Why This Role Stands Out
This hybrid role offers the opportunity to be the principal technical authority for a dynamic Microsoft 365 ecosystem, driving advanced optimization and security. You'll thrive here if you are an expert in cloud architecture with a passion for modern device management and zero-trust security. Apply today to shape the future of cloud infrastructure at Ekman Associates!
Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
Irvine, CA, United States
Posted
1 week ago
MFAActive DirectoryHTTPPowerShell
Job Description
Job Description
Title: Sr. MS 365 Systems Engineer / Architect
Location: Hybrid / Irvine, CA
Ekman Associates is a management consulting firm that specializes in developing business, digital, and technology strategy, delivering solutions, and addressing human resource demands.
Summary:
We are seeking a senior-level Microsoft 365 Systems Engineer / Architect. In this role, you will act as the principal technical authority for our cloud infrastructure, driving advanced optimization, security remediation, and operational governance across our entire cloud-native Microsoft 365 ecosystem. The ideal candidate is an expert in cloud architecture who can evaluate our existing tenant, enforce zero-trust security controls, optimize modern device management via Intune, and implement thorough compliance policies.
Responsibilities:
Cloud Identity & Access Governance
Title: Sr. MS 365 Systems Engineer / Architect
Location: Hybrid / Irvine, CA
Ekman Associates is a management consulting firm that specializes in developing business, digital, and technology strategy, delivering solutions, and addressing human resource demands.
Summary:
We are seeking a senior-level Microsoft 365 Systems Engineer / Architect. In this role, you will act as the principal technical authority for our cloud infrastructure, driving advanced optimization, security remediation, and operational governance across our entire cloud-native Microsoft 365 ecosystem. The ideal candidate is an expert in cloud architecture who can evaluate our existing tenant, enforce zero-trust security controls, optimize modern device management via Intune, and implement thorough compliance policies.
Responsibilities:
Cloud Identity & Access Governance
- Audit and optimize the core Microsoft Entra ID configuration, reinforcing enterprise best practices for cloud-only identity structures.
- Architect and implement robust Conditional Access Policies (CAPs), deploy phishing-resistant Multi-Factor Authentication (MFA), and configure Entra ID Protection policies.
- Standardize global administrative roles using Privileged Identity Management (PIM) and configure secure external collaboration settings.
- Design and deploy enterprise configuration, compliance, and application protection profiles within Microsoft Intune across Windows, macOS, and mobile operating systems.
- Streamline hardware provisioning infrastructure using cloud-native deployment methods including Windows Autopilot and Apple Business Manager.
- Set up automated patch management via Windows Update for Business and establish standardized security baselines.
- Review and maximize the performance, structural organization, and sharing configurations of Exchange Online, SharePoint Online, and Microsoft Teams.
- Configure Microsoft Purview Data Loss Prevention (DLP) rules, sensitivity labels, and retention schedules to safeguard intellectual property.
- Enforce robust tenant governance models including Microsoft Teams lifecycle automation, guest access reviews, and application permission policies.
- Systematically remediate tenant vulnerabilities to improve the organization's overall Microsoft Secure Score and security posture.
- Configure comprehensive audit logs, alert notifications, and diagnostic data integrations with core security monitoring systems.
- Author technical as-built architecture manuals, governance charters, and clear operational runbooks to ensure an effective handover to internal IT personnel at project conclusion.
- Experience Profile: Minimum 8+ years of enterprise systems engineering experience, with at least 5+ years dedicated strictly to cloud-native Microsoft 365 infrastructure and architecture design.
- Cloud-Only Specialization: Proven mastery managing pure cloud environments with zero hybrid constraints (no local Active Directory, no hybrid Exchange servers, and no write-back dependencies).
- Identity & Access Management: Expert-level knowledge of Microsoft Entra ID governance, Conditional Access design parameters, and identity boundary security.
- Unified Endpoint Management: Extensive experience engineering worldwide device fleets using Microsoft Intune, provisioning workflows, and custom app deployments.
- Information Governance: Direct hands-on proficiency executing data protection policies via Microsoft Purview, records management, and discovery engines.
- Automation Engineering: Strong PowerShell scripting skills utilizing the native Microsoft Graph SDK and modern API endpoints to automate tenant configuration management.
- Microsoft Certified: Microsoft 365 Enterprise Administrator Expert
- MCSA, MCSE
Similar jobs
- JM
Lead Software Engineer
NewJ.P. Morgan
Columbus, Ohio🇺🇸On-site11 minutes agoDockerFastAPIFlask+15Technology - NG
Staff CORE Systems Engineer
NewNorthrop Grumman
Towson, Maryland🇺🇸$169k - $253.6k/yrOn-site43 minutes agoMATLABAgileTechnology - BO
Senior Systems Engineer (Reliab, Maintain & Sys Health)
NewBoeing
Saint Louis, Missouri🇺🇸$164.9k - $223.1k/yrHybrid51 minutes agoTechnology - KP
IT Consultant V
NewKaiser Permanente
Greensboro, North Carolina🇺🇸Hybrid53 minutes agoTechnology - ZO
Senior Data Scientist, Marketing
NewZocdoc
New York🇺🇸$160k - $220k/yr13 hours agoSQLHTTPSPythonTechnology - VA
Avionics System Test Engineer
NewVast
Long Beach🇺🇸6 hours agoSpringEmbedded SystemsCompliance+8Technology