
Senior Microsoft 365 Engineer
Posted 11 hours ago

Posted 11 hours ago
This is a fully remote position, open to applicants in United States.
• Take charge of the Microsoft 365 platform at WellStreet.
• Develop sensitivity label taxonomies and DLP policies across Exchange, SharePoint, and Teams.
• Implement SSO and SCIM for clinical vendors while identifying deprovisioning challenges.
• Conduct quarterly access reviews for privileged groups utilizing Microsoft Graph automation.
• Address critical CVEs from SecOps, manage remediation timelines, and track progress.
• Transition Intune configuration from admin centers into a version-controlled repository.
• Design and oversee Entra ID tenant configuration, Conditional Access, hybrid identity, privileged access, password protection, SSPR, and access reviews.
• Administer Intune across Windows, macOS, iOS, and Android, focusing on compliance and configuration profiles, security baselines, Autopilot, update rings, and app packaging.
• Configure Exchange Online, Teams, and SharePoint, including mail flow and transport rules.
• Set up Purview DLP, sensitivity labeling, retention, audit, eDiscovery, and HIPAA/HITRUST control mapping.
• Oversee enterprise application SSO and SCIM, ensuring applications handling PHI do not utilize standalone credentials.
• Manage Defender endpoint detection and response, Defender for Office 365 anti-phishing and threat investigation, along with unified M365 alerting.
• Maintain an accurate application portfolio catalog and effective runbooks.
• Ensure vendors meet their SLAs and BAAs.
• Progress toward version-controlled, API-driven M365 management using Azure DevOps, Microsoft Graph, PowerShell, app-only authentication, and Key Vault.
• Leverage AI across engineering, administration, and documentation while applying suitable PHI review controls.
• Collaborate with infrastructure on shared Entra ID responsibilities and Defender workload-security boundaries.
• A minimum of five years in M365, identity, or security engineering.
• In-depth tenant-level expertise in Entra ID and Intune.
• Practical experience with Purview configuration, including DLP policies, labeling, retention, and eDiscovery.
• Proficient in Microsoft Graph and PowerShell; automation as a standard, with experience building against the API.
• Knowledge of Python is an advantage.
• Familiarity with version control; branches and pull requests should be routine.
• Experience working within a regulated framework such as HIPAA, HITRUST, SOC 2, or PCI.
• Capability to articulate controls rather than simply naming them.
• Daily use of AI with discernment regarding what needs review before interacting with a tenant containing PHI.
• Preferred: Experience with Terraform, Bicep, or Azure DevOps pipelines.
• Preferred: Exposure to declarative M365 management, including Microsoft365DSC, a Terraform M365 provider, or Graph Tenant Configuration Management APIs.
• Preferred: Background in healthcare IT.
• Preferred: Ownership of vulnerability or patch compliance programs.
• Preferred: Familiarity with FreshService or similar ITSM.
• Preferred: ITIL v4 certification.
• Preferred: Certifications SC-200, SC-300, SC-400, MS-102, or MD-102.
• A positive attitude towards patients, families, and colleagues.
• Eagerness to create exceptional customer experiences and mentor and lead center teams.
• A desire to work collaboratively in an energetic and supportive environment.
• A commitment to serving others and enhancing community health.
• Genuine platform ownership with the authority and support to establish an engineering practice.
• Implementation of version control, review, and automation to replace tribal knowledge and portal-based administration.
• Opportunity to set benchmarks as the inaugural dedicated hire for the function.
• Potential to become the clear leader as additional engineers are brought on board.
University Hospitals Urgent Care
WellStreet Urgent Care
Canadian Solar Inc.
Canadian Solar Inc.
Get handpicked remote jobs straight to your inbox weekly.