
System Administrator
Procon Consulting
The Role
Overview
Administer & secure Microsoft 365 GCC environment for 200+ staff, focusing on CUI compliance.
Key Responsibilities
- configuration drift
- defender deployment
- powershell automation
- purview dlp
- siem integration
- intune posture
Tasks
-Own periodic configuration drift checks, secure tenant setting reviews, and documented remediation actions for audit trails -Deploy and operate Microsoft Defender for Endpoint and Defender for Office 365 with advanced telemetry, custom detection rules, automated containment playbooks, and integration into the tenant's continuous monitoring and incident response processes. -Manage Autopilot profiles and lifecycle to ensure new company devices meet CUI security baselines before granting access -Build PowerShell/Graph automation to produce recurring compliance reports, control evidence packages, license and entitlement reports, and remediation tickets for noncompliant items. -Configure Microsoft Purview for DLP, sensitivity labeling, encryption, retention, and eDiscovery tailored to CUI handling requirements. -Maintain identity logs and evidence retention to support audits and assessments against NIST SP 800-171 controls. -Configure unified logging, retention, and automated evidence collection for controls mapped to NIST SP 800-171; ensure logs meet retention and integrity requirements for assessments. -Implement strict guest access and external sharing controls for Teams, SharePoint, and OneDrive with exception workflows and approvals. -Vet and configure SSO and data flows for third-party SaaS (e.g. Adobe, Bluebeam, backups) to ensure minimal exposure of CUI and appropriate contractual, technical, and monitoring controls. -Ensure Defender signals feed into a centralized SIEM or Microsoft Sentinel for correlation, retention, and evidence for assessments. -Maintain a formal tenant baseline configuration document, change control process, and Infrastructure-as-Code or scripted templates to reproduce hardened settings. -Enforce device posture for CUI access with Intune: strict enrollment gates, baseline configuration profiles, compliance policy strictness, controlled device enrollment (company-owned only where required), and device encryption enforcement. -Address escalation requests from Helpdesk Analyst and MSSP as needed -Harden identity configuration for CUI: implement strict Conditional Access policies, passwordless MFA, identity protection tuning, Privileged Identity Management (PIM), and emergency break-glass controls. -Produce and maintain artifacts required for audits: control evidence, configuration snapshots, access review records, and incident logs. -Implement and enforce app consent and app registration governance in Entra ID.
Requirements
- microsoft 365
- intune
- powershell
- sentinel
- purview
- m365 cert
What You Bring
-Experience implementing Microsoft Purview (DLP, retention, labels) or equivalent information protection controls -Microsoft certifications such as Microsoft 365 Certified: Endpoint Administrator Associate, Microsoft 365 Certified: Security Administrator, or Microsoft Certified: Identity and Access Administrator. -Familiarity with third-party MDM/MAM and backup solutions (e.g. Duo Federal). -Proficiency with PowerShell, Microsoft Graph, and automation for evidence collection and control enforcement. -Minimum 5-7 years experience administering Microsoft 365 for mid-size organizations. -Experience with Microsoft Sentinel, Intune Suite features, or Microsoft Copilot for Security. -Excellent documentation skills and experience creating runbooks and operational procedures. -Hands-on experience with Microsoft Intune / Endpoint Manager, Windows Autopilot, Microsoft Defender, Entra ID / Azure AD, Exchange Online, Teams, and Microsoft Purview. -Familiarity integrating SaaS apps (SSO/SAML/OAuth), managing app registrations, and configuring SSO. -Experience operating Microsoft Government Cloud tenants (GCC or GCC High) or implementing NIST SP 800-171 controls in Microsoft 365 tenants is highly desired. -Experience in tenant-to-tenant migrations, domain changes, or hybrid identity projects. -Background supporting remote/hybrid workforces and managing non-domain-joined devices. -Active security mindset with experience responding to incidents and remediating threats.
People Also Searched For
Building Engineer jobs in Silver Spring , Maryland , US
Construction Project Coordinator jobs in Silver Spring , Maryland , US
Construction Coordinator jobs in Silver Spring , Maryland , US
Building Engineer jobs in Maryland , US
Construction Project Coordinator jobs in Maryland , US
Construction Coordinator jobs in Maryland , US
Building Engineer jobs in Silver Spring , US
Construction Project Coordinator jobs in Silver Spring , US
Construction Coordinator jobs in Silver Spring , US
The Company
About Procon Consulting
-Specializes in delivering high-quality project management, engineering, and consultancy services. -Operates across multiple sectors including energy, infrastructure, buildings, utilities, and transport. -Known for expertise in handling complex, multidisciplinary projects from concept to completion. -Unique ability to manage both technical and strategic elements sets it apart in the consulting world. -Portfolio includes a wide variety of projects, from large transportation networks to advanced energy infrastructure. -Focused on delivering value through innovation, often leading the way in introducing new methodologies and technologies.
Sector Specialisms
Construction
Space Planning
Technology Management
Business Management
Facilities Management
Program Management
Project Management
Real Estate
