Sr Engineer M365 Platform
Plano, TX, US, 75024
Are you looking to Optimize your life? Start your exciting path to a rewarding career today!
We are Optimum, a leader in the fast-paced world of connectivity, and we're seeking driven and enthusiastic professionals to join our team, empower lives, fuel businesses, and drive innovation. Connectivity is now longer a luxury, but a necessity. A career at Optimum means you'll be enabling progress and enhancing lives by providing reliable, high-speed connectivity solutions that keep the world connected. Our successes, now and in the future, are powered by our amazing product, a commitment to our people and culture, and the connections we make in our communities.
If you are resourceful, collaborative, and passionate about delivering consistent excellence, Optimum is for you!
Job Summary
Senior Engineer – M365 Platform – Entra and Active Directory SME provides engineering, design, and implementation services for the enterprise hybrid identity estate spanning Microsoft Entra ID and Active Directory and is the subject matter expert for Entra as the organization moves to a cloud-first, Entra-authoritative operating model. This position owns identity-plane engineering across both directories during migration and de-hybridization: greenfield forest and tenant integration, directory synchronization topology, modern authentication, Conditional Access, privileged access, and the retirement of legacy on-premises identity dependencies. Acts as the senior escalation point for identity issues, completing assigned change requests and converting recurring problems into permanent engineering fixes. Applies new solutions through research and collaboration with the team, and determines the course of action for new application initiatives. Implements and documents new solutions as required by the business to improve the end user operating experience. The core infrastructure technology duties include enterprise Entra ID and Active Directory, modern authentication (OAuth 2.0, OIDC, SAML, WS-Federation), Conditional Access and phishing-resistant multifactor authentication, privileged access (Entra PIM, Tier 0 / Enterprise Access Model), Business-2-Business collaboration with external partners, application and workload identity onboarding, and license optimization. Expert knowledge is required across the following areas: Entra ID (Azure AD); Conditional Access Policies (CAPs); Entra Connect and Entra Cloud Sync; Active Directory (AD); Group Policy Objects (GPO); Entra Single Sign-On (SSO); Certificate Authorities (CA) and Public Key Infrastructure (PKI); Dynamic Host Configuration Protocol (DHCP); Domain Name System (DNS); Distributed File System (DFS); and Windows Server 2016, 2019, 2022, and 2025.
Environment and Scope: the estate supports approximately 20,000 users across four on-premises Active Directory domains, with a primary production tenant and a separate development tenant. Active work consists of a greenfield domain build, migration off the four legacy domains, and a full cleanup and re-architecture of the Entra tenants. The required skill set is deliberately broad and covers the full directory, authentication, and platform range rather than a single specialty. This is a build role rather than a maintenance role, and it carries the opportunity to fully own and remake the environment for the engineer who can operate at that level.
Responsibilities
• Own the design, engineering, and implementation of the enterprise identity plane across Entra ID and Active Directory, and serve as the organization's final internal technical authority on Entra.
• Plan and execute the move to a cloud-first, Entra-authoritative model: greenfield forest and tenant standup, coexistence design, wave-based user and workload cutover, and staged de-hybridization of on-premises identity dependencies.
• Design, pilot, and enforce Conditional Access and phishing-resistant authentication at enterprise scale, using report-only staging and What-If validation ahead of enforcement, and retire legacy authentication paths.
• Engineer privileged access to eliminate standing administrative privilege, implementing PIM, the Enterprise Access Model, and least-privilege role and administrative unit scoping.
• Onboard applications and workload identities to modern authentication and SSO, right-size application permissions, and remove long-lived credentials and legacy protocol dependencies.
• Build and maintain identity automation in PowerShell and Microsoft Graph under version control with peer review, replacing manual administrative processes.
• Track the Microsoft identity roadmap, Message Center announcements, and product deprecation timelines, and convert them into remediation plans and change requests ahead of Microsoft-forced deadlines.
• Produce design documentation, security and architecture review artifacts, and runbooks, and transition completed builds to Operations with the documentation and enablement required to run them.
• Serve as the senior escalation point for identity incidents, performing root cause analysis and delivering permanent engineering remediation rather than repeat manual intervention.
• Maintain identity resilience: Active Directory forest recovery planning, Entra tenant configuration backup and restore, break-glass account lifecycle, and periodic recovery testing.
• Partner with Security, Endpoint, Network, Identity Governance, and application teams on identity-dependent initiatives, and manage Microsoft and external advisory engagements without ceding internal design ownership.
• Mentor engineers and administrators on Entra and Active Directory practice, raising team capability through knowledge transfer and design review.
Qualifications
• Must have a minimum of 4 years of hands-on engineering experience with Entra ID at enterprise scale, within a minimum of 5 years of total Microsoft identity and directory platform experience that includes production Active Directory engineering.
• Attribute and object level knowledge of Active Directory, including schema, ACLs, SID history, and delegation models.
• Strong working knowledge of log analysis through KQL across Entra sign-in, audit, and provisioning logs.
• Extensive experience in design and troubleshooting of enterprise domains and tenants, including authentication, site layout, PKI and certificates, migration, consolidation, tenant-to-tenant and forest-to-forest consolidation, automation of access and access removal to various applications and/or authorities.
• Experience planning and executing migration from on-premises Active Directory to a cloud-native Entra ID model, including greenfield forest and tenant standup, coexistence, wave-based cutover, and de-hybridization of legacy identity dependencies.
• Working knowledge of directory synchronization design and operation - Entra Connect Sync, Entra Cloud Sync, staging mode, synchronization rules, filtering, source-of-authority transitions, and Entra Connect Health.
• Working knowledge of hybrid and cloud join models, including Entra hybrid join, Entra join, and cloud-native Windows provisioning with Autopilot and Intune, in coordination with Endpoint Engineering.
• Ability to analyze deployment articles and GitHub repositories to understand and implement identified configurations.
• Develop automation routines to replace manual processes and increase efficiency, using PowerShell and Microsoft Graph.
• Demonstrated knowledge of authentication, security, privacy, and compliance and how they factor into cloud and hybrid solutions.
• Strong working knowledge of network architecture and standards for large enterprise deployments and understanding of security and regulatory frameworks relevant to IT standards (PCI DSS, SOX, and CPNI).
• Interface with support, operations, and end users as needed to diagnose escalated problems and to validate engineering changes in production.
• Backup and Disaster Recovery experience, including Active Directory forest recovery and Entra ID tenant-level configuration backup and restore.
• Escalate problems to management and/or vendors in a timely fashion.
• Develop techniques and implement resolution of problems based on root cause analysis.
• Follow established Change Control procedures to document all production changes, and to limit unexpected interruptions to the production environment.
• Ability to prepare design documentation for security architecture and technical architecture review, and to work alongside external architecture-advisory partners without ceding internal design ownership.
• Degree in Computer Science or equivalent work experience.
• Experience in architecture and design of enterprise IT infrastructure.
At Optimum, every action and interaction we take part in, is driven by our three Guiding Principles: Do What’s Right, Drive One Optimum, and Make It Happen. These aren’t just words, they help us build trust, create real community, and embrace new ways of thinking. Our employees are empowered to do the right thing for our customers and co-workers and to recognize and reward these behaviors when we see them. It’s all part of the bigger picture of “Be The Difference” where each employee knows they have the power to enact real change, share new ideas, and understand that learning never stops.
If you have the drive to succeed and are ready to embark on a thrilling career, seize this opportunity today, and join our winning team. Together, we'll shape the future of connectivity.
All job descriptions and required skills, qualifications and responsibilities for a particular position are subject to modification by the Company from time to time, in the Company’s discretion based on business necessity.
We are an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, national origin, religion, age, disability, sex, sexual orientation, gender identity or protected veteran status, or any other basis protected by applicable federal, state, or local law. The Company provides reasonable accommodations upon request in accordance with applicable requirements.
Optimum collects personal information about its applicants for employment that may include personal identifiers, professional or employment related information, photos, education information and/or protected classifications under federal and state law. This information is collected for employment purposes, including identification, work authorization, FCRA-compliant background screening, human resource administration and compliance with federal, state, and local law.
Applicants for employment with the Company will never be asked to provide money (even if reimbursable) as part of the job application or hiring process. Please review our Fraud FAQ for further details.
Nearest Major Market: Plano
Nearest Secondary Market: Dallas