Senior Microsoft 365 Engineer

Urgent Care Management or Joint Venture PartnerAtlanta, GA

About The Position

We’re hiring the engineer who’ll own the Microsoft 365 platform at WellStreet, in an environment where identity and data governance are HIPAA obligations and not checkboxes. The governance you put in place is what we’ll run on, and how it gets managed is yours to define. A week in this job: Monday you’re designing the sensitivity label taxonomy and the DLP policies that enforce it across Exchange, SharePoint and Teams. Tuesday a clinical vendor needs SSO and SCIM, so you stand it up, and you’re the one who catches that their deprovisioning webhook never fires. Wednesday you close quarterly access reviews on privileged groups, driven off a Graph script you wrote instead of a spreadsheet somebody emails around. Thursday a Critical CVE lands from SecOps and you own the triage and the clock. Friday you take the Intune configuration that has only ever existed in an admin center and get it into the repo. What you’ll own: Entra ID: tenant architecture, Conditional Access, hybrid identity, privileged access, password protection and SSPR, access reviews Intune: tenant configuration across Windows, macOS, iOS and Android. Compliance and configuration profiles, security baselines, Autopilot, update rings, app packaging. Exchange Online, Teams and SharePoint: tenant configuration, mail flow, transport rules Purview: DLP, sensitivity labeling, retention, audit configuration, eDiscovery, and HIPAA and HITRUST control mapping Enterprise Applications: SSO and SCIM across the portfolio, plus the standard that no app touching PHI runs on standalone credentials Defender: endpoint detection and response on every managed device, Defender for Office 365 anti-phishing and threat investigation, and the unified alert view across the M365 estate. Defender for Servers, Defender for Cloud, and Defender for Identity — the workload security surface — sit with infrastructure. Vulnerability response: CVE triage from SecOps, remediation tracking, weekly report The application portfolio: an accurate catalog, runbooks that work, and the vendors in your domain held to their SLAs and their BAAs Where the lines are: Your world is Microsoft 365 and the people who use it: identity for humans, endpoints, collaboration, and governance of the data your users create. Azure cloud infrastructure, the applications running in it, and workload identity sit with our infrastructure side. Entra ID is shared, since it’s identity for both halves, and we split it by what the identity represents — people are yours, machines are theirs. The same split carries into Defender: endpoint and email protection are yours, workload protection on Servers, Cloud, and Identity is theirs. This job has depth, autonomy and a lot of engineering in it, but the depth runs toward M365 and not toward Azure. If you’d rather be building infrastructure, we’d both prefer to find out now. How we work, and where we’re going: Today this tenant is managed largely by clicking in admin centers. That’s what we’re hiring you to change. We’re building toward version-controlled, API-driven management in an Azure DevOps repo, with Graph and PowerShell as the primary instruments, app-only auth and Key Vault instead of interactive logins, and Python or declarative tooling where they earn their place. We have no illusions about how far that goes, since parts of the M365 surface have solid config-as-code coverage today and parts don’t. What we’re after is that opening a portal becomes a deliberate exception. We’re not asking for prior GitOps-on-M365 experience. That market barely exists and the tooling is mid-shift. We’re asking for the instinct and the judgment; the specific tooling we’ll work out together. We use AI heavily across engineering, administration and documentation, and we expect fluency with it, including a clear sense of what has to be reviewed before it touches a tenant holding PHI. About WellStreet Urgent Care WellStreet Urgent Care is committed to providing the highest quality patient and customer care. Our technology team plays an important role in supporting the people, systems, and operations that allow our urgent care centers to deliver exceptional service to our patients and communities. In addition to the above requirements, WellStreet is looking for team members with the following qualities: A positive attitude toward patients, families, and coworkers. Willingness to go the extra mile to create an outstanding experience for customers and to train and lead the center team to do the same. A desire to work in concert with others in an upbeat and supportive atmosphere while reinforcing the WellStreet mission to provide uncompromising service. A compelling desire to serve others, improve your community's health, and have fun every day.

Requirements

  • Five or more years in M365, identity, or security engineering.
  • Tenant-level depth in Entra ID and Intune.
  • Real Purview configuration experience: writing DLP policies, labeling, retention, eDiscovery.
  • Microsoft Graph and PowerShell fluency; automation by default and experience building against the API.
  • Proficiency with version control (Git), with branches and pull requests as normal practice.
  • Experience working within a regulated framework (HIPAA, HITRUST, SOC 2, or PCI) and ability to explain controls.
  • Daily use of AI with a clear understanding of where to trust and verify.
  • A positive attitude toward patients, families, and coworkers.
  • Willingness to go the extra mile to create an outstanding experience for customers and to train and lead the center team.
  • A desire to work in concert with others in an upbeat and supportive atmosphere.
  • A compelling desire to serve others, improve your community's health, and have fun every day.

Nice To Haves

  • Python experience.
  • Terraform, Bicep, or Azure DevOps pipelines experience.
  • Exposure to declarative M365 management (Microsoft365DSC, Terraform M365 provider, Graph Tenant Configuration Management APIs).
  • Healthcare IT experience.
  • Experience owning a vulnerability or patch compliance program.
  • Experience with FreshService or a comparable ITSM.
  • ITIL v4 certification.
  • SC-200, SC-300, SC-400, MS-102, MD-102 certifications.

Responsibilities

  • Design the sensitivity label taxonomy and DLP policies across Exchange, SharePoint, and Teams.
  • Implement and manage Single Sign-On (SSO) and SCIM for clinical vendors, including monitoring deprovisioning processes.
  • Automate quarterly access reviews for privileged groups using Microsoft Graph scripts.
  • Triage and manage critical CVEs from SecOps, owning the remediation process.
  • Transition Intune configurations from admin centers to a version-controlled repository.
  • Own the Microsoft 365 platform, including Entra ID, Intune, Exchange Online, Teams, SharePoint, Purview, Defender for Office 365, and vulnerability response.
  • Ensure enterprise applications have SSO and SCIM, and that no app touching PHI runs on standalone credentials.
  • Maintain an accurate catalog of applications and ensure vendors adhere to SLAs and BAAs.
  • Build toward version-controlled, API-driven management using Azure DevOps, Graph, and PowerShell.
  • Implement app-only authentication and Key Vault for secure access.
  • Utilize AI heavily in engineering, administration, and documentation, with careful review before applying to tenants with PHI.

Benefits

  • Real platform ownership with the mandate and backing to build an engineering practice.
  • Opportunity to set standards as the first dedicated hire for this function.
  • Potential to become the lead as the team grows.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service