Haystack
← Back to Jobs
Remote
Technology
SO

M365 Security Engineer

System OneUnited States🇺🇸United StatesPosted 15 Sept 2026

Quick Overview

Salary
$100/hr
Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
22 hours ago
MFASAMLSOC 2AzureHIPAAPowerShellVMwareWAFiOSAndroid

Job Description

Job Title: M365 Security Engineer
Remote for U.S based - Eastern or Central time zone
Type: Contract
Compensation: $100 per hour

We are hiring a Senior Security Engineer to design, implement, and migrate Microsoft cloud infrastructure for clients across state and local government, education, healthcare, utilities and cooperatives, nonprofits, and midmarket enterprise. 

This role spans Microsoft Entra ID, Microsoft 365, Microsoft Intune, Microsoft Purview, Microsoft Defender, and Azure infrastructure. You will deliver across concurrent client engagements, contribute technical input to solution scoping and estimation, and act as a trusted technical point of contact for client stakeholders from IT administrators through executive sponsors. 

We are looking for someone who can operate with incomplete information, make defensible assumptions, document them, and keep an engagement moving. 

Responsibilities 

Solution Design and Delivery 

  • Assess client environments and requirements, and design solutions that meet stated business and technical objectives. 

  • Lead or participate in Microsoft tenant migrations: tenant-to-tenant, on-premises to cloud, hybrid coexistence, and third-party platform sources. 

  • Configure and remediate Microsoft Entra ID, including Conditional Access, MFA, Privileged Identity Management, self-service password reset with password writeback, B2B and B2C, cross-tenant synchronization, hybrid identity, and ADFS-to-SAML modernization. 

  • Deploy passwordless authentication, including Windows Hello for Business using cloud Kerberos trust and FIDO2 security keys. 

  • Deploy and modernize endpoint management: Microsoft Intune, Windows Autopilot, Configuration Manager coexistence and transition, compliance policies, configuration profiles, update rings, application packaging, and OneDrive Known Folder Move. 

  • Implement Microsoft Purview data protection: sensitivity labels, data loss prevention, retention and records management, and eDiscovery. 

  • Deploy Microsoft Defender for Endpoint, Defender for Cloud, and Defender for Identity, including migration from third-party EDR platforms. 

  • Manage and troubleshoot escalated issues across identity, data protection, and device management. 

Azure Infrastructure 

  • Perform Azure Migrate assessments and execute server and workload migrations, including wave planning, cutover scheduling, and application-owner validation. 

  • Design and implement Azure networking, including VPN Gateway, Application Gateway and WAF, Bastion, and Front Door. 

  • Implement Azure Backup and Azure Site Recovery to meet client recovery objectives. 

  • Size and deploy Azure compute and storage, including Azure Files and storage account configuration. 

  • Deliver Azure Virtual Desktop and Windows 365 proofs of value and production deployments. 

Documentation and Enablement 

  • Produce design documents, as-built documentation, runbooks, and migration plans. 

  • Deliver knowledge transfer sessions and administrator training at project closeout. 

  • Track time accurately against estimated hours and communicate variance early. 

  • Stay current on Microsoft platform changes and share practice-level best practices internally. 

Required Qualifications 

  • Five or more years delivering Microsoft cloud infrastructure in a consulting, managed services provider, or enterprise engineering capacity. 

  • Demonstrated ownership of at least three end-to-end Microsoft 365 or Azure migration projects, including planning, execution, and cutover. 

  • Deep hands-on experience with Microsoft Entra ID and Microsoft 365 workloads, including Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams. 

  • Deep hands-on experience with Microsoft Intune and Windows endpoint management. 

  • Working knowledge of Azure IaaS: virtual machine sizing, storage, core networking, and backup. 

  • Practical experience with Microsoft Purview data protection and the Microsoft Defender suite. 

  • PowerShell and Microsoft Graph proficiency for automation, reporting, and bulk operations. 

  • Ability to manage multiple concurrent client engagements and shifting priorities. 

  • Excellent written and verbal communication; able to lead a client-facing technical discussion independently. 

Preferred Qualifications 

  • Azure Virtual Desktop or Windows 365 deployment experience. 

  • Hypervisor migration experience, such as VMware to Hyper-V or VMware to Azure. 

  • Third-party migration tooling: AvePoint Fly, Quest, BitTitan, or ShareGate. 

  • macOS, iOS, and Android management. 

  • Delivery experience in regulated or public-sector environments: HIPAA, CJIS, FERPA, SOC 2, or NERC CIP. 

  • Microsoft Sentinel exposure. 

  • Familiarity with Microsoft Copilot, Power Platform, and AI governance concepts. 

Certifications 

Preferred, not required. Candidates without current certifications who demonstrate equivalent hands-on depth will be considered, and BlueAlly supports certification attainment after hire. 

  • SC-300: Microsoft Certified: Identity and Access Administrator Associate 

  • MD-102: Microsoft 365 Certified: Endpoint Administrator Associate 

  • MS-102: Microsoft 365 Certified: Administrator Expert 

  • AZ-104: Microsoft Certified: Azure Administrator Associate 

  • SC-400: Microsoft Certified: Information Protection and Compliance Administrator Associate 

  • AZ-305: Microsoft Certified: Azure Solutions Architect Expert 

  • AZ-140: Microsoft Certified: Azure Virtual Desktop Specialty 

Work Conditions 

  • Remote-first, United States based. Preference for candidates in the Eastern or Central time zone. 

  • Periodic evening and weekend work is required to support migration cutovers and client maintenance windows. 
     

System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.

System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.

Ref: #404-IT Pittsburgh

Similar jobs