M365 Platform and Security Engineer
We are an award-winning California-based environmental consulting firm with 550+ professionals and more than 30 years of diverse experience serving clients in transportation, energy, water, infrastructure, private development, and government sectors. Our mission is to deliver practical, science-based environmental and planning solutions that support communities, infrastructure, and natural systems
As a people-centric organization, we value collaboration, fairness, and transparency, and are committed to fostering a workplace that supports both personal and professional growth while offering robust career opportunities. We are especially proud of our recent Great Place To Work® certification, which reflects an independent assessment of our culture and our team member experiences.
About The Role
Rincon Consultants, Inc. is seeking a Microsoft 365 Platform and Security Engineer to own and operate the Microsoft 365 E5 control plane. This role is responsible for administering identity, endpoint, collaboration, and data protection platforms; establishing enforceable governance standards; and enabling AI capabilities securely and responsibly.
This position plays a critical role in reducing organizational risk, standardizing Microsoft tenant configuration, improving operational maturity, and decreasing reliance on managed service providers for core Microsoft platform administration.
How We Collaborate
This role may offer a hybrid work setup, blending time in the office with remote work as business needs evolve. We enjoy coming together in person to collaborate, connect with teammates, and partner with clients. We may prioritize candidates who live within 50 miles of a Rincon office. Eligible office locations for this role include Carlsbad, Fresno, Los Angeles, Monterey, Oakland, Palm Springs, Riverside, Sacramento, San Luis Obispo, San Diego, San Jose, Santa Barbara, and Ventura. This position is also open to candidates outside of California
What You’ll Do
Microsoft Platform Administration
- Administer and maintain Microsoft Entra ID, Intune, Microsoft Defender, Microsoft Purview, SharePoint, Teams, and related Microsoft 365 services.
- Own baseline Microsoft Fabric control plane configuration and coordination in partnership with data and enablement teams.
- Ensure consistent, secure configuration across Microsoft E5 services.
- Manage tenant configuration, platform changes, testing, and documentation to support operational stability and scalability.
Security & Governance
- Design, implement, and enforce identity, device, access, collaboration, and data protection controls.
- Establish governance standards that protect organizational data while minimizing user friction.
- Configure and maintain controls such as Conditional Access, MFA, Privileged Identity Management (PIM), device compliance policies, sensitivity labels, Data Loss Prevention (DLP), retention policies, and sharing boundaries.
- Partner with IT Operations, Security, and Enablement teams to ensure controls are practical, supportable, and adopted.
AI Enablement
- Enable AI safely by implementing appropriate sensitivity labels, Data Loss Prevention (DLP) policies, retention controls, and sharing and access boundaries.
- Assess and remediate oversharing, permissions, and content exposure risks that could affect AI-enabled experiences.
- Ensure AI capabilities operate within approved governance, compliance, and access models.
Platform Standards & Improvement
- Develop tenant-wide standards that reduce support tickets and improve automation and self-service.
- Improve overall Microsoft E5 security posture without introducing excessive operational burden.
- Document platform standards, configurations, runbooks, and support procedures to support consistency and scalability.
- Recommend and implement improvements that strengthen governance, security, usability, and long-term maintainability of the Microsoft environment.
Vendor & MSP Coordination
- Serve as the internal administrator for Microsoft tenant configuration in collaboration with MSP partners.
- Coordinate with MSPs and specialty vendors for overflow or specialized platform work as needed.
- Reduce long-term dependency on external providers for routine tenant administration while maintaining effective escalation paths for advanced or specialized support.
What You’ll Bring
- 5+ years of experience administering Microsoft 365 and related cloud security platforms in an enterprise environment.
- Hands-on experience with Microsoft Entra ID, Intune, Microsoft Defender, Microsoft Purview, SharePoint, and Teams administration.
- Demonstrated experience implementing and managing Conditional Access, MFA, device compliance, DLP, retention, sensitivity labeling, and privileged access controls.
- Experience supporting or administering Microsoft 365 security and compliance capabilities in a regulated or policy-driven environment.
- Strong understanding of Microsoft 365 governance, tenant administration, identity and access management, endpoint management, and collaboration security.
- Ability to document standards, procedures, and technical configurations clearly and consistently.
- Strong problem-solving, organizational, and communication skills.
- Ability to work effectively across technical, operational, and leadership teams.
Nice to Have
- Microsoft certifications such as MS-102, SC-300, SC-400, MD-102, or AZ-500.
- Experience supporting AI readiness, rollout, or governance.
- Experience with Microsoft Fabric administration or coordination.
- Experience working with MSPs, external partners, or outsourced support models.
- Experience in professional services, consulting, or other multi-project business environments.
- Familiarity with compliance and audit support.
Investing in You
The base salary range for this full-time position is 120,000.00 to 140,000.00, plus a generous benefits program. Salary ranges are based on the market median of similar jobs, according to third-party salary benchmark surveys. Base pay is determined based on internal equity and a candidate’s job-related knowledge, skills, and experience.
We offer a comprehensive Total Rewards Package designed to support employee well-being, growth, and financial security. Our benefits are designed to offer flexibility and choice, including health coverage options, employer-sponsored insurance, retirement benefits, generous time off, and programs that support learning, growth, and community engagement.
Explore more about our culture, benefits, and life at Rincon on our Culture and Benefits page.
Additional Employment Information
Individuals offered employment must successfully complete a pre-employment drug screening as a condition of employment. Additionally, those hired who may be assigned to federal projects will be subject to further drug testing, including screening for cannabinoids (THC/marijuana), in compliance with the Drug-Free Workplace Act of 1988 and other applicable federal regulations, which take precedence over California state and local laws.
Rincon Consultants, Inc does not accept unsolicited applicant/candidate resumes from search firm recruiters and/or temporary agencies that do not have a signed contract and specified work order with Rincon Consultants. Further, such resumes received will be deemed the sole property of Rincon Consultants and no fees will be paid in the event Rincon Consultants subsequently hires such individual. Rincon Consultants is an equal opportunity employer. All aspects of employment will be based on merit, competence, performance, and business needs. We do not discriminate on the basis of race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law.