Job Title: Senior Microsoft 365 Systems Engineer / Architect (Level III)
- Position Type: Contract (6 Months, potential to go longer)
- Location: Onsite / Hybrid [Remote for highly exceptional skills]
- Ecosystem Structure: 100% Cloud-Native Microsoft 365 (Zero On-Premises Footprint)
- Hourly Rate on W2: around $70/hour (NO C2C, NO 1099, NO Sponsorship) - can be somewhat flexible based on the level of relevant experience
Role Summary
We are seeking a senior-level Microsoft 365 Systems Engineer / Architect for 6-month contract project. In this role, you will act as the principal technical authority for our cloud infrastructure, driving advanced optimization, security remediation, and operational governance across our entire cloud-native Microsoft 365 ecosystem. The ideal candidate is an expert in cloud architecture who can evaluate our existing tenant, enforce zero-trust security controls, optimize modern device management via Intune, and implement thorough compliance policies.
Key Responsibilities
- Cloud Identity & Access Governance
- Audit and optimize the core Microsoft Entra ID configuration, reinforcing enterprise best practices for cloud-only identity structures.
- Architect and implement robust Conditional Access Policies (CAPs), deploy phishing-resistant Multi-Factor Authentication (MFA), and configure Entra ID Protection policies.
- Standardize global administrative roles using Privileged Identity Management (PIM) and configure secure external collaboration settings.
- Endpoint Management & Cloud Deployment
- Design and deploy enterprise configuration, compliance, and application protection profiles within Microsoft Intune across Windows, macOS, and mobile operating systems.
- Streamline hardware provisioning infrastructure using cloud-native deployment methods including Windows Autopilot and Apple Business Manager.
- Set up automated patch management via Windows Update for Business and establish standardized security baselines.
- Collaboration, Messaging & Content Compliance
- Review and maximize the performance, structural organization, and sharing configurations of Exchange Online, SharePoint Online, and Microsoft Teams.
- Configure Microsoft Purview Data Loss Prevention (DLP) rules, sensitivity labels, and retention schedules to safeguard intellectual property.
- Enforce robust tenant governance models including Microsoft Teams lifecycle automation, guest access reviews, and application permission policies.
- Security Engineering & Documentation
- Systematically remediate tenant vulnerabilities to improve the organization's overall Microsoft Secure Score and security posture.
- Configure comprehensive audit logs, alert notifications, and diagnostic data integrations with core security monitoring systems.
- Author technical as-built architecture manuals, governance charters, and clear operational runbooks to ensure an effective handover to internal IT personnel at project conclusion.
Required Technical Skills & Qualifications
- Experience Profile: Minimum 8+ years of enterprise systems engineering experience, with at least 5+ years dedicated strictly to cloud-native Microsoft 365 infrastructure and architecture design.
- Cloud-Only Specialization: Proven mastery managing pure cloud environments with zero hybrid constraints (no local Active Directory, no hybrid Exchange servers, and no write-back dependencies).
- Identity & Access Management: Expert-level knowledge of Microsoft Entra ID governance, Conditional Access design parameters, and identity boundary security.
- Unified Endpoint Management: Extensive experience engineering worldwide device fleets using Microsoft Intune, provisioning workflows, and custom app deployments.
- Information Governance: Direct hands-on proficiency executing data protection policies via Microsoft Purview, records management, and discovery engines.
- Automation Engineering: Strong PowerShell scripting skills utilizing the native Microsoft Graph SDK and modern API endpoints to automate tenant configuration management.
Preferred Certifications
- Microsoft Certified: Microsoft 365 Enterprise Administrator Expert
- MCSA, MCSE
All qualified applicants will receive consideration for employment without regard to race, color, national origin, age, ancestry, religion, sex, sexual orientation, gender identity, gender expression, marital status, disability, medical condition, genetic information, pregnancy, or military or veteran status. We consider all qualified applicants, including those with criminal histories, in a manner consistent with state and local laws, including the California Fair Chance Act, City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, Los Angeles County Fair Chance Ordinance, and San Francisco Fair Chance Ordinance.