Senior Azure & M365 Infrastructure Engineer
- Location
- Newark, NJ
- Work type
- Full Time · Hybrid
- Posted
- 2026-07-20
Job description
The Role
You will design, build, and automate the Azure and Microsoft 365 platforms behind our managed cloud service, with a focus on repeatable, infrastructure-as-code delivery for new and existing clients. You will be a senior escalation point for Managed Services, vendors, and Microsoft support, and partner with architects and Cybersecurity to modernize client estates. This role follows a hybrid working model, with 4 days on-site and 1 day working from home.
Responsibilities:
Serve as the senior onsite technical lead and trusted advisor to the client’s CTO and senior stakeholders
Design and deploy Azure and Microsoft 365 solutions using infrastructure-as-code (Bicep, ARM, Terraform, PowerShell)
Build Azure landing zones aligned to the Cloud Adoption Framework
Lead public cloud migrations: email, files, apps, servers, and identity
Act as senior escalation for Managed Services, vendors, and Microsoft support
Administer Microsoft Entra ID: conditional access, PIM, RBAC, and hybrid identity
Run M365 security: Defender for Endpoint/XDR, Sentinel, Purview, and Intune
Improve design, security, performance, and cost, and keep documentation current
Requirements
Essential (Azure & Microsoft)
Proven track record as a senior technical resource in a dedicated or client-facing environment
4+ years with Azure and Microsoft 365 infrastructure
Azure compute: VMs, Availability Sets/Zones, Storage Accounts, Site Recovery
Azure networking: VNets, Virtual WAN, ExpressRoute, VPN Gateway, NSGs
Microsoft Entra ID: conditional access and hybrid identity
M365 admin: Exchange Online, Teams, SharePoint, OneDrive, Intune (MAM/MDM), Defender for Endpoint
Public cloud migrations and configuration management
Automation: PowerShell with Bicep/ARM or Terraform
Strong written documentation for infrastructure or cloud environments
Eligible to work in the United States
Great to Have
Azure governance: Policy, RBAC, Management Groups, and Landing Zones aligned to the Cloud Adoption Framework
Azure security and edge: Application Gateway (WAF), Firewall, DDoS Protection
Microsoft security and compliance tools: Purview, Sentinel, Defender for Cloud
Networking (Nice to Have)
Fortinet (FortiGate) firewalls
Cisco Meraki switches and access points
Ubiquiti UniFi switching, access points, and controllers
LAN/WAN, VLANs, routing, DNS, DHCP, and VPN
Certifications (a plus)
AZ-104, AZ-305, AZ-700, MS-102 or SC-300, and Fortinet NSE
Who You Are
Consultative, solution-focused, and proactive
Hands-on, accountable, and versatile
Always learning, and shares knowledge across the team