Four Winds Health logo

Senior Microsoft 365 Engineer

Four Winds Health
Posted 3 hours ago
United StatesRemoteEngineering & Development
Is this job info correct?

POSITION: Senior Microsoft 365 Engineer (Identity, Endpoint & Compliance)

We’re hiring the engineer who’ll own the Microsoft 365 platform at WellStreet, in an environment where identity and data governance are HIPAA obligations and not checkboxes. The governance you put in place is what we’ll run on, and how it gets managed is yours to define.

A week in this job:

Monday you’re designing the sensitivity label taxonomy and the DLP policies that enforce it across Exchange, SharePoint and Teams. Tuesday a clinical vendor needs SSO and SCIM, so you stand it up, and you’re the one who catches that their deprovisioning webhook never fires. Wednesday you close quarterly access reviews on privileged groups, driven off a Graph script you wrote instead of a spreadsheet somebody emails around. Thursday a Critical CVE lands from SecOps and you own the triage and the clock. Friday you take the Intune configuration that has only ever existed in an admin center and get it into the repo.

What you’ll own:

• Entra ID: tenant architecture, Conditional Access, hybrid identity, privileged access, password protection and SSPR, access reviews

• Intune: tenant configuration across Windows, macOS, iOS and Android. Compliance and configuration profiles, security baselines, Autopilot, update rings, app packaging.

• Exchange Online, Teams and SharePoint: tenant configuration, mail flow, transport rules

• Purview: DLP, sensitivity labeling, retention, audit configuration, eDiscovery, and HIPAA and HITRUST control mapping

• Enterprise Applications: SSO and SCIM across the portfolio, plus the standard that no app touching PHI runs on standalone credentials

• Defender: endpoint detection and response on every managed device, Defender for Office 365 anti-phishing and threat investigation, and the unified alert view across the M365 estate. Defender for Servers, Defender for Cloud, and Defender for Identity — the workload security surface — sit with infrastructure.

• Vulnerability response: CVE triage from SecOps, remediation tracking, weekly report

• The application portfolio: an accurate catalog, runbooks that work, and the vendors in your domain held to their SLAs and their BAAs

Where the lines are:

Your world is Microsoft 365 and the people who use it: identity for humans, endpoints, collaboration, and governance of the data your users create. Azure cloud infrastructure, the applications running in it, and workload identity sit with our infrastructure side. Entra ID is shared, since it’s identity for both halves, and we split it by what the identity represents — people are yours, machines are theirs. The same split carries into Defender: endpoint and email protection are yours, workload protection on Servers, Cloud, and Identity is theirs.

This job has depth, autonomy and a lot of engineering in it, but the depth runs toward M365 and not toward Azure. If you’d rather be building infrastructure, we’d both prefer to find out now.

How we work, and where we’re going:

Today this tenant is managed largely by clicking in admin centers. That’s what we’re hiring you to change.

We’re building toward version-controlled, API-driven management in an Azure DevOps repo, with Graph and PowerShell as the primary instruments, app-only auth and Key Vault instead of interactive logins, and Python or declarative tooling where they earn their place. We have no illusions about how far that goes, since parts of the M365 surface have solid config-as-code coverage today and parts don’t. What we’re after is that opening a portal becomes a deliberate exception.

We’re not asking for prior GitOps-on-M365 experience. That market barely exists and the tooling is mid-shift. We’re asking for the instinct and the judgment; the specific tooling we’ll work out together.

We use AI heavily across engineering, administration and documentation, and we expect fluency with it, including a clear sense of what has to be reviewed before it touches a tenant holding PHI.

What we need:

• Five or more years in M365, identity or security engineering, with tenant-level depth in Entra ID and Intune

• Real Purview configuration experience: writing DLP policies, labeling, retention, eDiscovery. Not just familiarity.

• Microsoft Graph and PowerShell fluency. This is the one hard technical gate. You automate by default and you’ve built real things against the API. Python is a plus.

• Version control is where your work lives, and branches and pull requests are normal practice for you

• You’ve worked against a regulated framework, whether HIPAA, HITRUST, SOC 2 or PCI, and you can explain a control instead of just naming it

• You use AI daily and can say where you trust it and where you check it

Nice to have:

Terraform, Bicep or Azure DevOps pipelines. Any exposure to declarative M365 management: Microsoft365DSC, a Terraform M365 provider, the Graph Tenant Configuration Management APIs. Healthcare IT. Owning a vulnerability or patch compliance program. FreshService or a comparable ITSM. ITIL v4. SC-200, SC-300, SC-400, MS-102, MD-102.

Why take this job:

Real platform ownership, plus the mandate and the backing to build an engineering practice around it: version control, review and automation in place of tribal knowledge and portal archaeology. You’re the first dedicated hire for this function, so you’re setting standards instead of inheriting a decade of somebody else’s. As we add engineers, this seat is the obvious lead.

About WellStreet Urgent Care

WellStreet Urgent Care is committed to providing the highest quality patient and customer care. Our technology team plays an important role in supporting the people, systems, and operations that allow our urgent care centers to deliver exceptional service to our patients and communities.

In addition to the above requirements, WellStreet is looking for team members with the following qualities:

• A positive attitude toward patients, families, and coworkers.

• Willingness to go the extra mile to create an outstanding experience for customers and to train and lead the center team to do the same.

• A desire to work in concert with others in an upbeat and supportive atmosphere while reinforcing the WellStreet mission to provide uncompromising service.

• A compelling desire to serve others, improve your community's health, and have fun every day.

Similar jobs