Microsoft 365 Security Hardening Services — Entra & Intune
- Salary
- $150/hr
- Hiring from
- United States
- Work type
- Remote
- Posted
538,071 remote jobs, straight from company career pages
100% free · New jobs every hour
Show job descriptionHide job description
Request for qualifications from independent IT security services businesses.
About goCloudOffice®
goCloudOffice® is a modern, AI-driven IT consulting company. Founded in 2003 and based in Silicon Valley, we serve customers nationwide across the United States. Our customers are small businesses of 5 to 50 people, in industries that include biotechnology, law and professional services. They own their business applications, and we run their IT with senior engineering judgment and AI-augmented support that has been in daily production since summer 2024.
The engagement
Engagement: Microsoft 365 security hardening services for a life-sciences customer in the San Francisco Bay Area.
The services strengthen the customer's Microsoft 365 environment across identity, endpoints, data governance, collaboration, threat protection, email and domain security, and the business applications that sign in through Microsoft Entra ID. They leave behind documentation that a third-party assessor can verify.
This is a business-to-business engagement under a master services agreement and a statement of work between goCloudOffice® and your business, which invoices for the services it delivers.
Engagement contact: the goCloudOffice® account lead. The provider directs its own work and personnel.
The provider coordinates hand-offs with the customer's IT lead and with goCloudOffice®'s existing providers, and the customer's leadership makes the business and risk decisions the work calls for.
Scope of services
- Identity and access. Conditional Access, emergency access, administrator authentication strengths and privileged-role assignments reviewed against a documented baseline and aligned to it, with every change piloted in report-only mode before enforcement; privileged-access reviews; a maintained policy register.
- Endpoints. Intune compliance and app-protection policies for Windows, macOS and personal mobile devices reviewed and brought to baseline; local administrator rights and Windows LAPS managed to baseline; Microsoft Secure Score remediation; Microsoft Defender and endpoint detection and response configuration reviewed and aligned.
- Data governance. Microsoft Purview retention, sensitivity labels and data loss prevention reviewed and tuned, with every change proven in simulation or with a pilot group before enforcement.
- Collaboration. SharePoint, OneDrive and Teams external-sharing, guest-access and lifecycle settings reviewed and brought to baseline, and a secure site and permission design for SharePoint content.
- Threat protection and monitoring. Defender for Office 365 policies, unified audit logging and alert policies reviewed and brought to baseline.
- Email and domain security. SPF, DKIM, DMARC and MTA-STS reviewed and maintained at enforcement, with any policy change staged; registrar and DNS security controls verified.
- Business applications. Single sign-on and SCIM provisioning from Microsoft Entra ID across the customer's business applications, and the HR-driven joiner, mover and leaver process, reviewed, extended where needed and verified with a test.
- Governance and evidence. Microsoft 365 incident response documentation reviewed and exercised in a tabletop, Microsoft 365 evidence connected to a compliance platform, an audit-readiness register for regulated records, and decision memos that set out options, costs and risks for the customer's leadership.
- AI-assisted delivery. AI tools used as a daily part of the work, with every output verified before it reaches a customer system.
Services must meet the customer's security, access and confidentiality policies and the service levels in the statement of work.
Before any access to the customer's systems or information, the provider and each person it assigns sign the customer's confidentiality agreement and acknowledge the customer's insider-trading policy; the customer may designate them as covered persons subject to its trading blackout and pre-clearance rules, and these obligations continue after the engagement ends.
The provider uses its own equipment and business identity; goCloudOffice® grants only the proprietary system access the services require. In the customer's Microsoft 365 tenant, the provider works through named, least-privilege administrator accounts in its own name, approved by the customer and logged.
The customer's leadership owns licensing, vendor contracts, risk acceptance and business policy. The provider prepares the options and delivers the approach the customer chooses.
What your business brings (required qualifications)
1. An independently established IT security services business. Your business:
- operates under its own business name, including in customer systems and at customer sites;
- regularly contracts with other businesses and advertises its services to the public;
- holds the business licenses and registrations its work requires (for example, in its home city, and in the customer's city where site visits require it);
- carries general liability insurance (USD 1M per occurrence, USD 2M aggregate), technology errors-and-omissions and network security and privacy liability insurance (USD 1M per claim; USD 2M preferred) with breach-response cover, hired and non-owned auto insurance (USD 1M) where the services include site visits, and workers' compensation where the business has W-2 personnel;
- provides its own equipment.
Preferred structure: A corporation, or an LLC taxed as an S-corporation, whose own W-2 personnel perform the services is preferred. Sole proprietorships and single-member LLCs are also considered.
2. Typically seven or more years of hands-on experience securing and administering Microsoft 365 environments.
3. Microsoft Entra ID identity protection: Conditional Access designed and rolled out in stages with report-only mode first, emergency-access accounts, phishing-resistant multi-factor authentication (FIDO2 security keys and passkeys), and Privileged Identity Management.
4. Microsoft Intune endpoint security: compliance policies for Windows and macOS, app protection policies for personal mobile devices, Windows LAPS, and managed approaches to local administrator rights.
5. Microsoft Defender and endpoint detection and response: Defender for Office 365 and Defender for Endpoint, including Defender working alongside a third-party EDR platform, and migrations between EDR platforms.
6. Microsoft Purview data governance: retention policies, sensitivity labels, data loss prevention, and audit logging with alert policies.
7. SharePoint, OneDrive and Teams governance: external sharing, guest access, and team and site lifecycle settings.
8. Secure Score remediation and safe change practice: triaging recommendations, applying changes in piloted, reversible batches, and recording each risk decision the customer makes.
9. Email and domain security: SPF, DKIM and DMARC enforcement staged to reject, MTA-STS, and registrar and DNS hardening.
10. Application identity integration: SAML single sign-on and SCIM provisioning from Microsoft Entra ID to business applications, and joiner, mover and leaver processes driven by an HR system.
11. Audit-ready evidence: clear records of controls, configurations and decisions that a third-party assessor or a compliance platform can verify.
12. AI-assisted service delivery. Providers should demonstrate at least one year of AI-assisted service delivery in their practice (for example, AI-assisted troubleshooting, documentation or automation). We look for:
- Tools: any mainstream assistant, such as Microsoft 365 Copilot, ChatGPT, Claude, Gemini or GitHub Copilot.
- A clear method for checking AI output: confirming answers against vendor documentation such as Microsoft Learn, testing in report-only or simulation mode, on a test account or with a dry run (for example PowerShell's -WhatIf) before production, reading every line of a script before running it, and keeping customer data inside tools approved for it.
13. Clear communication with customer IT and executive leadership: plain-language change notices, decision memos that set out options, costs and risks, and concise written status updates.
Where a qualification names years, equivalent depth gained in fewer years counts; tell us how.
Also valuable (preferred qualifications)
- A. Relevant certifications, such as the Expert-level Microsoft certification earned through exam SC-100, Identity and Access Administrator Associate (SC-300), Information Protection and Compliance Administrator Associate (SC-400, or its successor SC-401), Microsoft 365 Administrator Expert (MS-102), Endpoint Administrator Associate (MD-102) or Azure Security Engineer Associate (AZ-500). Certifications are welcome, optional evidence of this depth.
- B. Experience in life-sciences or other regulated environments, such as 21 CFR Part 11 and GxP record-keeping, SOC 2 readiness, or IT general controls audits.
- C. Experience connecting Microsoft 365 evidence to a compliance automation platform.
- D. Experience writing Microsoft 365 incident response playbooks (for example, for business email compromise) and facilitating tabletop exercises.
- E. Experience designing SharePoint site and permission architecture for content moving from another file-sharing platform, and evaluating Microsoft 365 backup options.
- F. Experience with a remote monitoring and management platform (such as NinjaOne) and with zero-trust network access or VPN services connected to Microsoft Entra ID.
- G. More than one qualified person in your business who can perform the services, for coverage continuity.
Rate, scope and term
- Budgeted rate: USD 150 per hour. Providers propose their own rates and commercial terms.
- Expected size: approximately 290 to 400 service hours over approximately four months starting in the fourth quarter of 2026, about 25 to 30 service hours per week, scheduled by the provider within customer availability windows; scope may change by statement of work.
- Delivery: mainly remote, performed from within the United States (customer data and evidence are handled only in the United States), with occasional on-site sessions at the customer site in the San Francisco Bay Area, which the provider schedules with the customer within agreed availability windows.
- Term: a statement of work for the engagement window, organized by phase milestones, with a re-estimate after the discovery phase.
How to respond
Submit your business's qualifications: a capability statement, résumés of the personnel who would perform the services, and answers to the response questions. The questions cover business details, licenses and insurance, who performs the services, other clients (count and industries; no names), equipment, how your business secures its administrative access to client systems, availability windows and a delivery plan, your proposed rate and terms, and one example of AI-assisted service delivery. Please send résumés without photographs, dates of birth, government identification numbers or home addresses, and share the notice below with the personnel whose résumés you submit. The qualification process is clear and quick:
1. A review of your response against the posted qualifications.
2. A 25-minute introductory qualification call about how your business runs.
3. A technical qualification call with a Microsoft 365 hardening scenario and a practical exercise, using the AI assistant of your choice or one we provide.
4. A conversation about the customer engagement, under a mutual nondisclosure agreement.
5. Two references from clients of comparable Microsoft 365 security engagements.
6. A final decision by goCloudOffice®'s founder.
Every respondent receives an answer. Reasonable accommodations and other adjustments to any step are available on request; the notice below explains how to reach us.
AI-assistance and privacy notice
This notice covers the businesses that respond to this request for qualifications and the personnel they name. goCloudOffice, Inc. may use AI-assisted tools — Manatal, the platform that hosts our request page, and AI models from Anthropic — to organize and summarize responses against the qualifications posted here and to draft our replies. People, not tools, make every selection decision, and a person reads every response before any decision is made. We keep response records for four years and never sell or share them. You may decline AI assistance, ask for human re-review of any step, or request an accommodation for a qualification call through our contact form at https://www.gocloudoffice.com/contact/; doing so will not affect how we evaluate your response. Our full privacy notice for respondents, including California privacy rights, is at https://www.gocloudoffice.com/legal/respondent-privacy-notice/.
Equal opportunity
goCloudOffice® selects providers on the posted qualifications alone. It welcomes responses from every qualified business, and considers them without regard to the race, color, religion or creed, sex, pregnancy, gender identity or expression, sexual orientation, national origin, ancestry, age, physical or mental disability, medical condition, genetic information, marital status, military or veteran status, or reproductive health decision-making of the business's owners or personnel, or any other characteristic protected by law.