Sr Cloud Engineer – Microsoft 365 / Entra ID
Aroha Technologies, Inc · Crystal City, VA · 2 wk ago
HybridContract
Location: Crystal City, VA (Hybrid 3-day onsite: Tuesday & Thursday mandatory, plus one additional day)
Employment Type: Full-Time
About the Role
We are seeking an experienced Senior Cloud Engineer Microsoft 365 / Entra ID to join our IT Infrastructure Operations team. In this role, you will be responsible for designing, administering, securing, and optimizing enterprise Microsoft 365 and Entra ID environments while driving automation, governance, and modern cloud operational practices. This is a highly technical, hands-on individual contributor role supporting enterprise collaboration, identity, messaging, and security platforms in a large-scale Microsoft ecosystem.
Responsibilities
- Design, administer, and optimize Microsoft 365 services including Exchange Online, SharePoint Online, Teams, OneDrive, Microsoft Copilot, and related collaboration services.
- Manage and secure Microsoft Entra ID (Azure AD), including Conditional Access, Identity Protection, MFA, RBAC, Privileged Identity Management (PIM), Enterprise Applications, and App Registrations.
- Own Exchange Online administration, including:
- Mail flow
- Transport rules
- Connectors
- Hybrid Exchange
- Security policies
- Advanced mail troubleshooting
- Implement and maintain Microsoft 365 security and compliance solutions including:
- Microsoft Defender
- Microsoft Purview
- Data Loss Prevention (DLP)
- Retention policies
- eDiscovery
- Auditing
- Investigate security incidents and operational issues using KQL, Microsoft Defender, Log Analytics, and Microsoft Sentinel (preferred).
- Develop PowerShell automation and Microsoft Graph API integrations to streamline administration, provisioning, and reporting.
- Support CI/CD and Infrastructure-as-Code practices using Azure DevOps and GitHub.
- Collaborate with infrastructure, networking, and security teams to maintain enterprise identity and cloud security best practices.
- Support Kubernetes/AKS identity integrations where Microsoft Entra ID authentication is required.
- Lead root cause analysis and resolution of Microsoft 365 and identity-related incidents.
- Produce technical documentation, architecture diagrams, operational runbooks, and governance standards.
- Mentor junior engineers and promote Microsoft 365 operational excellence.
Requirements
- Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field (or equivalent experience).
- 9+ years of IT infrastructure or cloud engineering experience.
- 5+ years of hands-on Microsoft 365 administration within a mid-to-large enterprise environment.
- Deep expertise with Microsoft Entra ID (Azure AD).
- Expert-level experience administering Exchange Online.
Skills
- Strong understanding of:
- Conditional Access
- MFA
- OAuth
- OpenID Connect (OIDC)
- Federation
- Single Sign-On (SSO)
- Identity Protection
- RBAC
- Experience with Microsoft Defender, Microsoft Purview, DLP, retention policies, auditing, and compliance.
- Strong PowerShell scripting and automation skills.
- Experience writing and troubleshooting KQL queries in Microsoft Defender, Sentinel, or Log Analytics.
- Experience using Azure DevOps or GitHub for automation, source control, or CI/CD workflows.
- Excellent troubleshooting, analytical, and communication skills.
Preferred Qualifications
- Experience with Microsoft Graph API.
- Experience administering Microsoft Sentinel.
- Knowledge of Kubernetes or Azure Kubernetes Service (AKS) identity integration.
- Experience with Microsoft Copilot administration.
- Familiarity with LSoft ListPlex.
- Microsoft certifications related to Microsoft 365, Azure, or Security are highly desirable.