Senior M365 & Exchange Engineer
Listed on 2026-06-29
-
IT/Tech
Cybersecurity, Azure, Information Security
Overview
Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the US and abroad. Our exceptionally talented team is highly collaborative in spirit and practice, producing Results that Matter. Come work with the best!
We offer opportunity, unique challenges, and clear-sighted commitment to the mission. SPA:
Objective. Responsive. Trusted.
We seek an experienced Senior M365 & Exchange Engineer with deep expertise in Microsoft 365 services, Exchange Online, Azure Active Directory, and enterprise identity governance. This role focuses on designing, deploying, and managing modern cloud-based productivity, messaging, and identity platforms while ensuring security, stability, and operational excellence across the Microsoft 365 ecosystem.
The ideal candidate will have hands‑on experience with Microsoft 365 administration, identity and access management, Exchange Online, and hybrid identity integrations, along with strong knowledge of governance, security, and compliance best practices.
Why Join Us?- Work in a dynamic, cloud‑forward environment, modernizing enterprise identity, email, and collaboration platforms.
- Lead initiatives across Microsoft 365 security, automation, and platform governance.
- Gain hands‑on experience with enterprise‑scale identity systems, cloud security controls, and Zero Trust implementation.
SPA has an immediate need for an On‑site/Hybrid/Remote Senior M365 & Exchange Engineer.
Responsibilities- Design, deploy, and manage Exchange Online environments to ensure secure, reliable, and efficient messaging services.
- Administer mail flow, connectors, transport rules, distribution groups, shared mailboxes, resource accounts, auditing configurations, and retention policies.
- Maintain and optimize Exchange Online Protection (EOP) and Defender for Office 365 to manage threats, filter spam, and ensure message hygiene.
- Perform advanced troubleshooting for email delivery, hybrid mail flow, secure mail routing, and service health issues.
- Support migrations, tenant integrations, and lifecycle‑management activities.
- Administer Azure Active Directory (Azure AD)/Entra , including users, groups, roles, conditional access, and identity governance.
- Manage authentication and access controls, including Conditional Access, MFA, SSO, and passwordless capabilities.
- Support hybrid identity solutions such as Azure AD Connect/Entra Connect, federation services, pass‑through authentication, MFA/SSO integrations, and synchronization technologies.
- Implement and enforce RBAC, least privilege, privileged identity management (PIM), and identity security best practices.
- Manage enterprise application integrations, app registrations, service principals, OAuth permissions, and SaaS identity lifecycle.
- Manage and support Office 365 services, including SharePoint Online, One Drive for Business, Microsoft Teams, and compliance tools.
- Apply and maintain governance models, including DLP policies, retention policies, information protection labels, and data security controls.
- Monitor and improve tenant posture using Microsoft Secure Score, audit logs, and compliance center insights.
- Support cross‑platform integrations across Microsoft 365 workloads to ensure a consistent, secure user experience.
- Ensure compliance with frameworks such as NIST SP 800‑171, CMMC, and ISO 27001 as they apply to Microsoft 365 and identity environments.
- Support Microsoft Purview, retention policies, information protection labels, and data protection initiatives.
- Implement cloud security hardening, conditional access baselines, authentication protections, and auditing policies.
- Contribute to security assessments, audits, incident response processes, and remediation activities.
- Monitor service health and performance across Microsoft 365 and Azure AD using built‑in and enterprise…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).