Design sensitivity label taxonomies and DLP policies across Exchange, SharePoint, and Teams
Set up SSO and SCIM for clinical vendors and identify deprovisioning issues
Close quarterly access reviews on privileged groups using Microsoft Graph automation
Triage critical CVEs from SecOps, own remediation timing, and track remediation
Move Intune configuration from admin centers into a version-controlled repository
Architect and manage Entra ID tenant configuration, Conditional Access, hybrid identity, privileged access, password protection, SSPR, and access reviews
Manage Intune across Windows, macOS, iOS, and Android, including compliance and configuration profiles, security baselines, Autopilot, update rings, and app packaging
Configure Exchange Online, Teams, and SharePoint, including mail flow and transport rules
Configure Purview DLP, sensitivity labeling, retention, audit, eDiscovery, and HIPAA/HITRUST control mapping
Manage enterprise application SSO and SCIM and ensure applications handling PHI do not use standalone credentials
Manage Defender endpoint detection and response, Defender for Office 365 anti-phishing and threat investigation, and unified M365 alerting
Maintain an accurate application portfolio catalog and effective runbooks
Hold vendors accountable to SLAs and BAAs
Build toward version-controlled, API-driven M365 management using Azure DevOps, Microsoft Graph, PowerShell, app-only authentication, and Key Vault
Use AI across engineering, administration, and documentation while applying appropriate PHI review controls
Collaborate with infrastructure on shared Entra ID responsibilities and Defender workload-security boundaries
Requirements
Five or more years in M365, identity, or security engineering
Tenant-level depth in Entra ID and Intune
Real Purview configuration experience, including DLP policies, labeling, retention, and eDiscovery
Fluency with Microsoft Graph and PowerShell; automation by default and experience building against the API
Python is a plus
Version control experience; branches and pull requests are normal practice
Experience working against a regulated framework such as HIPAA, HITRUST, SOC 2, or PCI
Ability to explain controls rather than merely name them
Daily AI use and judgment about what requires review before touching a tenant holding PHI
Nice to have: Terraform, Bicep, or Azure DevOps pipelines
Nice to have: declarative M365 management exposure, including Microsoft365DSC, a Terraform M365 provider, or Graph Tenant Configuration Management APIs
Nice to have: healthcare IT experience
Nice to have: vulnerability or patch compliance program ownership
Nice to have: FreshService or comparable ITSM
#J-18808-Ljbffr
NOTE / HINWEIS:
EN: Please refer to Fuchsjobs for the source of your application
DE: Bitte erwähne Fuchsjobs, als Quelle Deiner Bewerbung
Stelleninformationen
Veröffentlichungsdatum:
16 Sep 2026
Standort:
Remote
Typ:
Vollzeit
Arbeitsmodell:
Vor Ort
Kategorie:
Erfahrung:
2+ years
Arbeitsverhältnis:
Angestellt
KI Suchagent
Möchtest über ähnliche Jobs informiert werden? Dann beauftrage jetzt den Fuchsjobs KI Suchagenten!