
Senior Microsoft 365 Engineer
Posted 11 hours ago

Posted 11 hours ago
This is a fully remote position, open to applicants in United States.
• Take full responsibility for the Microsoft 365 platform at WellStreet, ensuring identity and data governance is in accordance with HIPAA requirements.
• Create sensitivity label taxonomies and develop DLP policies for Exchange, SharePoint, and Teams.
• Implement Single Sign-On (SSO) and System for Cross-domain Identity Management (SCIM) for clinical vendors while overseeing deprovisioning processes.
• Conduct quarterly access reviews for privileged groups utilizing Microsoft Graph automation.
• Address critical CVEs from SecOps, oversee remediation tracking, and generate weekly reports.
• Transition Intune configurations from admin centers to a version-controlled repository.
• Oversee Entra ID tenant architecture, Conditional Access, hybrid identity, privileged access, password protection, SSPR, and access reviews.
• Manage Intune settings across Windows, macOS, iOS, and Android, including compliance and configuration profiles, security baselines, Autopilot, update rings, and app packaging.
• Administer tenant configuration for Exchange Online, Teams, and SharePoint, including mail flow and transport rules.
• Configure Purview DLP, sensitivity labeling, retention, audit, eDiscovery, and mapping of HIPAA/HITRUST controls.
• Oversee enterprise application SSO and SCIM while enforcing standards for applications handling Protected Health Information (PHI).
• Manage Defender endpoint detection and response, Defender for Office 365 anti-phishing measures, threat investigations, and unified alerts.
• Maintain a precise application catalog, effective runbooks, vendor Service Level Agreements (SLAs), and Business Associate Agreements (BAAs).
• Work towards version-controlled, API-driven M365 management within Azure DevOps using Microsoft Graph, PowerShell, app-only authentication, and Key Vault.
• Utilize Python or declarative tools as appropriate.
• Establish engineering standards and best practices as the inaugural dedicated hire for this role.
• Minimum of five years of experience in M365, identity, or security engineering.
• In-depth knowledge of Entra ID and Intune at the tenant level.
• Practical experience with Purview configuration, including crafting DLP policies, labeling, retention, and eDiscovery.
• Proficiency in Microsoft Graph and PowerShell; this is a critical technical requirement.
• Experience in automating processes using the Microsoft Graph API.
• Familiarity with version control practices; branches and pull requests should be standard procedure.
• Background working within regulated frameworks such as HIPAA, HITRUST, SOC 2, or PCI.
• Ability to articulate controls rather than merely naming them.
• Daily use of AI with discernment regarding what necessitates review before interacting with a tenant containing PHI.
• Knowledge of Python is advantageous.
• Preferred skills: Terraform, Bicep, Azure DevOps pipelines, declarative M365 management, healthcare IT, ownership of vulnerability or patch compliance programs, FreshService or similar ITSM tools, ITIL v4, SC-200, SC-300, SC-400, MS-102, or MD-102.
• A positive demeanor towards patients, families, and colleagues.
• Willingness to go above and beyond to provide an exceptional customer experience and mentor the center team.
• Eagerness to collaborate in a lively and supportive environment.
• Commitment to serving others and enhancing community health.
• Genuine platform ownership with the authority and support to establish an engineering practice.
• Implementation of version control, review, and automation to replace tribal knowledge and portal archaeology.
• Opportunity to define standards as the first dedicated hire in this capacity.
• Potential to emerge as the clear leader as additional engineers join the team.
WellStreet Urgent Care
Prisma Health Urgent Care
Canadian Solar Inc.
Canadian Solar Inc.
Get handpicked remote jobs straight to your inbox weekly.