Engineer, administer, configure, troubleshoot, and provide sustaining support for Microsoft 365 services in a hybrid enterprise environment.
Support Microsoft 365 workloads including Exchange Online, SharePoint Online, OneDrive, Teams, Microsoft 365 Groups, Lists, OneNote, Forms, Power Automate, Power BI, and Microsoft 365 Apps.
Provide technical support for enterprise messaging, collaboration, meeting, productivity, and user-management services.
Support Entra ID and hybrid identity, including Active Directory, Entra Connect, DirSync, ADFS, user/group administration, dynamic groups, role assignments, and identity lifecycle management.
Configure and troubleshoot Conditional Access, MFA, PIM, Identity Protection, Modern Authentication, token-based authentication, and hybrid authentication services.
Provide engineering support for Microsoft Intune-managed Windows devices, including configuration, compliance, application deployment, endpoint security, troubleshooting, and device lifecycle management.
Develop, maintain, and enhance PowerShell and Microsoft Graph automation for administration, reporting, monitoring, system health checks, operational validation, and self-service capabilities.
Modify existing automation and develop new scripts using PowerShell, Python, C#, C++, or related technologies.
Support Azure application registrations and authentication modernization, including migration from Basic Authentication to Modern Authentication.
Manage and troubleshoot application permissions, Microsoft Graph permissions, certificates, secrets, service principals, and application registrations.
Support Microsoft PKI, certificate-based authentication, device certificates, and certificate dependencies for Microsoft 365, applications, and endpoint services.
Support Microsoft 365 security services, including Microsoft Defender, Conditional Access, Identity Protection, endpoint security, and secure service configuration.
Troubleshoot Microsoft 365 mail flow, messaging, identity, authentication, endpoint, collaboration, and access issues.
Collaborate with Service Desk, Deskside Support, Identity Management, Endpoint Management, Security, Datacomm/Networking, Application, Mobility, and Engineering teams to resolve complex technical issues.
Serve as a senior escalation point for Microsoft 365, identity, endpoint, access, automation, and application-related issues.
Identify opportunities to improve user experience, service reliability, security, automation, and operational efficiency.
Support requirements gathering, solution evaluation, testing, implementation, and lifecycle management for Microsoft 365 services and related technologies.
Develop technical roadmaps and service strategies for Microsoft 365, Entra ID, Intune, automation, and hybrid infrastructure.
Evaluate the Microsoft 365 Roadmap and emerging technologies and provide recommendations based on business value, security, reliability, and operational impact.
Support business continuity and disaster recovery planning for Microsoft 365 and related hybrid services.
Maintain and troubleshoot existing automation scripts, health checks, monitoring solutions, reporting, and operational validation processes.
Develop secure, repeatable automation processes that can be used by junior engineers and administrators.
Create and maintain technical documentation, including engineering designs, As-Built documents, Visio diagrams, runbooks, SOPs, knowledge guides, ConOps, script documentation, health-check procedures, and operations guides.
Maintain comprehensive documentation for Microsoft 365, Entra ID, Intune, automation, configurations, processes, and procedures.
Participate in Agile Scrum ceremonies, sprint activities, planning, reviews, retrospectives, and backlog-related activities.
Follow ITIL, change-management, incident-management, problem-management, and production-support processes.
Provide technical guidance and mentorship to junior engineers and administrators.
Deliver technical presentations and communicate complex technical concepts to customer technical teams, management, and leadership.
Provide technical guidance related to data privacy, compliance, identity, endpoint security, automation, and enterprise risk.
Required Qualifications
Bachelor’s degree with 8+ years of relevant experience or Master’s degree with 6+ years of relevant experience. Additional relevant experience may substitute for education.
Extensive hands-on experience implementing and administering Microsoft 365 services in enterprise or hybrid environments.
Strong experience with:
Exchange Online
SharePoint Online
OneDrive
Microsoft Teams
Microsoft 365 Apps
Microsoft 365 Groups
Microsoft Intune
Microsoft Entra ID
Strong PowerShell and Microsoft Graph experience.
Experience developing automation using PowerShell, Python, C#, C++, or related scripting/programming technologies.
Strong Active Directory experience, including user/group administration, object manipulation, synchronization, and troubleshooting.
Experience with Entra Connect/DirSync, ADFS, MFA, PIM, Conditional Access, dynamic groups, role assignments, and hybrid identity.
Strong understanding of Modern Authentication, authentication protocols, token-based authentication, identity lifecycle, and Conditional Access behavior.
Experience with Microsoft 365 security services, including Microsoft Defender, Identity Protection, endpoint security, and secure configuration.
Experience with Azure application registrations, service principals, API permissions, Microsoft Graph permissions, certificates, and secrets.
Experience migrating applications from Basic Authentication to Modern Authentication.
Working knowledge of Microsoft PKI, certificate-based authentication, device certificates, and certificate dependencies.
Strong understanding of infrastructure and networking fundamentals, including DNS, DHCP, WINS, TCP/IP, routing, and client/server technologies.
Experience developing or maintaining system health checks, monitoring, reporting, and operational automation.
Strong troubleshooting and problem-solving skills with the ability to resolve complex, cross-functional technical issues.
Strong technical writing, presentation, communication, and customer-facing skills.
Ability to work independently with minimal supervision while effectively collaborating across multiple IT teams.
Ability to obtain and maintain a Public Trust or higher security clearance.
Preferred Qualifications
Experience working in Agile/Scrum environments.
Experience applying DevOps methodologies and practices.
Experience working within an ITIL-based service-management environment.
Experience with ServiceNow/SNOW, incident management, problem management, and change control.
Experience supporting enterprise environments with 10,000+ users.
Experience supporting federal government or highly regulated environments.
Understanding of Capstone and NARA data-retention/compliance principles.
Experience with Azure services supporting Microsoft 365 automation and integrations, including:
Azure Automation
Azure Logic Apps
Azure Functions
Azure Key Vault
Azure Storage
Managed Identities
Service Principals
Application Registrations
Experience developing or maintaining Power Automate flows, Power BI dashboards/reports, SharePoint Online lists/libraries, Microsoft Forms intake processes, and other Microsoft 365 operational solutions.
Experience with enterprise-scale Microsoft 365 automation and Tier 0/self-service solutions.
Experience mentoring junior engineers, administrators, or technical staff