Employer : An MSP company located in Las Vegas, Nevada
Work Setup : Remote
Working Schedule : Monday to Friday, Pacific Standard Time
Salary : Php 110,000 - Php 137,500
Position Summary
We are seeking an experienced Microsoft 365 Security Implementation Specialist to design, deploy, and configure enterprise-wide security solutions using Microsoft's comprehensive security stack. This role focuses on implementing Zero Trust architecture, configuring advanced security controls, and ensuring robust protection across cloud and endpoint environments. The ideal candidate will have deep expertise in Microsoft Intune, Defender for Endpoint, Conditional Access, and compliance frameworks, with a proven track record of successful security implementations in enterprise environments.
Key Responsibilities
Zero Trust Architecture Implementation
- Design and deploy comprehensive Zero Trust security models using Microsoft 365 security suite
- Configure identity-centric security controls leveraging Microsoft Entra ID (Azure AD) capabilities
- Implement least-privilege access models with Just-In-Time (JIT) and Privileged Identity Management (PIM)
- Establish micro-segmentation strategies and network security boundaries
Endpoint Management & Protection
Deploy and configure Microsoft Intune for comprehensive Mobile Device Management (MDM) and Mobile Application Management (MAM)Implement Windows Autopilot for zero-touch device provisioning and configurationConfigure device compliance policies aligned with CIS Controls and security baselinesDeploy and optimize Microsoft Defender for Endpoint across hybrid environmentsEstablish endpoint detection and response (EDR) capabilities with automated remediationIdentity & Access Management
Design and implement Conditional Access policies based on risk assessment and organizational requirementsConfigure Multi-Factor Authentication (MFA) and passwordless authentication methodsDeploy identity protection policies and risk-based access controlsIntegrate identity governance with automated access reviews and lifecycle managementCloud Security & Compliance
Configure Microsoft Defender for Cloud Apps (CASB) for Shadow IT discovery and controlImplement Data Loss Prevention (DLP) policies across Microsoft 365 servicesDeploy Microsoft Purview for data governance, classification, and compliance managementEnsure alignment with CIS 18 Critical Security Controls and other regulatory frameworksConfigure security monitoring and automated alerting systemsIntegration & Automation
Develop PowerShell scripts and Microsoft Graph API integrations for security automationIntegrate Microsoft security solutions with existing SIEM / SOAR platformsCreate custom security workflows and incident response playbooksImplement Infrastructure as Code (IaC) for consistent security deploymentsFramework Implementation & Documentation
Apply NIST Cybersecurity Framework and CMMC requirements to Microsoft 365 implementationsDevelop security configuration baselines and hardening guidesCreate comprehensive technical documentation and security proceduresConduct security assessments and gap analyses against industry frameworksRequired Qualifications
Education & Experience
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field (or equivalent experience)3-5 years for mid-level positions; 5-8+ years for senior-level positions of hands-on experience with Microsoft 365 and Azure security technologiesDemonstrated experience implementing security solutions in enterprise environments (1,000+ users)Proven track record of successful Microsoft security tool deployments and configurationsTechnical Requirements
Expert-level proficiency in Microsoft Intune / Endpoint Manager configuration and deploymentAdvanced knowledge of Microsoft Defender suite (Defender for Endpoint, Office 365, Cloud Apps)Strong experience with Conditional Access policy design and implementationHands-on expertise with Microsoft Entra ID (Azure AD) and identity managementPowerShell scripting capabilities for automation and bulk operationsUnderstanding of networking fundamentals and security principlesExperience with security compliance frameworks, particularly CIS ControlsPreferred Qualifications
Microsoft Certifications (Highly Valued)
SC-300 : Microsoft Identity and Access Administrator AssociateSC-200 : Security Operations Analyst AssociateAZ-500 : Azure Security Engineer AssociateSC-100 : Cybersecurity Architect Expert (for senior roles)MD-102 : Endpoint Administrator AssociateMS-102 : Microsoft 365 Administrator ExpertAdditional Technical Skills
Experience with Zero Trust implementation and architectureKnowledge of additional compliance frameworks (NIST 800-171, CMMC, ISO 27001)Familiarity with Microsoft Sentinel and KQL (Kusto Query Language)Experience with hybrid cloud environments and multi-cloud securityUnderstanding of DevSecOps practices and Infrastructure as Code (Terraform, ARM templates)Integration experience with third-party security tools and SIEM platformsSoft Skills & Competencies
Strong analytical and problem-solving abilitiesExcellent written and verbal communication skills for technical and executive audiencesAbility to manage multiple implementation projects simultaneouslyExperience working in cross-functional teams and hybrid work environmentsClient-facing consulting experience (for senior positions)Security-first mindset with attention to detail