Senior Microsoft Cloud Services Engineer
Key Responsibilities
-
Architect, implement, and maintain Azure-based infrastructure (networking, compute, storage, identity, security controls) to support business-critical workloads with defined availability and performance targets.
-
Lead cloud migrations and modernization efforts, including workload assessment, landing zone design, migration planning and execution, and post-migration optimization.
-
Own Microsoft 365 service operations (Exchange Online, SharePoint Online, OneDrive, Teams) including configuration, governance, lifecycle management, and service health monitoring.
-
Design and enforce cloud security best practices such as identity hardening (Microsoft Entra ID), Conditional Access, least privilege RBAC, secure network patterns, and policy-based compliance.
-
Implement Infrastructure as Code (IaC) and automation using tools such as Terraform, Bicep/ARM, and PowerShell to improve consistency, deployment speed, and auditability.
-
Monitor, troubleshoot, and resolve complex incidents across Azure and Microsoft 365; perform root cause analysis and implement preventive improvements.
-
Establish and maintain operational standards including documentation, runbooks, change management, patching strategies, backup and disaster recovery, and service-level reporting.
-
Optimize cloud costs and performance using tagging strategies, capacity planning, rightsizing, reservations or savings plans, and cost governance processes.
-
Collaborate cross-functionally with security, networking, application teams, and vendors to deliver integrated cloud solutions; provide technical guidance during planning and implementation.
-
Mentor and uplift engineers through coaching, peer reviews for automation and IaC, and leadership in adopting cloud best practices and standards.
Required Qualifications
-
Overall 13+ years of IT infrastructure/engineering experience with 4+ years of hands-on experience in Azure and/or Microsoft 365 in enterprise environments.
-
Bachelor’s degree in Computer Science, Information Systems, or equivalent practical experience.
-
One or more current Microsoft certifications such as Azure Administrator Associate (AZ-104) or equivalent, Microsoft 365 Administrator/Expert-level certification, or Azure Solutions Architect Expert.
-
Proven Azure engineering experience across core services including networking, compute, storage, identity, monitoring, and governance.
-
Microsoft 365 administration experience managing tenant configuration, governance, and troubleshooting across key workloads.
-
Strong identity and access management skills with Microsoft Entra ID, MFA, Conditional Access, SSO integration, and role-based access control (RBAC).
-
Demonstrated ability to implement cloud security controls and support compliance requirements using Microsoft security capabilities (e.g., Defender, Purview concepts).
-
Proficiency in PowerShell and at least one Infrastructure as Code approach (Terraform and/or Bicep/ARM) with CI/CD integration exposure.
-
Strong operational background in incident response, problem management, monitoring, backup/disaster recovery, and change control for production services.
-
Excellent communication, documentation, and stakeholder management skills; ability to explain complex concepts to technical and non-technical audiences.
Preferred Qualifications
-
Advanced certifications such as Azure Solutions Architect Expert, Azure Security Engineer Associate (AZ-500), DevOps Engineer Expert (AZ-400), or Microsoft Security (SC-200/SC-300/SC-100).
-
Hybrid identity experience (Entra Connect or Cloud Sync) and integration of on-premises Active Directory with Microsoft cloud services.
-
Deep Azure networking design experience (hub-and-spoke, firewalling, private endpoints, ExpressRoute/VPN, DNS, routing).
-
Hands-on experience implementing Microsoft Defender for Cloud, Defender for Endpoint/Identity/Office 365, and security monitoring workflows (e.g., Microsoft Sentinel).
-
Experience designing governance at scale (Azure landing zones, management groups, policy/initiative structures, standardized subscription models).
-
Familiarity with Git-based workflows, Azure DevOps or GitHub Actions pipelines, and automated testing for infrastructure deployments.
-
Experience working in ITSM/ITIL-aligned environments (e.g., ServiceNow) and driving measurable operational improvements.
Technical Skills and Competencies
|
Area |
Skills / Tools |
|
Microsoft Azure |
Virtual Networks, VMs, Storage Accounts, Azure Backup, Azure Monitor/Log Analytics, Key Vault; Azure Policy, Management Groups, RBAC, tagging standards; VPN Gateway, ExpressRoute, Private Link/Private Endpoints, NSGs, Azure Firewall, Application Gateway/WAF, DNS; Microsoft Entra ID, PIM, Conditional Access; Defender for Cloud. |
|
Microsoft 365 |
Exchange Online, SharePoint Online, OneDrive, Teams; service health management; governance and lifecycle administration; security and compliance concepts (Purview: DLP, retention; Defender for Office 365; Secure Score). |
|
Automation, IaC, and Tooling |
PowerShell (advanced), Azure CLI; Terraform and/or Bicep/ARM; CI/CD with Azure DevOps and/or GitHub Actions; monitoring and alerting, dashboards, runbooks, SLO/SLA reporting; documentation and diagramming. |
|
Operational and Leadership Competencies |
Technical leadership and mentoring; structured troubleshooting and root cause analysis; cross-team collaboration; requirements translation into scalable designs; ownership mindset for reliability, security, and cost optimization. |
Additional Information
Work Environment and Expectations
-
Participate in an on-call rotation and occasional after-hours maintenance windows as required for critical changes and incident response.
-
Partner with security and compliance teams to ensure cloud services meet organizational and regulatory requirements.
-
Contribute to standards, reference architectures, and continuous improvement initiatives across the cloud platform.
What Success Looks Like (First 6 to 12 Months)
-
Improved reliability and observability of cloud services through standardized monitoring, runbooks, and operational metrics.
-
Measurable progress in security posture through identity hardening, policy compliance, and risk reduction initiatives.
-
Reduced deployment cycle time and configuration drift through increased adoption of Infrastructure as Code and automation.
-
Demonstrated leadership through mentoring, high-quality documentation, and successful delivery of key cloud initiatives.
Equal Opportunity Statement: We are an equal opportunity employer and value diversity. Employment decisions are based on qualifications, merit, and business needs.