Senior Microsoft 365 Engineer

Posted 1ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior Microsoft 365 Engineer owning Microsoft 365 identity, endpoint, and compliance for WellStreet Urgent Care. Automating regulated healthcare governance with Graph, PowerShell, Intune, and Purview.

Responsibilities:

  • Own the Microsoft 365 platform at WellStreet, with identity and data governance aligned to HIPAA obligations
  • Design sensitivity label taxonomies and DLP policies across Exchange, SharePoint, and Teams
  • Implement SSO and SCIM for clinical vendors and monitor deprovisioning
  • Close quarterly access reviews on privileged groups using Microsoft Graph automation
  • Triage critical CVEs from SecOps, manage remediation tracking, and produce weekly reports
  • Move Intune configuration from admin centers into a version-controlled repository
  • Manage Entra ID tenant architecture, Conditional Access, hybrid identity, privileged access, password protection, SSPR, and access reviews
  • Manage Intune across Windows, macOS, iOS, and Android, including compliance and configuration profiles, security baselines, Autopilot, update rings, and app packaging
  • Administer Exchange Online, Teams, and SharePoint tenant configuration, mail flow, and transport rules
  • Configure Purview DLP, sensitivity labeling, retention, audit, eDiscovery, and HIPAA/HITRUST control mapping
  • Manage enterprise application SSO and SCIM and enforce standards for applications handling PHI
  • Manage Defender endpoint detection and response, Defender for Office 365 anti-phishing, threat investigation, and unified alerts
  • Maintain an accurate application catalog, effective runbooks, vendor SLAs, and BAAs
  • Build toward version-controlled, API-driven M365 management in Azure DevOps using Microsoft Graph, PowerShell, app-only authentication, and Key Vault
  • Use Python or declarative tooling where appropriate
  • Establish engineering standards and practices as the first dedicated hire for this function

Requirements:

  • Five or more years in M365, identity or security engineering
  • Tenant-level depth in Entra ID and Intune
  • Real Purview configuration experience, including writing DLP policies, labeling, retention, and eDiscovery
  • Fluency in Microsoft Graph and PowerShell; this is the hard technical gate
  • Experience automating against the Microsoft Graph API
  • Version control experience; branches and pull requests are normal practice
  • Experience working against a regulated framework such as HIPAA, HITRUST, SOC 2, or PCI
  • Ability to explain a control rather than just name it
  • Daily AI use and judgment about what must be reviewed before touching a tenant holding PHI
  • Python is a plus
  • Nice to have: Terraform, Bicep, Azure DevOps pipelines, declarative M365 management, healthcare IT, vulnerability or patch compliance program ownership, FreshService or comparable ITSM, ITIL v4, SC-200, SC-300, SC-400, MS-102, or MD-102
  • Positive attitude toward patients, families, and coworkers
  • Willingness to go the extra mile to create an outstanding customer experience and train and lead the center team
  • Desire to work collaboratively in an upbeat and supportive atmosphere
  • Desire to serve others and improve community health

Benefits:

  • Real platform ownership with the mandate and backing to build an engineering practice
  • Version control, review, and automation in place of tribal knowledge and portal archaeology
  • Opportunity to set standards as the first dedicated hire for this function
  • Potential to become the obvious lead as engineers are added