Senior Microsoft 365 Engineer
Posted 1ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior Microsoft 365 Engineer owning identity, endpoint, and compliance for WellStreet Urgent Care. Automating HIPAA-governed Microsoft 365 operations through Graph, PowerShell, and version control.
Responsibilities:
- Own the Microsoft 365 platform at WellStreet
- Design sensitivity label taxonomies and DLP policies across Exchange, SharePoint, and Teams
- Set up SSO and SCIM for clinical vendors and identify deprovisioning issues
- Close quarterly access reviews on privileged groups using Microsoft Graph automation
- Triage critical CVEs from SecOps, own remediation timing, and track remediation
- Move Intune configuration from admin centers into a version-controlled repository
- Architect and manage Entra ID tenant configuration, Conditional Access, hybrid identity, privileged access, password protection, SSPR, and access reviews
- Manage Intune across Windows, macOS, iOS, and Android, including compliance and configuration profiles, security baselines, Autopilot, update rings, and app packaging
- Configure Exchange Online, Teams, and SharePoint, including mail flow and transport rules
- Configure Purview DLP, sensitivity labeling, retention, audit, eDiscovery, and HIPAA/HITRUST control mapping
- Manage enterprise application SSO and SCIM and ensure applications handling PHI do not use standalone credentials
- Manage Defender endpoint detection and response, Defender for Office 365 anti-phishing and threat investigation, and unified M365 alerting
- Maintain an accurate application portfolio catalog and effective runbooks
- Hold vendors accountable to SLAs and BAAs
- Build toward version-controlled, API-driven M365 management using Azure DevOps, Microsoft Graph, PowerShell, app-only authentication, and Key Vault
- Use AI across engineering, administration, and documentation while applying appropriate PHI review controls
- Collaborate with infrastructure on shared Entra ID responsibilities and Defender workload-security boundaries
Requirements:
- Five or more years in M365, identity, or security engineering
- Tenant-level depth in Entra ID and Intune
- Real Purview configuration experience, including DLP policies, labeling, retention, and eDiscovery
- Fluency with Microsoft Graph and PowerShell; automation by default and experience building against the API
- Python is a plus
- Version control experience; branches and pull requests are normal practice
- Experience working against a regulated framework such as HIPAA, HITRUST, SOC 2, or PCI
- Ability to explain controls rather than merely name them
- Daily AI use and judgment about what requires review before touching a tenant holding PHI
- Nice to have: Terraform, Bicep, or Azure DevOps pipelines
- Nice to have: declarative M365 management exposure, including Microsoft365DSC, a Terraform M365 provider, or Graph Tenant Configuration Management APIs
- Nice to have: healthcare IT experience
- Nice to have: vulnerability or patch compliance program ownership
- Nice to have: FreshService or comparable ITSM
- Nice to have: ITIL v4
- Nice to have: SC-200, SC-300, SC-400, MS-102, or MD-102
- Positive attitude toward patients, families, and coworkers
- Willingness to create outstanding customer experiences and train and lead center teams
- Desire to work collaboratively in an upbeat and supportive atmosphere
- Desire to serve others and improve community health
Benefits:
- Real platform ownership with mandate and backing to build an engineering practice
- Version control, review, and automation replacing tribal knowledge and portal-based administration
- Opportunity to set standards as the first dedicated hire for the function
- Potential to become the obvious lead as engineers are added

















