flow, transport rules
  • Purview: DLP, sensitivity labeling, retention, audit configuration, eDiscovery, and HIPAA and HITRUST control mapping
  • Enterprise Applications: SSO and SCIM across the portfolio, plus the standard that no app touching PHI runs on standalone credentials
  • Defender: endpoint detection and response on every managed device, Defender for Office 365 anti-phishing and threat investigation, and the unified alert view across the M365 estate. Defender for Servers, Defender for Cloud, and Defender for Identity — the workload security surface — sit with infrastructure.
  • Vulnerability response: CVE triage from SecOps, remediation tracking, weekly report
  • The application portfolio: an accurate catalog, runbooks that work, and the vendors in your domain held to their SLAs and their BAAs
Where the lines are:

Your world is Microsoft 365 and the people who use it: identity for humans, endpoints, collaboration, and governance of the data your users create. Azure cloud infrastructure, the applications running in it, and workload identity sit with our infrastructure side. Entra ID is shared, since it’s identity for both halves, and we split it by what the identity represents — people are yours, machines are theirs. The same split carries into Defender: endpoint and email protection are yours, workload protection on Servers, Cloud, and Identity is theirs.

This job has depth, autonomy and a lot of engineering in it, but the depth runs toward M365 and not toward Azure. If you’d rather be building infrastructure, we’d both prefer to find out now.

How we work, and where we’re going:

Today this tenant is managed largely by clicking in admin centers. That’s what we’re hiring you to change.

We’re building toward version-controlled, API-driven management in an Azure DevOps repo, with Graph and PowerShell as the primary instruments, app-only auth and Key Vault instead of interactive logins, and Python or declarative tooling where they earn their place. We have no illusion about how far that goes, since parts of the M365 surface have solid config-as-code coverage today and parts don’t. What we’re after is that opening a portal becomes a deliberate exception.

We’re not asking for prior GitOps-on-M365 experience. That market barely exists and the tooling is mid-shift. We’re asking for the instinct and the judgment; the specific tooling we’ll work out together.

We use AI heavily across engineering, administration and documentation, and we expect fluency with it, including a clear sense of what has to be reviewed before it touches a tenant holding PHI.

What we need:
  • Five or more years in M365, identity or security engineering, with tenant-level depth in Entra ID and Intune
  • Real Purview configuration experience: writing DLP policies, labeling, retention, eDiscovery. Not just familiarity.
  • Microsoft Graph and PowerShell fluency. This is the one hard technical gate. You automate by default and you’ve built real things against the API. Python is a plus.
  • Version control is where your work lives, and branches and pull requests are normal practice for you
  • You’ve worked against a regulated framework, whether HIPAA, HITRUST, SOC 2 or PCI, and you can explain a control instead of just naming it
  • You use AI daily and can say where you trust it and where you check it
Nice to have:
  • Terraform, Bicep or Azure DevOps pipelines. Any exposure to declarative M365 management: Microsoft365DSC, a Terraform M365 provider, the Graph Tenant Configuration Management APIs. Healthcare IT. Owning a vulnerability or patch compliance program. FreshService or a comparable ITSM. ITIL v4. SC-200, SC-300, SC-400, MS-102, MD-102.
Why take this job:

Real platform ownership, plus the mandate and the backing to build an engineering practice around it: version control, review and automation in place of tribal knowledge and portal archaeology. You’re the first dedicated hire for this function, so you’re setting standards instead of inheriting a decade of somebody else’s. As we add engineers, this seat is the obvious lead.

About WellStreet Urgent Care

WellStreet Urgent Care is committed to providing the highest quality patient and customer care. Our technology team plays an important role in supporting the people, systems, and operations that allow our urgent care centers to deliver exceptional service to our patients and communities.

In addition to the above requirements, WellStreet is looking for team members with the following qualities:

  • A positive attitude toward patients, families, and coworkers.
  • Willingness to go the extra mile to create an outstanding experience for customers and to train and lead the center team to do the same.
  • A desire to work in concert with others in an upbeat and supportive atmosphere while reinforcing the WellStreet mission to provide uncompromising service.
  • A compelling desire to serve others, improve your community's health, and have fun every day.
Qualifications
Skills
Behaviors
Motivations

:

Education
Experience
Licenses & Certifications

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Microsoft 365 Engineer
Senior Microsoft 365 Engineer

Corewell Health Urgent Care • Atlanta (GA)

On-site
USD 140,000 - 190,000
None
Senior Microsoft 365 Engineer
Senior Microsoft 365 Engineer

Four Winds Health • Atlanta (GA)

On-site
USD 140,000 - 170,000
Senior Microsoft 365 Engineer
Senior Microsoft 365 Engineer

University Hospitals Urgent Care by WellStreet • Atlanta (GA)

On-site
USD 120,000 - 180,000
Senior Microsoft 365 Engineer
Senior Microsoft 365 Engineer

Prisma Health UC by Wellstreet, LLC • Atlanta (GA)

On-site
USD 140,000 - 180,000
Corporate Technology Specialist
Corporate Technology Specialist

Four Winds Health • Atlanta (GA)

On-site
USD 60,000 - 90,000
Senior Microsoft 365 Platform Engineer | HIPAA-Governed IT
Senior Microsoft 365 Platform Engineer | HIPAA-Governed IT

Four Winds Health • Atlanta (GA)

On-site
USD 140,000 - 170,000
Senior IT M365 Engineer - Hybrid
Senior IT M365 Engineer - Hybrid

Surgery Partners, Inc. • Brentwood (TN), Northern (KY)

Hybrid
USD 85,000 - 120,000
Health insurance
401(k) retirement plan with company 1
PTO
Workplace Tech Microsoft Platforms Manager
Workplace Tech Microsoft Platforms Manager

Koitecc Solutions • Dallas (TX), Northern (KY)

Hybrid
USD 140,000 - 200,000
DevSecOps Engineer
DevSecOps Engineer

Claritas Rx • Northern (KY)

Hybrid
USD 130,000 - 160,000
IT Systems Engineer
IT Systems Engineer

LegalSight • United States

Hybrid
USD 110,000 - 150,000