Quick Overview
Job Description
Job Title: M365 Security Engineer
Remote for U.S based - Eastern or Central time zone
Type: Contract
Compensation: $100 per hour
We are hiring a Senior Security Engineer to design, implement, and migrate Microsoft cloud infrastructure for clients across state and local government, education, healthcare, utilities and cooperatives, nonprofits, and midmarket enterprise.
This role spans Microsoft Entra ID, Microsoft 365, Microsoft Intune, Microsoft Purview, Microsoft Defender, and Azure infrastructure. You will deliver across concurrent client engagements, contribute technical input to solution scoping and estimation, and act as a trusted technical point of contact for client stakeholders from IT administrators through executive sponsors.
We are looking for someone who can operate with incomplete information, make defensible assumptions, document them, and keep an engagement moving.
Responsibilities
Solution Design and Delivery
Assess client environments and requirements, and design solutions that meet stated business and technical objectives.
Lead or participate in Microsoft tenant migrations: tenant-to-tenant, on-premises to cloud, hybrid coexistence, and third-party platform sources.
Configure and remediate Microsoft Entra ID, including Conditional Access, MFA, Privileged Identity Management, self-service password reset with password writeback, B2B and B2C, cross-tenant synchronization, hybrid identity, and ADFS-to-SAML modernization.
Deploy passwordless authentication, including Windows Hello for Business using cloud Kerberos trust and FIDO2 security keys.
Deploy and modernize endpoint management: Microsoft Intune, Windows Autopilot, Configuration Manager coexistence and transition, compliance policies, configuration profiles, update rings, application packaging, and OneDrive Known Folder Move.
Implement Microsoft Purview data protection: sensitivity labels, data loss prevention, retention and records management, and eDiscovery.
Deploy Microsoft Defender for Endpoint, Defender for Cloud, and Defender for Identity, including migration from third-party EDR platforms.
Manage and troubleshoot escalated issues across identity, data protection, and device management.
Azure Infrastructure
Perform Azure Migrate assessments and execute server and workload migrations, including wave planning, cutover scheduling, and application-owner validation.
Design and implement Azure networking, including VPN Gateway, Application Gateway and WAF, Bastion, and Front Door.
Implement Azure Backup and Azure Site Recovery to meet client recovery objectives.
Size and deploy Azure compute and storage, including Azure Files and storage account configuration.
Deliver Azure Virtual Desktop and Windows 365 proofs of value and production deployments.
Documentation and Enablement
Produce design documents, as-built documentation, runbooks, and migration plans.
Deliver knowledge transfer sessions and administrator training at project closeout.
Track time accurately against estimated hours and communicate variance early.
Stay current on Microsoft platform changes and share practice-level best practices internally.
Required Qualifications
Five or more years delivering Microsoft cloud infrastructure in a consulting, managed services provider, or enterprise engineering capacity.
Demonstrated ownership of at least three end-to-end Microsoft 365 or Azure migration projects, including planning, execution, and cutover.
Deep hands-on experience with Microsoft Entra ID and Microsoft 365 workloads, including Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams.
Deep hands-on experience with Microsoft Intune and Windows endpoint management.
Working knowledge of Azure IaaS: virtual machine sizing, storage, core networking, and backup.
Practical experience with Microsoft Purview data protection and the Microsoft Defender suite.
PowerShell and Microsoft Graph proficiency for automation, reporting, and bulk operations.
Ability to manage multiple concurrent client engagements and shifting priorities.
Excellent written and verbal communication; able to lead a client-facing technical discussion independently.
Preferred Qualifications
Azure Virtual Desktop or Windows 365 deployment experience.
Hypervisor migration experience, such as VMware to Hyper-V or VMware to Azure.
Third-party migration tooling: AvePoint Fly, Quest, BitTitan, or ShareGate.
macOS, iOS, and Android management.
Delivery experience in regulated or public-sector environments: HIPAA, CJIS, FERPA, SOC 2, or NERC CIP.
Microsoft Sentinel exposure.
Familiarity with Microsoft Copilot, Power Platform, and AI governance concepts.
Certifications
Preferred, not required. Candidates without current certifications who demonstrate equivalent hands-on depth will be considered, and BlueAlly supports certification attainment after hire.
SC-300: Microsoft Certified: Identity and Access Administrator Associate
MD-102: Microsoft 365 Certified: Endpoint Administrator Associate
MS-102: Microsoft 365 Certified: Administrator Expert
AZ-104: Microsoft Certified: Azure Administrator Associate
SC-400: Microsoft Certified: Information Protection and Compliance Administrator Associate
AZ-305: Microsoft Certified: Azure Solutions Architect Expert
AZ-140: Microsoft Certified: Azure Virtual Desktop Specialty
Work Conditions
Remote-first, United States based. Preference for candidates in the Eastern or Central time zone.
Periodic evening and weekend work is required to support migration cutovers and client maintenance windows.
System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.
Ref: #404-IT PittsburghSimilar jobs
- E-
ISSO with Security Clearance
NewE-INFOSOL LLC
Clarksburg, WV🇺🇸Hybrid22 hours agoAWSTechnology - SS
AI Security Engineering Vulnerability Protection Engineer
NewSriven Systems Inc.
United States🇺🇸Remote22 hours agoAdministrative - RD
Network Security Engineer: II
NewRandstad Digital
Louisville, KY🇺🇸$52 - $62/hrRemote22 hours agoAWSTCP/IPAzure+1Technology - VC
Network Security Analyst 2
NewV-Soft Consulting Group, Inc
Austin, TX🇺🇸Hybrid22 hours agoAgileTechnology - RS
Data Security Engineer (IBM Guardium)
NewReliable Software Resources
United States🇺🇸On-site22 hours agoMySQLOracleSQL+10Technology - PE
Sr. CI Cyber Special Agent Trainer/Mentor (Cyber Analyst) with Security Clearance
NewPrescient Edge
Fort Meade, MD🇺🇸Hybrid22 hours agoTechnology