Job Title: M365 Security Engineer
Remote for U.S based - Eastern or Central time zone
Type: Contract
Compensation: $100 per hour
We are hiring a Senior Security Engineer to design, implement, and migrate Microsoft cloud infrastructure for clients across state and local government, education, healthcare, utilities and cooperatives, nonprofits, and midmarket enterprise.
This role spans Microsoft Entra ID, Microsoft 365, Microsoft Intune, Microsoft Purview, Microsoft Defender, and Azure infrastructure. You will deliver across concurrent client engagements, contribute technical input to solution scoping and estimation, and act as a trusted technical point of contact for client stakeholders from IT administrators through executive sponsors.
We are looking for someone who can operate with incomplete information, make defensible assumptions, document them, and keep an engagement moving.
Responsibilities
Solution Design and Delivery
Lead or participate in Microsoft tenant migrations: tenant-to-tenant, on-premises to cloud, hybrid coexistence, and third-party platform sources.
Configure and remediate Microsoft Entra ID, including Conditional Access, MFA, Privileged Identity Management, self-service password reset with password writeback, B2B and B2C, cross-tenant synchronization, hybrid identity, and ADFS-to-SAML modernization.
Deploy and modernize endpoint management: Microsoft Intune, Windows Autopilot, Configuration Manager coexistence and transition, compliance policies, configuration profiles, update rings, application packaging, and OneDrive Known Folder Move.
Implement Microsoft Purview data protection: sensitivity labels, data loss prevention, retention and records management, and eDiscovery.
Deploy Microsoft Defender for Endpoint, Defender for Cloud, and Defender for Identity, including migration from third-party EDR platforms.
Azure Infrastructure
Perform Azure Migrate assessments and execute server and workload migrations, including wave planning, cutover scheduling, and application-owner validation.
Design and implement Azure networking, including VPN Gateway, Application Gateway and WAF, Bastion, and Front Door.
Documentation and Enablement
Required Qualifications
Demonstrated ownership of at least three end-to-end Microsoft 365 or Azure migration projects, including planning, execution, and cutover.
Deep hands-on experience with Microsoft Entra ID and Microsoft 365 workloads, including Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams.
Preferred Qualifications
Delivery experience in regulated or public-sector environments: HIPAA, CJIS, FERPA, SOC 2, or NERC CIP.
Certifications
Preferred, not required. Candidates without current certifications who demonstrate equivalent hands-on depth will be considered, and BlueAlly supports certification attainment after hire.
Work Conditions
System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.
Ref: #404-IT Pittsburgh