Senior Microsoft Security Engineer
Position Type: Admin/Professional
Department: Information Technology
Full or Part Time: Full Time
Pay Grade: MN13
Summary
The Senior Microsoft Security Engineer will lead the design, implementation, and ongoing administration of Microsoft’s security, identity, endpoint management, compliance, and threat protection platforms. This role will be responsible for deploying and optimizing Microsoft Sentinel, Microsoft Entra ID, Microsoft Defender, Microsoft Intune, and Microsoft Purview to support a Zero Trust security architecture and enhance the organization’s overall security posture. The position requires expertise in Microsoft 365 security technologies, cloud identity management, endpoint security, security operations, compliance controls, and automation.
Principal Functional Responsibilities
Identity and Access Management (Microsoft Entra ID)
- Design and implement Conditional Access policies.
- Deploy and manage Multi-Factor Authentication (MFA).
- Configure Privileged Identity Management (PIM).
- Implement Identity Governance and Access Reviews.
- Monitor and remediate identity-related security risks.
- Manage Single Sign-On (SSO) integrations and federation services.
Security Operations and Threat Detection (Microsoft Sentinel)
- Lead implementation and operational management of Microsoft Sentinel.
- Configure data connectors, analytics rules, workbooks, and automation playbooks.
- Develop incident response workflows and playbooks.
- Perform threat hunting using KQL (Kusto Query Language).
- Integrate Sentinel with Microsoft Defender and third-party security tools.
- Create executive and operational security dashboards.
Endpoint Security and Management (Microsoft Intune)
- Deploy and administer Microsoft Intune.
- Design device compliance and configuration policies.
- Implement Microsoft Autopilot for device provisioning.
- Manage application deployment and lifecycle management.
- Configure mobile device management (MDM) and mobile application management (MAM).
- Ensure endpoint compliance and device security standards.
Microsoft Defender Security Suite
- Deploy and optimize Microsoft Defender for Endpoint.
- Implement Defender for Office 365.
- Configure Defender for Identity.
- Manage Microsoft Defender XDR capabilities.
- Investigate and respond to security incidents.
- Develop threat detection and response strategies.
Compliance and Data Protection (Microsoft Purview)
- Implement Data Loss Prevention (DLP) policies.
- Configure Sensitivity Labels and Information Protection.
- Develop records management and retention policies.
- Implement Insider Risk Management controls.
- Support compliance audits and regulatory requirements.
- Monitor and report on data security risks.
Security Governance and Architecture
- Support the organization's Zero Trust strategy.
- Perform security assessments and gap analyses.
- Recommend security improvements and best practices.
- Develop security standards, policies, and procedures.
- Conduct risk assessments and remediation planning.
- Collaborate with business and IT stakeholders on security initiatives.
Automation and Reporting
- Develop PowerShell scripts and automation workflows.
- Create executive security metrics and reports.
- Monitor security KPls and compliance posture.
- Improve operational efficiency through automation.
Other Duties
Perform other duties as assigned.
Qualifications
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field.
- Minimum 5 years of cybersecurity experience.
- Minimum 3 years managing Microsoft 365 security technologies.
- Experience implementing Microsoft Sentinel, Defender, Intune, Entra ID, and Purview.
- Experience supporting cloud security initiatives in Azure and Microsoft 365.
- Experience with security incident response and threat management.
Preferred Qualifications
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
- Microsoft Certified: Security Operations Analyst (SC-200)
- Microsoft Certified: Identity and Access Administrator (SC-300)
- Microsoft Certified: Information Protection Administrator (SC-400)
- Microsoft Certified: Endpoint Administrator (MD-102)
- CISSP (Preferred)
- Azure Security Engineer Associate (AZ-500)
Physical Requirements
Must be able to utilize a phone, computer and other office equipment.
Department Specific Information
Join Northeast OhioMedical University's (NEOMED) Department of InformationTechnology
NEOMED is a mission-driven, community-based medical university committed to educating health professionals, advancing discovery, and improving the health of our region. We are seeking a Senior Microsoft Security Engineer who wants to contribute to meaningful work in a collaborative academic environment.
At our organization, we are committed to fostering a collaborative and team-oriented environment that is essential to fulfilling our mission. We believe every employee should feel appreciated, valued, and empowered. To maintain a supportive organizational culture, we seek individuals whose values align with our mission and who thrive in a team-based approach. We encourage individuals whose values align with this collaborative approach to apply.
Starting Salary Range
$92,730 – $103,000, commensurate with experience.
This position requires candidates to be authorized to work in the United States without sponsorship.
Benefits & Perks
Healthcare Coverage
- Competitive medical, dental, and vision insurance through Medical Mutual
- Flexible Spending Account (FSA) or Health Savings Account (HSA)
- Short-and long-term disability coverage, Long-term care coverage options, and Life insurance
Retirement
- State retirement plan with 14% employer matching to help you plan for the future
Paid Time Off
- Generous vacation and sick leave, in addition to 11 paid holidays each year
Additional Benefits
- Hybrid work environment (up to two remote days per week after six months) (Policy#3349-7-151)
- Educational benefits with our partner universities (Policy#3349-07-45)
- Ongoing investment in your professional growth through on-site training and Lean Six Sigma certification
- Employee wellness activities and initiatives that support a healthy work-life balance.
NEOMED is committed to providing equal employment opportunities to qualified applicants without discrimination on the basis of age, color, disability, gender identity or expression, genetic information, national origin, race, religion, sex, sexual orientation, transgender status, status as a parent during pregnancy and immediately after the birth of a child, status as a parent of a young child, status as a foster parent, veteran status or any other category protected by applicable state or federal law. As an Equal Opportunity Employer, NEOMED also affirms its commitment to nondiscrimination in its employment policies and practices. In compliance with Title IX (20 U.S.C Sec. 1681 etseq.), NEOMED prohibits sex discrimination, including sexual harassment.