Lead Microsoft Platforms Engineer
Role details
Job location
Tech stack
Job description
UVA ITS is seeking a Lead Microsoft Platforms Engineer to join the Enterprise Infrastructure division. This role serves as the lead engineer, primary technical contact, and subject matter expert for critical Microsoft services, including Microsoft 365, enterprise email, Microsoft Defender, Entra ID, Active Directory, and related Azure services., The Lead Microsoft Platforms Engineer provides technical leadership across service design, administration, security, automation, incident response, and continuous improvement. The successful candidate will bring deep experience across the Microsoft ecosystem, including Microsoft 365 integrated applications, hybrid messaging and identity environments, secure email gateways, and emerging Microsoft AI capabilities such as Copilot, Copilot Studio, and Copilot agents. This position is responsible for secure, reliable, and efficient service delivery; responsive customer support; and timely resolution of complex technical issues., * Lead service ownership and technical direction for core Microsoft platforms, serving as the lead engineer and subject matter expert for Microsoft 365, Exchange Online and enterprise email, Teams, SharePoint, OneDrive, Bookings, shared mailboxes, distribution lists, room calendars, Power Platform, Microsoft Fabric, Entra ID, and Active Directory
- Engineer and administer enterprise messaging services, including Exchange Hybrid provisioning and attributes, inbound and outbound mail routing, mail flow rules, connectors, message tracing, domain and DNS configuration, DMARC, FortiMail, Microsoft Defender policies, quarantine monitoring, and anti-spam, anti-virus, anti-malware, and anti-phishing controls
- Design and manage identity and access services, including Conditional Access, Privileged Identity Management, role-based access control, single sign-on, multifactor authentication, user and group lifecycle, provisioning and licensing, Entra B2B and external collaboration, guest access, app registrations, enterprise applications, directory synchronization, and the Entra consent framework
- Develop and support enterprise integrations and automation using Microsoft Graph API, Azure Functions, Automation Runbooks, Copilot, Copilot Studio, Copilot agents, and Microsoft Fabric workspaces, capacities, access controls, licensing, and governance
- Support related Azure infrastructure and networking services, including virtual machines, Network Security Groups, firewalls, Traffic Manager, load balancers, ARM templates, provisioning, monitoring, and platform connectivity
- Ensure secure and reliable operations through monitoring, alerting, tuning, escalation, SIEM tools such as Splunk, Microsoft Sentinel, and Azure Monitor, advanced troubleshooting, incident response, Tier 3 help desk escalation, M365 entitlement and information management, permissions management, and service lifecycle governance
- Drive operational excellence and continuous improvement by developing service roadmaps, introducing new service offerings, maintaining thorough product and technical documentation, owning knowledge-base content, mentoring engineers, leading cross-functional initiatives, delivering excellent customer service, and performing other duties as assigned, This is primarily a sedentary job involving extensive use of desktop computers. The job does occasionally require traveling some distance to attend meetings or programs., * Background checks will be conducted on all new hires prior to employment
- Education verification will be required prior to employment
- This position will not consider candidates who require immigration sponsorship now or in the future
Requirements
- Bachelor's degree in Computer Science, Information Systems, or a related field; relevant experience may be considered in lieu of a degree, * At least five years of relevant experience administering Microsoft 365, Exchange, Windows Server, Active Directory, and Azure in a mid-sized to large enterprise environment
- Proven experience designing, implementing, and supporting Microsoft 365 solutions, including Exchange Online, Teams, SharePoint Online, and OneDrive
- Experience supporting hybrid environments, including Exchange Hybrid, migrations, directory synchronization, and Entra ID integrations such as single sign-on and Conditional Access
- Experience implementing and managing identity and access solutions, including single sign-on, multifactor authentication, Conditional Access, role-based access control, and Entra Privileged Identity Management
- Experience supporting enterprise integrations and automation using platform administration or scripting tools, including Azure Functions and Automation Runbooks
- Experience with Microsoft Defender EDR/XDR capabilities, including anti-spam, anti-phishing, anti-malware, quarantine, and related security-policy administration
- Experience administering a secure email gateway such as FortiMail, including mail routing and Anti-X policy configuration for anti-spam, anti-virus, anti-malware, and anti-phishing protection
- Demonstrated ability to troubleshoot complex infrastructure and cloud-platform issues and support advanced incident response
- Demonstrated ability to communicate complex technical concepts to technical and non-technical audiences
- Strong customer-service orientation, collaborative problem-solving skills, written and verbal communication skills, and ability to coordinate across multiple groups to complete projects on time, * Master's degree in Computer Science, Information Systems, or a related field, * Eight or more years of experience supporting hybrid Microsoft environments
- Familiarity with Microsoft AI capabilities, including Copilot, Copilot Studio, agent development, deployment, and governance
- Microsoft Fabric administration experience, including workspace provisioning, access control, licensing, governance, and capacity management
- Experience with Microsoft Graph API, enterprise application integrations, and the Entra consent framework
- Experience with SIEM and monitoring technologies such as Splunk, Microsoft Sentinel, and Azure Monitor
- Experience supporting enterprise security, information management, entitlement management, and governance initiatives
- Experience working in higher education or another large, complex enterprise environment
- Strong proficiency with FortiMail or similar secure email gateway systems, including mail routing, transport policies, and Anti-X tuning
- Experience managing Microsoft 365 domains, DNS, and DMARC configuration
- Familiarity with Azure virtual-machine provisioning, ARM templates, Traffic Manager, and load-balancer provisioning and monitoring
- Experience mentoring engineers and leading cross-functional technical initiatives
- Experience developing roadmaps, creating product documentation, deploying new service offerings, and driving continuous improvement
- Experience managing and resolving critical-service incidents using ServiceNow or a comparable IT service management platform
Benefits & conditions
Pulled from the full job description
- Paid parental leave
- Parental leave
- Health insurance
- Paid time off
- Vision insurance
- Dental insurance
- Flexible spending account