Senior Microsoft 365 Engineer
Listed on 2026-09-16
-
IT/Tech
Cybersecurity
We’re hiring the engineer who’ll own the Microsoft 365 platform at Well Street, in an environment where identity and data governance are HIPAA obligations and not check boxes. The governance you put in place is what we’ll run on, and how it gets managed is yours to define.
A week in this job:Monday you’re designing the sensitivity label taxonomy and the DLP policies that enforce it across Exchange, SharePoint and Teams. Tuesday a clinical vendor needs SSO and SCIM, so you stand it up, and you’re the one who catches that their deprovisioning webhook never fires. Wednesday you close quarterly access reviews on privileged groups, driven off a Graph script you wrote instead of a spreadsheet somebody emails around.
Thursday a Critical CVE lands from Sec Ops and you own the triage and the clock. Friday you take the Intune configuration that has only ever existed in an admin center and get it into the repo.
- Entra t architecture, Conditional Access, hybrid identity, privileged access, password protection and SSPR, access reviews
- Intune: tenant configuration across Windows, macOS, iOS and Android. Compliance and configuration profiles, security baselines, Autopilot, update rings, app packaging.
- Exchange Online, Teams and SharePoint: tenant configuration, mail flow, transport rules
- Purview: DLP, sensitivity labeling, retention, audit configuration, eDiscovery, and HIPAA and HITRUST control mapping
- Enterprise Applications: SSO and SCIM across the portfolio, plus the standard that no app touching PHI runs on standalone credentials
- Defender: endpoint detection and response on every managed device, Defender for Office 365 anti-phishing and threat investigation, and the unified alert view across the M365 estate. Defender for Servers, Defender for Cloud, and Defender for Identity — the workload security surface — sit with infrastructure.
- Vulnerability response: CVE triage from Sec Ops, remediation tracking, weekly report
- The application portfolio: an accurate catalog, runbooks that work, and the vendors in your domain held to their SLAs and their BAAs
Your world is Microsoft 365 and the people who use it: identity for humans, endpoints, collaboration, and governance of the data your users create. Azure cloud infrastructure, the applications running in it, and workload identity sit with our infrastructure side. Entra shared, since it’s identity for both halves, and we split it by what the identity represents — people are yours, machines are theirs.
The same split carries into Defender: endpoint and email protection are yours, workload protection on Servers, Cloud, and Identity is theirs.
This job has depth, autonomy and a lot of engineering in it, but the depth runs toward M365 and not toward Azure. If you’d rather be building infrastructure, we’d both prefer to find out now.
How we work, and where we’re going:Today this tenant is managed largely by clicking in admin centers. That’s what we’re hiring you to change.
We’re building toward version-controlled, API-driven management in an Azure Dev Ops repo, with Graph and Power Shell as the primary instruments, app‑only auth and Key Vault instead of interactive logins, and Python or declarative tooling where they earn their place. We have no illustrations about how far that goes, since parts of the M365 surface have solid config‑as‑code coverage today and parts don’t.
What we’re after is that opening a portal becomes a deliberate exception.
We’re not asking for prior Git Ops‑on‑M365 experience. That market barely exists and the tooling is mid‑shift. We’re asking for the instinct and the judgment; the specific tooling we’ll work out together.
We use AI heavily across engineering, administration and documentation, and we expect…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).