Microsoft Security Engineer
$170,000–$230,000 year
On-siteLos Angeles, California, United States
Job Summary
Own the architecture, configuration baseline, and lifecycle of the Microsoft 365 tenant supporting active directory accounts, Exchange Online, SharePoint, Teams, and OneDrive. Define and enforce tenant-wide policies for identity, licensing, data loss prevention, retention, and information protection while leading remediation of legacy configurations and technical debt. Architect and operate Azure subscriptions, management groups, and policy structures aligned to the Cloud Adoption Framework and Zero Trust principles. Design, harden, and optimize Azure Virtual Machines, including sizing, availability sets, disk encryption, backup, patching, and Just-in-Time access. Implement and tune Microsoft Defender for Cloud, Defender for Servers, Microsoft Sentinel, and Azure Monitor to deliver actionable telemetry to the SOC. Partner with the Cybersecurity organization to translate security requirements into enforceable Microsoft platform controls and maintain alignment with NIST 800-53, CIS benchmarks, and state/federal mandates. Manage hybrid identity through Entra ID, Entra Connect, Conditional Access, and PIM, including integration with on-premises Active Directory. Manage Microsoft licensing strategy across E3, E5, and add-on SKUs to align entitlements with security requirements and budget constraints.
Required Qualifications
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field. Equivalent professional experience considered in lieu of a degree.
- Minimum 8 years of progressive experience designing and operating enterprise Microsoft environments, with at least 5 years focused on M365 and Azure at scale.
- Expert-level command of Microsoft 365 administration, including hands-on experience with tenants of 10,000 accounts or more.
- Demonstrated expertise in Azure IaaS and PaaS, with deep knowledge of Azure Virtual Machines, networking, storage, identity, and governance.
- Strong working knowledge of Active Directory, Group Policy, Windows Server, certificate services, and traditional on-premises Microsoft infrastructure.
- Proven track record applying NIST, CIS, or equivalent frameworks to Microsoft cloud environments.
- Proficiency with PowerShell, including Microsoft Graph, Exchange Online, and Azure modules.
- Excellent written and verbal communication skills, with the ability to brief both engineers and executives.
Desired Qualifications
- Prior experience in a government, transit, utility, or other regulated public sector environment.
- Active Microsoft certifications such as Azure Solutions Architect Expert, Cybersecurity Architect Expert, Identity and Access Administrator, or Microsoft 365 Administrator Expert.
- Experience with Microsoft Sentinel, Defender XDR, Purview, and Intune at enterprise scale.
- CISSP, CCSP, or equivalent senior security certification.
- Hands-on experience with infrastructure-as-code, CI/CD pipelines, and GitHub or Azure DevOps in a controlled-change environment.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.