Salary: USD65 - USD75 per hour
- Position Type: Contract (6 Months, potential to go longer)
- Location: Onsite / Hybrid [Remote for highly exceptional skills]
- Hourly Rate on W2: around $70/hour (NO C2C, NO 1099, NO Sponsorship) - can be somewhat flexible based on the level of relevant experience
Role Summary
We are seeking a senior-level Microsoft 365 Systems Engineer / Architect for 6-month contract project. In this role, you will act as the principal technical authority for our cloud infrastructure, driving advanced optimization, security remediation, and operational governance across our entire cloud-native Microsoft 365 ecosystem. The ideal candidate is an expert in cloud architecture who can evaluate our existing tenant, enforce zero-trust security controls, optimize modern device management via Intune, and implement thorough compliance policies.
Key Responsibilities
- Cloud Identity & Access Governance
- Audit and optimize the core Microsoft Entra ID configuration, reinforcing enterprise best practices for cloud-only identity structures.
- Architect and implement robust Conditional Access Policies (CAPs), deploy phishing-resistant Multi-Factor Authentication (MFA), and configure Entra ID Protection policies.
- Standardize global administrative roles using Privileged Identity Management (PIM) and configure secure external collaboration settings.
- Design and deploy enterprise configuration, compliance, and application protection profiles within Microsoft Intune across Windows, macOS, and mobile operating systems.
- Streamline hardware provisioning infrastructure using cloud-native deployment methods including Windows Autopilot and Apple Business Manager.
- Set up automated patch management via Windows Update for Business and establish standardized security baselines.
- Review and maximize the performance, structural organization, and sharing configurations of Exchange Online, SharePoint Online, and Microsoft Teams.
- Configure Microsoft Purview Data Loss Prevention (DLP) rules, sensitivity labels, and retention schedules to safeguard intellectual property.
- Enforce robust tenant governance models including Microsoft Teams lifecycle automation, guest access reviews, and application permission policies.
- Security Engineering & Documentation
- Systematically remediate tenant vulnerabilities to improve the organization’s overall Microsoft Secure Score and security posture.
- Configure comprehensive audit logs, alert notifications, and diagnostic data integrations with core security monitoring systems.
- Author technical as-built architecture manuals, governance charters, and clear operational runbooks to ensure an effective handover to internal IT personnel at project conclusion.
Required Technical Skills & Qualifications
- Experience Profile: Minimum 8+ years of enterprise systems engineering experience, with at least 5+ years dedicated strictly to cloud-native Microsoft 365 infrastructure and architecture design.
- Cloud-Only Specialization: Proven mastery managing pure cloud environments with zero hybrid constraints (no local Active Directory, no hybrid Exchange servers, and no write-back dependencies).
- Identity & Access Management: Expert-level knowledge of Microsoft Entra ID governance, Conditional Access design parameters, and identity boundary security.
- Unified Endpoint Management: Extensive experience engineering worldwide device fleets using Microsoft Intune, provisioning workflows, and custom app deployments.
- Information Governance: Direct hands-on proficiency executing data protection policies via Microsoft Purview, records management, and discovery engines.
- Automation Engineering: Strong PowerShell scripting skills utilizing the native Microsoft Graph SDK and modern API endpoints to automate tenant configuration management.
Preferred Certifications