← Back to jobs

Senior Azure & M365 Infrastructure Engineer

Location
Newark, NJ
Work type
Full Time · Hybrid
Posted
2026-07-20

Job description

The Role

You will design, build, and automate the Azure and Microsoft 365 platforms behind our managed cloud service, with a focus on repeatable, infrastructure-as-code delivery for new and existing clients. You will be a senior escalation point for Managed Services, vendors, and Microsoft support, and partner with architects and Cybersecurity to modernize client estates. This role follows a hybrid working model, with 4 days on-site and 1 day working from home.

Responsibilities:

Serve as the senior onsite technical lead and trusted advisor to the client’s CTO and senior stakeholders
Design and deploy Azure and Microsoft 365 solutions using infrastructure-as-code (Bicep, ARM, Terraform, PowerShell)
Build Azure landing zones aligned to the Cloud Adoption Framework
Lead public cloud migrations: email, files, apps, servers, and identity
Act as senior escalation for Managed Services, vendors, and Microsoft support
Administer Microsoft Entra ID: conditional access, PIM, RBAC, and hybrid identity
Run M365 security: Defender for Endpoint/XDR, Sentinel, Purview, and Intune
Improve design, security, performance, and cost, and keep documentation current

Requirements
Essential (Azure & Microsoft)

Proven track record as a senior technical resource in a dedicated or client-facing environment
4+ years with Azure and Microsoft 365 infrastructure
Azure compute: VMs, Availability Sets/Zones, Storage Accounts, Site Recovery
Azure networking: VNets, Virtual WAN, ExpressRoute, VPN Gateway, NSGs
Microsoft Entra ID: conditional access and hybrid identity
M365 admin: Exchange Online, Teams, SharePoint, OneDrive, Intune (MAM/MDM), Defender for Endpoint
Public cloud migrations and configuration management
Automation: PowerShell with Bicep/ARM or Terraform
Strong written documentation for infrastructure or cloud environments
Eligible to work in the United States

Great to Have

Azure governance: Policy, RBAC, Management Groups, and Landing Zones aligned to the Cloud Adoption Framework
Azure security and edge: Application Gateway (WAF), Firewall, DDoS Protection
Microsoft security and compliance tools: Purview, Sentinel, Defender for Cloud

Networking (Nice to Have)

Fortinet (FortiGate) firewalls
Cisco Meraki switches and access points
Ubiquiti UniFi switching, access points, and controllers
LAN/WAN, VLANs, routing, DNS, DHCP, and VPN

Certifications (a plus)

AZ-104, AZ-305, AZ-700, MS-102 or SC-300, and Fortinet NSE

Who You Are

Consultative, solution-focused, and proactive
Hands-on, accountable, and versatile
Always learning, and shares knowledge across the team

Original source