About the role
The Security Engineer leads our security hardening engagements — the service line focused on closing the configuration gaps that make SMB cloud environments vulnerable. This means identity protection, email authentication, device management, and conditional access policy design, executed in live client environments with full documentation produced on delivery.
You understand how attacks actually work in the M365 and Google Workspace context — credential phishing, MFA bypass, email spoofing, BEC — and you know how to configure environments to resist them. You also understand that security controls that users can't work around are controls that will get disabled. You design accordingly.
This is a consulting role. You'll explain what you're doing and why to clients who are not security professionals. Strong written and verbal communication is as important as technical depth.
What you'll do
- Conduct security assessments of Microsoft 365 and Google Workspace environments and produce written findings reports with prioritized recommendations
- Implement and validate DMARC, DKIM, and SPF configurations and move clients from p=none to p=reject
- Design and deploy Conditional Access policies including MFA enforcement, device compliance requirements, and sign-in risk policies
- Configure Microsoft Intune or Google Endpoint Management device enrollment and compliance policies
- Enable and configure audit logging, alert policies, and sign-in risk monitoring
- Produce security configuration documentation delivered to client at engagement close
What we're looking for
Required
- 3+ years of hands-on security configuration experience in Microsoft 365 or Google Workspace environments
- Deep working knowledge of DMARC/DKIM/SPF — not just conceptual, but implementation and troubleshooting
- Familiarity with CIS Controls, CISA M365 security baseline, or equivalent frameworks
- Ability to explain security decisions clearly to non-technical business stakeholders
Nice to have
- SC-300, SC-200, or AZ-500 Microsoft certification
- Security+, CISSP, or similar vendor-neutral certification
- Prior experience in a consulting or managed services environment