> Markdown version of [/jobs/ext/3298366-microsoft-365-engineer-identity-endpoint-compliance](https://www.wearedevelopers.com/jobs/ext/3298366-microsoft-365-engineer-identity-endpoint-compliance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Microsoft 365 Engineer (Identity, Endpoint & Compliance) - **Company:** WellStreet Urgent Care - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Artificial Intelligence, Android Software Development, Apple IOS, Apple Mac Systems, Application Portfolio Management, Health Informatics, Spreadsheets, Cloud Computing, Configuration Management, Cyber Security, Data Governance, Python (Programming Language), Microsoft Office, Windows PowerShell, Anti-Phishing, Azure DevOps Pipelines, Microsoft SharePoint, Enterprise Software Applications, Microsoft InTune, Deployment Automation, Bicep, CIS Benchmarks, Terraform, Network Server, Software Version Control - **Published:** September 12, 2026 - **Apply:** https://www.dice.com/job-detail/e2dbae1e-c52c-4985-8426-758ffbc40df2 ## About the Role Five or more years in M365, identity or security engineering, with tenant-level depth in Entra ID and Intune Real Purview configuration experience: writing DLP policies, labeling, retention, eDiscovery. Not just familiarity., Terraform, Bicep or Azure DevOps pipelines. Any exposure to declarative M365 management: Microsoft365DSC, a Terraform M365 provider, the Graph Tenant Configuration Management APIs. Healthcare IT. Owning a vulnerability or patch compliance program. FreshService or a comparable ITSM. ITIL v4. SC-200, SC-300, SC-400, MS-102, MD-102., A positive attitude toward patients, families, and coworkers. Willingness to go the extra mile to create an outstanding experience for customers and to train and lead the center team to do the same. A desire to work in concert with others in an upbeat and supportive atmosphere while reinforcing the WellStreet mission to provide uncompromising service. A compelling desire to serve others, improve your community's health, and have fun every day. ## Description We're hiring the engineer who'll own the Microsoft 365 platform at WellStreet, in an environment where identity and data governance are HIPAA obligations and not checkboxes. The governance you put in place is what we'll run on, and how it gets managed is yours to define. A week in this job: Monday you're designing the sensitivity label taxonomy and the DLP policies that enforce it across Exchange, SharePoint and Teams. Tuesday a clinical vendor needs SSO and SCIM, so you stand it up, and you're the one who catches that their deprovisioning webhook never fires. Wednesday you close quarterly access reviews on privileged groups, driven off a Graph script you wrote instead of a spreadsheet somebody emails around. Thursday a Critical CVE lands from SecOps and you own the triage and the clock. Friday you take the Intune configuration that has only ever existed in an admin center and get it into the repo. What you'll own: Entra ID: tenant architecture, Conditional Access, hybrid identity, privileged access, password protection and SSPR, access reviews Intune: tenant configuration across Windows, macOS, iOS and Android. Compliance and configuration profiles, security baselines, Autopilot, update rings, app packaging. Exchange Online, Teams and SharePoint: tenant configuration, mail flow, transport rules Purview: DLP, sensitivity labeling, retention, audit configuration, eDiscovery, and HIPAA and HITRUST control mapping Enterprise Applications: SSO and SCIM across the portfolio, plus the standard that no app touching PHI runs on standalone credentials Defender: endpoint detection and response on every managed device, Defender for Office 365 anti-phishing and threat investigation, and the unified alert view across the M365 estate. Defender for Servers, Defender for Cloud, and Defender for Identity - the workload security surface - sit with infrastructure. Vulnerability response: CVE triage from SecOps, remediation tracking, weekly report The application portfolio: an accurate catalog, runbooks that work, and the vendors in your domain held to their SLAs and their BAAs, Microsoft Graph and PowerShell fluency. This is the one hard technical gate. You automate by default and you've built real things against the API. Python is a plus. Version control is where your work lives, and branches and pull requests are normal practice for you You've worked against a regulated framework, whether HIPAA, HITRUST, SOC 2 or PCI, and you can explain a control instead of just naming it You use AI daily and can say where you trust it and where you check it