M365 / Collaboration Platform Administrator

ICFWashington, DC
$108,006 - $183,610Hybrid

About The Position

This role is contingent upon a contract award. ICF is seeking an M365 / Collaboration Platform Administrator to configure, govern, and maintain the Microsoft 365, Google Workspace, and SaaS productivity platform environment for a federal technology program. Reporting to the Cloud / Enterprise Architecture Lead, this role owns tenant configuration, data protection settings, SaaS platform governance, and Power Platform administration across a broad portfolio of collaboration and productivity tools. The ideal candidate has deep experience hardening and operating M365 and SaaS environments in federal settings. The right candidate understands how to configure collaboration platforms securely at scale, govern low-code tooling without blocking adoption, and keep tenant settings audit-ready without constant manual intervention. This position requires that the job be performed in the United States. ICF does monitor employee work locations and blocks access from foreign locations/foreign IP addresses and also prohibits personal VPN connections.

Requirements

  • Bachelor's degree or equivalent
  • 5+ years of experience in M365 administration, SaaS platform management, or a related discipline
  • 3+ years configuring and administering Microsoft 365 tenants, including Exchange Online, SharePoint, Teams, and security and compliance settings
  • 2+ years administering Power Platform environments, including environment governance, DLP policies, and ALM pipelines
  • 2+ years supporting federal IT programs in HHS, NIH, FDA, or other health-focused agencies
  • U.S. Citizenship required due to federal contract requirements
  • Ability to obtain and maintain a Public Trust background investigation
  • Candidate must reside in the US, be authorized to work in the US, and work must be performed in the US

Nice To Haves

  • Experience administering Google Workspace tenants in addition to M365
  • Familiarity with NIST 800-53, CIS Level 1 benchmarks, and CISA guidelines as they apply to SaaS and collaboration platform configuration
  • Experience managing Exchange Online mail flow, including transport rules, anti-phishing configuration, and DNS record management
  • Relevant certifications such as Microsoft 365 Certified: Administrator Expert, Microsoft 365 Certified: Teams Administrator Associate, or equivalent
  • Experience using PowerShell and Microsoft Graph API for automated tenant administration and audit reporting

Responsibilities

  • Configure and manage Microsoft 365 and Google Workspace tenants, including email, collaboration, storage, and meetings, hardened against NIST 800-53, CIS Level 1, and CISA baselines, with DLP rules, retention labels, and external sharing controls.
  • Manage SaaS collaboration platforms including OneDrive, SharePoint, Teams, Slack, GitHub, and others, maintaining access controls, data boundaries, approval workflows, and guest access configurations.
  • Govern and maintain the Power Platform environment, including Power Apps, Power Automate, and Power BI, setting up environments, security models, and data boundaries so teams can build solutions within defined guardrails.
  • Apply data protection and compliance settings across all platforms, including sensitivity labels, DLP rules, conditional access, encryption settings, and device or location restrictions.
  • Manage the agency email architecture, including Exchange Online configuration, mail flow policies, transport rules, spam and phishing protections, and safe links and attachments.
  • Use PowerShell, Graph API, and scripted automation to build, change, and audit platform configurations consistently and at scale rather than through manual administration.
  • Manage licenses and subscriptions across platforms, using reports and automation to reclaim unused licenses, right-size plans, and control app sprawl.
  • Perform quarterly reviews of platform configurations against security baselines and compliance requirements, preferably using compliance-as-code approaches.
  • Coordinate with identity, device, and cybersecurity teams so that SaaS access policies, device compliance rules, and conditional access work together as part of a consistent Zero Trust model.
  • Maintain documentation of platform configurations, reference patterns, and runbooks so others can safely operate and extend the environment.

Benefits

  • Reasonable Accommodations are available, including, but not limited to, for disabled veterans, individuals with disabilities, and individuals with sincerely held religious beliefs, in all phases of the application and employment process.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service