Microsoft 365 Security & Governance Consultant
This a Full Remote job, the offer is available from: New York (USA)
Microsoft 365 Security & Governance Consultant
Company: SMX Services & Consulting, Inc.
Position: Microsoft 365 Security & Governance Consultant
Engagement: Government Professional Services
Work Location: Remote
Customer: Suffolk County Government, New York
Compensation: $88–$92 per hour, based on qualifications and experience
Anticipated Period of Performance: Award/PO approval through May 20, 2027, or completion of the project
Position Type: Consultant / Project-Based
Position Overview
SMX Services & Consulting, Inc. is seeking an experienced Microsoft 365 Security & Governance Consultant to support a Suffolk County Government Microsoft 365 security and governance initiative.
The consultant will serve as an independent technical advisor responsible for evaluating the security and governance posture of the County's Microsoft 365 environment, identifying security and configuration gaps, assessing identity and access controls, reviewing Active Directory trust relationships, and developing prioritized recommendations aligned with the County's migration and security objectives.
This is a remote professional-services engagement requiring a consultant who can independently assess complex Microsoft environments and communicate actionable security recommendations to both technical stakeholders and executive leadership.
Key Responsibilities
The consultant will support Microsoft 365 security and governance assessment activities, including:
Microsoft 365 Tenant Security & Configuration
-
Review tenant-wide Microsoft 365 security and governance configurations.
-
Evaluate global settings, security baselines, administrative roles, and related security controls.
-
Identify configuration weaknesses, security gaps, and opportunities to strengthen the environment.
-
Develop practical recommendations to improve the County's Microsoft 365 security posture.
Identity & Access Management
-
Assess Microsoft Entra ID identity and access configurations.
-
Review privileged and administrative roles.
-
Evaluate Multi-Factor Authentication controls.
-
Assess Conditional Access policies and configurations.
-
Review Role-Based Access Control and privilege assignments.
-
Identify excessive privileges and opportunities to strengthen least-privilege access.
Microsoft 365 Workload Security
Assess security and governance configurations associated with:
-
Microsoft Entra ID
-
Microsoft Exchange Online
-
Microsoft Teams
-
Microsoft SharePoint Online
-
Microsoft OneDrive
The consultant will identify configuration risks and provide recommendations for improving security across these Microsoft 365 services.
Auditing, Logging & Monitoring
-
Assess Microsoft 365 auditing and logging capabilities.
-
Review relevant audit logs and monitoring configurations.
-
Evaluate mailbox auditing.
-
Review Teams and SharePoint activity visibility.
-
Identify gaps affecting security monitoring, investigation, and governance.
Compliance & Information Governance
Evaluate applicable Microsoft 365 security and compliance capabilities, including:
-
eDiscovery
-
Data retention
-
Data Loss Prevention (DLP)
-
Security and compliance alerting
-
Information governance controls
Provide recommendations for improving the effective use and configuration of these capabilities.
Active Directory Trust Relationship Assessment
Analyze Active Directory forest trust relationships involving Suffolk County and associated environments, including the District Attorney and Police Department environments.
Responsibilities include:
-
Reviewing relevant forest trust relationships.
-
Identifying potential security exposure created through trust configurations.
-
Evaluating potential lateral-access risks.
-
Identifying opportunities to restrict or segment access.
-
Recommending improvements that strengthen identity and directory security.
Security Gap Analysis & Remediation Roadmap
-
Document identified security and governance gaps.
-
Assess the potential impact and priority of findings.
-
Organize recommendations into immediate, medium-term, and longer-term actions.
-
Identify issues that should be addressed before or in alignment with Microsoft 365 migration activities.
-
Develop an actionable remediation roadmap for Suffolk County.
Knowledge Transfer & Executive Communication
-
Clearly explain technical findings to County stakeholders.
-
Conduct interactive knowledge-transfer activities.
-
Present security risks and recommendations in a manner understandable to both technical personnel and leadership.
-
Support County leadership and security stakeholders in understanding remediation priorities and recommended next steps.
Desired Technical Experience
Strong hands-on knowledge in several of the following areas is highly desirable:
-
Microsoft 365 security architecture
-
Microsoft Entra ID
-
Identity and Access Management
-
Conditional Access
-
Multi-Factor Authentication
-
Privileged access and administrative role management
-
Role-Based Access Control
-
Exchange Online security
-
Microsoft Teams security and governance
-
SharePoint Online security and governance
-
OneDrive security and governance
-
Microsoft Purview or related Microsoft 365 compliance capabilities
-
eDiscovery
-
Data Loss Prevention
-
Retention and information governance
-
Microsoft 365 auditing and security monitoring
-
Active Directory
-
Active Directory forest trusts
-
Security gap assessments
-
Cybersecurity risk analysis
-
Security remediation planning
Ideal Candidate Profile
The successful candidate should be capable of working independently as the primary consultant for the engagement and should be comfortable moving between hands-on technical assessment, cybersecurity analysis, governance recommendations, and executive-level communication.
The ideal candidate will be able to evaluate an existing Microsoft environment objectively, distinguish critical security issues from longer-term improvements, and convert technical findings into a practical remediation roadmap.
Experience performing Microsoft 365 security assessments, tenant reviews, identity-security assessments, Active Directory security reviews, or Microsoft cloud governance engagements is particularly relevant.
Deliverable-Oriented Skills
Candidates should be comfortable producing professional technical and executive-facing materials that may include:
-
Security assessment findings
-
Configuration gap analysis
-
Risk-prioritized recommendations
-
Microsoft 365 security and governance observations
-
Identity and access findings
-
Active Directory trust findings
-
Remediation recommendations
-
Prioritized remediation roadmap
-
Knowledge-transfer and executive briefing materials
Security & Administrative Requirements
The selected candidate must:
-
Be willing and able to work remotely.
-
Provide evidence of a recent background check or agree to a background check performed by Suffolk County Government.
-
Agree to execute a Suffolk County Government-issued Non-Disclosure Agreement (NDA).
-
Protect County information and system-access information obtained during the engagement.
Security Clearance: No Secret or Top Secret security clearance requirement is stated for this engagement.
Hardware / Software / Licensing
This is a professional-services consulting engagement. The current requirement does not specify contractor-provided hardware or third-party software licenses.
The consultant will assess Microsoft 365 security and governance capabilities within the County's environment. Any access to County systems and Microsoft services will be subject to County authorization and applicable security requirements.
Work Arrangement
Remote: Yes. The solicitation permits all work to be performed remotely.
The consultant must nevertheless be available to coordinate with Suffolk County technical personnel, security stakeholders, and leadership as required throughout the engagement.
Compensation
Target pay range: $88–$92 per hour
Final compensation will be based on relevant Microsoft 365 security, identity, governance, Active Directory, assessment, and consulting experience.
About SMX Services & Consulting, Inc.
SMX Services & Consulting, Inc. provides information technology consulting, professional services, staffing, cybersecurity, cloud, systems engineering, and related technology services to government and commercial organizations.
SMX Services & Consulting, Inc. is an equal opportunity employer. Employment and engagement decisions are made in accordance with applicable law.
How to Apply
Qualified candidates should submit a current resume highlighting relevant experience with Microsoft 365 security and governance, Microsoft Entra ID, identity and access management, Microsoft cloud security, Active Directory security, compliance/governance, and security assessment engagements.
Please clearly identify hands-on Microsoft 365 security assessment and Active Directory trust/security experience in your resume.
This offer from "SMX Services & Consulting, Inc." has been enriched by Jobgether.com and got a 74% flex score.