Senior Azure & M365 Platform Engineer (Hybrid)
$137.5k - $192.5kTeichert Pipelines
Purpose
The Senior Azure & M365 Platform Engineer plans, designs, implements, and operates identity, access, and endpoint services across Teichert's hybrid Active Directory / Entra ID environment. This senior role leads SSO, MFA, and MDM initiatives, serves as the senior technical authority on Azure and Microsoft 365 platforms, and partners with security, networking, and end-user computing teams. The position combines hands-on architecture and administration with project delivery, automation, Tier 3 escalation, and mentorship of junior administrators.
Focus & Scope
Essential duties and responsibilities, i.e. those which are basic, necessary, and an integral part of the job, are indicated below:
Relationships, Qualifications and Requirements, & Competencies
Key Relationships
Reports to:
Education:
Specific Job Requirements:
Equipment Used, Physical Demands, and Work Environment
Equipment Used:
BASE SALARY RANGE:
$137,500.00 - $192,500.00
The range displayed reflects the range the company reasonable expects to pay for the position. The actual base salary is subject to variation due to the role, level, geographic location, relevant education, training, or experience, among other factors. Employer Disclosure Statement
The above statements and job description is intended to describe the nature and level of work being performed within this job. They are not intended to be an exhaustive list of all responsibilities, duties, and tasks. Other similar or additional duties are performed as assigned. Equal Opportunity Employer
Teichert and its subsidiaries pride themselves on being an Equal Opportunity Employer. Individuals seeking employment at our company are considered without regards to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by federal, state or local laws.
Applicants with disabilities may be entitled to reasonable accommodation. A reasonable accommodation is a change in the way things are normally done that will ensure an equal employment opportunity without imposing an undue hardship on the company. If you are an applicant with a disability, please inform Robert Maxey (View email address on click.appcast.io) if you need assistance completing any forms or to otherwise participate in the application process. Notice to Staffing Agencies
Teichert, Inc. and its subsidiaries ("Teichert") will not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to Teichert, including unsolicited resumes sent to a Teichert mailing address, fax machine or email address, directly to Teichert employees, or to Teichert's resume database will be considered Teichert property. Teichert will NOT pay a fee for any placement resulting from the receipt of an unsolicited resume. Teichert will consider any candidate for whom an Agency has submitted an unsolicited resume to have been referred by the Agency free of any charges or fees. Agencies must obtain advance written approval from Teichert's recruiting function to submit resumes, and then only in conjunction with a valid fully-executed contract for service and in response to a specific job opening. Teichert will not pay a fee to any Agency that does not have such agreement in place. Agency agreements will only be valid if in writing and signed by Teichert's Human Resources Representative or his/ her designee. No other Teichert employee is authorized to bind Teichert to any agreement regarding the placement of candidates by Agencies.
The Senior Azure & M365 Platform Engineer plans, designs, implements, and operates identity, access, and endpoint services across Teichert's hybrid Active Directory / Entra ID environment. This senior role leads SSO, MFA, and MDM initiatives, serves as the senior technical authority on Azure and Microsoft 365 platforms, and partners with security, networking, and end-user computing teams. The position combines hands-on architecture and administration with project delivery, automation, Tier 3 escalation, and mentorship of junior administrators.
Focus & Scope
Essential duties and responsibilities, i.e. those which are basic, necessary, and an integral part of the job, are indicated below:
- Architects and administers on-premises Active Directory (forests, domains, replication, Group Policy, DNS, DHCP, DFS) integrated with Entra ID via Entra Connect, including password hash sync, pass-through authentication, and seamless SSO; maintains hybrid identity health and remediates replication, sync, and authentication issues across the estate.
- Implements SSO and MFA across cloud and on-premises applications using Entra ID, AD FS, SAML, OAuth 2.0, and OpenID Connect including Conditional Access policies, authentication strengths, passwordless, and risk-based access controls.
- Manages identity governance: RBAC, Privileged Identity Management (PIM), just-in-time access, access reviews, and tiered admin models; audits AD and Entra ID against security baselines and remediates findings.
- Implements MDM with Microsoft Intune for Windows, iOS, Android, and macOS endpoints; enrollment, configuration profiles, compliance policies, app deployment, app protection policies, and endpoint compliance signals feeding Conditional Access; administers Windows Autopilot, co-management with Configuration Manager, Windows Update for Business, and BitLocker key escrow.
- Administers Azure infrastructure (VMs, VNets, NSGs, storage, hybrid connectivity via ExpressRoute/VPN/Azure Arc) and governance (management groups, subscriptions, RBAC, Azure Policy, Key Vault, Azure Monitor/Log Analytics, cost and tagging); builds and maintains infrastructure as code with Bicep, ARM, or Terraform and CI/CD pipelines in Azure DevOps or GitHub Actions; maintains Windows Server roles (domain controllers, AD CS/PKI) and Windows endpoint baselines via Group Policy and Intune aligned to CIS Benchmarks and NIST 800-171.
- Builds identity lifecycle automation across AD, Entra ID, Microsoft 365, and downstream apps; HRIS-driven joiner/mover/leaver (JML) workflows via PowerShell, Microsoft Graph, Entra ID lifecycle workflows, and SCIM; automates license assignment, group/Teams membership, mailbox and OneDrive provisioning, and role/department/location-based entitlements; executes secure offboarding (access revocation, session termination, MFA removal, mailbox conversion/retention, data preservation) and partners with HR, Security, and app owners on source-of-truth integrations and lifecycle audit readiness.
- Develops PowerShell, Microsoft Graph, and Azure CLI automation across AD, Entra ID, Intune, Azure, and Microsoft 365; manages source control, code reviews, and pipeline-based release of configuration and policy artifacts; builds runbooks and self-service tooling that reduce toil and improve change quality.
- Leads infrastructure projects including SSO rollouts, MFA deployments, MDM enrollments, tenant migrations, and SharePoint/Teams migrations (Sharegate preferred); produces architectural diagrams, design documents, runbooks, and standard operating procedures.
- Acts as Tier 3 escalation for Azure, Microsoft 365, identity, and endpoint incidents and serves as subject matter expert on related change and problem records; mentors junior administrators and partners with the service desk to improve L1/L2 resolution.
- Administers Microsoft 365 services (Exchange Online, SharePoint Online, OneDrive, Teams) for availability, performance, and adoption including Teams provisioning and lifecycle governance, meeting/messaging policies, third-party and LOB app management, and guest/external access; monitors M365 service health and usage analytics to drive adoption, optimize licensing, and communicate status to stakeholders, and manages Power Platform governance (environment management, DLP connector policies, and Power Automate oversight).
- Manages the email security stack (Microsoft Defender for Office 365, Proofpoint, SPF/DKIM/DMARC, anti-phishing/anti-spoofing, safe attachments/links, and message encryption) and administers Microsoft Purview (DLP, sensitivity labels, retention, litigation hold, and eDiscovery) in support of CIS v8 and NIST 800-171; investigates and remediates email threats and user-reported phishing via Defender and Proofpoint workflows.
Relationships, Qualifications and Requirements, & Competencies
Key Relationships
Reports to:
- IT Director - Operations
- None
- Technology vendors, Microsoft support, third-party software and service providers
- All business units and divisions of the Teichert Family of Companies and Executive Leadership
Education:
- Bachelor's degree in Computer Science, Information Technology, or a related field, or an equivalent combination of training, education, and experience.
- Microsoft certifications such as Identity and Access Administrator Associate (SC-300), Endpoint Administrator Associate (MD-102), Microsoft 365 Administrator Expert (MS-102), Azure Administrator Associate (AZ-104), or Azure Solutions Architect Expert (AZ-305) preferred
- Minimum 10 years of progressive experience administering Azure, Microsoft 365, and Active Directory environments in medium-to-large enterprises.
- Experience in construction, engineering, or industrial industry environment a plus.
Specific Job Requirements:
- Successful completion of pre-employment drug, alcohol, and background investigation.
- Hands-on hybrid AD / Entra ID expertise: Entra Connect, AD FS or modern federation, and hybrid join required.
- Demonstrated experience planning, designing, and implementing SSO, MFA, and Conditional Access in an Entra ID / Microsoft 365 environment required.
- Demonstrated experience planning, designing, and implementing MDM (Microsoft Intune preferred) across Windows and mobile platforms required.
- Strong PowerShell scripting skills for automation across AD, Entra ID, Intune, and Microsoft 365 required.
- Strong working knowledge of Microsoft 365 services (Exchange Online, SharePoint Online, OneDrive, Teams) and their administration in a hybrid environment required.
- Experience administering Microsoft Purview (DLP, sensitivity labels, retention, eDiscovery) and Microsoft Defender for Office 365 required.
- Working knowledge of Group Policy, DNS, DHCP, PKI, and Windows security hardening required.
- Hands-on experience with Azure infrastructure (VMs, networking, storage, hybrid connectivity) and Azure governance (management groups, subscriptions, RBAC, Azure Policy, Key Vault, Azure Monitor/Log Analytics) required.
- Infrastructure as code with Bicep, ARM, or Terraform and CI/CD via Azure DevOps or GitHub Actions required.
- Automation with Microsoft Graph and Azure CLI required.
- Familiarity with security frameworks such as CIS Benchmarks, NIST 800-171, and Zero Trust principles required.
- Experience designing identity lifecycle automation (onboarding, offboarding, role-based provisioning) via PowerShell, Microsoft Graph, and HRIS-driven workflows required.
- Working knowledge of ITIL (Incident, Service Request, Change) with enterprise ITSM tooling such as ServiceNow, Jira Service Management, Cherwell, or BMC Helix required.
- Sharegate experience for SharePoint, Teams, and OneDrive migrations and tenant management preferred.
- Experience with Privileged Access Management (PAM) / Privileged Identity Management (PIM) tooling, Microsoft Defender for Identity, Defender for Endpoint, and Microsoft Sentinel preferred.
- Experience with Proofpoint (PoD, SEG, CASB) and email threat response workflows, working knowledge of email authentication standards (SPF, DKIM, DMARC, BIMI), and networking fundamentals (TCP/IP, DNS, VPN, certificate-based authentication) preferred.
- Excellent troubleshooting and problem-solving skills with the ability to explain technical concepts to non-technical staff.
- Ability to preserve confidential and proprietary information and avoid conflicts of interest.
- Must be able to clearly communicate both verbally and in written form with internal and external customers.
- Building Relationships
- Listening
- Planning/Prioritizing
- Initiative
- Dependability
- Judgement/Decision Making
- Learning/Development
Equipment Used, Physical Demands, and Work Environment
Equipment Used:
- General office equipment, telephone, automobile, personal protective equipment (i.e. safety glasses, hearing protection) when visiting plants.
- Physical: Sitting for long periods of time working on the computer or attending meetings. Job site visits require walking on uneven ground, steep slopes, and exposure to extreme temperature and/or humidity. Some lifting of materials and equipment up to 50 lbs.
- Work Environment: Typical office environment with adequate temperatures and lighting, low levels of noise. Demands of meeting tight deadlines. Exposed to the conditions of job sites which can include loud noise, dust, fumes, and extreme weather conditions prevalent at the time. May work various hours, including early mornings, dusk or evenings.
BASE SALARY RANGE:
$137,500.00 - $192,500.00
The range displayed reflects the range the company reasonable expects to pay for the position. The actual base salary is subject to variation due to the role, level, geographic location, relevant education, training, or experience, among other factors. Employer Disclosure Statement
The above statements and job description is intended to describe the nature and level of work being performed within this job. They are not intended to be an exhaustive list of all responsibilities, duties, and tasks. Other similar or additional duties are performed as assigned. Equal Opportunity Employer
Teichert and its subsidiaries pride themselves on being an Equal Opportunity Employer. Individuals seeking employment at our company are considered without regards to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by federal, state or local laws.
Applicants with disabilities may be entitled to reasonable accommodation. A reasonable accommodation is a change in the way things are normally done that will ensure an equal employment opportunity without imposing an undue hardship on the company. If you are an applicant with a disability, please inform Robert Maxey (View email address on click.appcast.io) if you need assistance completing any forms or to otherwise participate in the application process. Notice to Staffing Agencies
Teichert, Inc. and its subsidiaries ("Teichert") will not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to Teichert, including unsolicited resumes sent to a Teichert mailing address, fax machine or email address, directly to Teichert employees, or to Teichert's resume database will be considered Teichert property. Teichert will NOT pay a fee for any placement resulting from the receipt of an unsolicited resume. Teichert will consider any candidate for whom an Agency has submitted an unsolicited resume to have been referred by the Agency free of any charges or fees. Agencies must obtain advance written approval from Teichert's recruiting function to submit resumes, and then only in conjunction with a valid fully-executed contract for service and in response to a specific job opening. Teichert will not pay a fee to any Agency that does not have such agreement in place. Agency agreements will only be valid if in writing and signed by Teichert's Human Resources Representative or his/ her designee. No other Teichert employee is authorized to bind Teichert to any agreement regarding the placement of candidates by Agencies.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Senior Azure & M365 Platform Engineer (Hybrid) in Sacramento, CA vacancy
- ...An established industry player is seeking a skilled Hybrid Cloud Solutions Design Specialist with a strong technical background in GCP... ...years of experience, a proven ability to build relationships with senior IT executives, and a knack for adapting to new technologies. If...SeniorFor contractors
- ...implementing, automating, and maintaining security platforms that support enterprise cybersecurity... ...cloud experience blended with platform engineering capabilities to mature the AI Security... ...security tools and platforms (GCP, AWS, Azure) • Container security (Docker,...SeniorImmediate startRemote workFlexible hours
- ...encompasses ownership of the architecture and performance of SaaS platforms and integrations. As the lead, you'll manage a lean team, drive... ...with stakeholders to deliver scalable solutions. A hybrid work environment is offered. #J-18808-Ljbffr International Executive...Senior
- ...Join Blue Shield of CA as a Senior Behavioral Health Utilization Management Clinician in Rancho Cordova, CA. In this hybrid role, you will conduct clinical reviews for mental health and substance use requests, ensuring compliance with evidence-based guidelines. The position...Senior
$122.57k
A leading facilities management company is seeking a Senior Integration Engineer in Sacramento, CA. This role requires a seasoned technical leader... ...years of software development experience and expertise in Azure and API integrations. The compensation range is $122,573.13...Senior$89.2k - $209.5k
...Description Role Summary Oracle Health Platform Engineering builds core platform capabilities that... ..., and operations. We are seeking a Senior Software Developer (IC3) to design,... ...Cloud experience preferred (OCI, AWS, Azure, or GCP), including cloud-native development...SeniorTemporary workVisa sponsorshipFlexible hours- ...Hazen and Sawyer is looking for a Senior Hydrogeologist/Project Manager in Sacramento, CA. This full-time role involves leading groundwater... ...skills. Key benefits include comprehensive health benefits, a hybrid work schedule, and opportunities for professional growth. #J-188...SeniorFull time
- ...next-generation data center SSD solutions. This role involves setting architectural vision and driving system design decisions in a hybrid work environment. The ideal candidate should have over 5 years of experience in embedded systems architecture, collaborating...Senior
$54 - $66 per hour
...requests, maintain regulatory compliance, and have strong leadership skills. The position requires 7+ years of UM experience and offers a pay range of $54-$66/hour as a hybrid role. Join a collaborative environment dedicated to quality healthcare delivery. #J-18808-Ljbffr...Senior$85k - $134k
...A leading infrastructure consulting firm is seeking a talented Proposal Specialist IV for a hybrid role involving proposal development and strategy. The ideal candidate has at least 6 years of marketing experience within the A/E industry and is proficient in design tools...Senior- ...certification, and a minimum of 7 years of relevant clinical experience. The position emphasizes analytical and documentation skills, with a hybrid workplace model allowing for in-office collaboration two days a week. Ideal candidates will have experience in health plans or...SeniorWork at office2 days per week
- ...The County of Sacramento is seeking a Senior Accountant to lead and oversee an accounting team. In this role, you will ensure that accounting... .... A CPA license may substitute for the degree. You will have opportunities for hybrid telework arrangements. #J-18808-Ljbffr...SeniorRemote work
- ...EY is seeking a Real Estate Tax Senior Manager in Sacramento, California, to lead tax planning projects and provide strategic outcomes... ...project management and client relationships. The position offers a hybrid work model and a comprehensive benefits package. #J-18808-Ljbffr...Senior
- ...Sacramento County, CA is looking for a Senior Accountant under general supervision to lead and oversee accounting staff while performing... ...and have at least two years of relevant experience. A telework hybrid work schedule may be available. Apply to join a dedicated team in...SeniorRemote work
- ...stakeholders. Candidates should have a Bachelor's degree in a relevant field and over 10 years of experience in risk management, with strong communication and analytical skills. This position is hybrid and offers a significant opportunity for impact. #J-18808-Ljbffr...Senior
- ...CFA Institute is seeking a Senior Regional Consultant - Wealth Management to sell MFS Investment products in California, Nevada, and Hawaii... ...skills in communication and leadership. This position offers a hybrid work model and competitive compensation. #J-18808-Ljbffr...Senior
- ...A leading global consulting firm seeks a Cloud Engineer to design, implement, and manage cloud infrastructure solutions. Candidates should have expertise in Azure and Kubernetes, along with strong problem-solving and communication skills. The role involves collaborating...
- ...A prominent California university is seeking a Senior Research Analyst to support Institutional Research by managing research projects... ...experience in research and data analysis. The position offers a hybrid work option, competitive salary, and a generous benefits package...Senior
- ...Twenty Four Seven Hotels is seeking an experienced Sales Executive to drive revenue across a portfolio of hotels in Sacramento. This hybrid role requires at least five years of sales management experience in hotels, preferably with premium brands like Marriott and Hilton...Senior
$194.29k - $297.9k
...NTT DATA is looking for a Sr. Sales Executive - SLED in Sacramento, California. This hybrid role requires a strong background in enterprise sales and public sector markets. The ideal candidate will have over 7 years of experience in identifying market opportunities, developing...Senior- ...Golden1 is seeking a Senior Service Designer to enhance member experiences across its services. The role involves collaboration with various... ...experience in prototyping tools like Adobe and Figma, is essential. This is a hybrid position located in California. #J-18808-Ljbffr...Senior
- ...Ericsson is looking for a Senior Business Development Manager to drive business growth in Mobile Financial Services in North America. This hybrid role requires generating new business, managing sales cycles, and developing strong relationships with clients. Ideal candidates...Senior
- ...California Department of Housing & Community Development seeks a Senior Housing Policy Specialist to conduct research and develop... ...land use and housing for special populations. The position offers hybrid work arrangements and requires strong analytical skills and experience...Senior
$76.52k - $163.9k
...financial goals. Key skills include a strong sales background, knowledge of commercial lending, and financial analysis. The role offers a hybrid working model, with a competitive benefits package and a compensation range of $76,520.00 - $163,900.00. #J-18808-Ljbffr...Senior- ...Jacobs Engineering Group Inc. is seeking a Senior Ecosystem Restoration Design Engineer Lead in California to manage ecological restoration projects across... ...high-quality plans and reports. The position offers a hybrid work model and is critical for stream restoration...Senior
$39.42 - $50 per hour
...A leading employment law firm seeks an Attorney Practice Coordinator in Sacramento, California. This hybrid role involves coordinating support for multiple attorneys, handling court documentation, and ensuring deadlines are met. Candidates should have at least 10 years...SeniorHourly pay- ...candidate will have a Bachelor's degree and 5 years of sales experience. A valid driver’s license is necessary, and the position offers a hybrid work schedule. Employees enjoy various benefits, including competitive compensation and a comprehensive rewards package. #J-18808-...Senior
$11.99k - $16.1k
...least six years of legal experience with expertise in California statute law and strong negotiation skills. The position offers a hybrid work model with a salary range of $11,993.00 - $16,096.00, set to begin on July 1, 2025. Ideal candidates will have extensive knowledge...Senior$123k - $207k
...construction crews and managing project inspectors. With a focus on maintaining safety and reliability in electric service, this position offers a hybrid work environment and competitive salary ranging from $123,000 to $207,000 based on experience and location. #J-18808-Ljbffr...Senior- ...NACBA is looking for a Senior Accountant in Sacramento to lead and oversee various accounting duties within multiple county departments... ...communicating job expectations. The position may offer a telework hybrid schedule. Applicants should hold a Bachelor’s degree in...SeniorRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Azure & M365 Platform Engineer (Hybrid). Be the first to apply!
Related searches
- platform developer Sacramento, CA
- platform engineer Sacramento, CA
- client platform engineer Sacramento, CA
- senior platform engineer Sacramento, CA
- senior automation controls engineer Sacramento, CA
- senior accounts payable Sacramento, CA
- senior brand designer Sacramento, CA
- senior cost analyst Sacramento, CA
- senior business analyst contract Sacramento, CA
- senior app developer Sacramento, CA

