About the job
Join our dynamic team at Keylane as a Microsoft 365 Security and Compliance Engineer. We are on the lookout for a skilled expert proficient in Microsoft Defender, Microsoft Purview, and the Microsoft 365 Admin Center. In this pivotal role, you will be responsible for designing, implementing, and enhancing security and compliance frameworks within Microsoft 365, ensuring that risk and regulatory obligations are effectively translated into enforceable technical measures. Ideal candidates will exhibit strong analytical abilities, meticulous execution, and the capacity to serve as a technical authority while providing practical advice to IT and security stakeholders.
Key Responsibilities
Admin Center Management
- Take ownership of Microsoft 365 tenant administration through the Microsoft 365 Admin Center, managing core workloads including Exchange, SharePoint, OneDrive, Teams, and associated admin portals.
- Oversee user and group lifecycle operations, establish licensing strategies, monitor service health, and manage incident communications.
- Define and uphold tenant-wide configuration standards, governance frameworks, and administrative procedures.
- Manage administrative roles and access models with a focus on least privilege principles, conducting role assignment reviews and implementing privileged access controls as needed.
- Lead service readiness and change management processes, including feature releases, Message Center evaluations, impact assessments, stakeholder communications, and rollout strategies.
- Diagnose Microsoft 365 service complications utilizing service health telemetry, audit logs, and diagnostic tools; engage with Microsoft support teams as necessary.
- Create detailed documentation including tenant configuration baselines, runbooks, operational playbooks, and escalation procedures.
Security Engineering & Operations
- Architect, deploy, and enhance Microsoft Defender solutions, focusing on policy and control baselining.
- Implement and fine-tune Defender security controls encompassing endpoint protection, identity protection, email, collaboration security, and cloud application security monitoring.
- Develop detection and response use cases, triage workflows, alert tuning, and incident response playbooks.
- Perform root-cause analyses of security incidents and lead remediation and hardening initiatives.
- Integrate Defender telemetry with SIEM/SOAR platforms (e.g., Microsoft Sentinel) and standardize operational reporting metrics (KPIs/KRIs).
Compliance and Governance
- Design and deploy information protection and compliance capabilities such as sensitivity labeling, encryption, DLP, and retention policies.
- Implement data governance and lifecycle management strategies that align with business and legal requirements.
- Establish and maintain compliance policies for Microsoft 365 workloads including Exchange, SharePoint, OneDrive, and Teams.
- Support eDiscovery, audits, and investigations ensuring compliance with regulatory standards.
