On-site, Washington, DC
Contract
Engineering
XCell was born out of a passion for using the power of design to transform organizations in ways that build up our communities. We work in small, fast-paced agile teams that use Design Thinking to help Government, Non-Profit and Educational organizations solve complex challenges. We value our team and culture — finding the right fit takes time, and we believe in hiring slow.
Citizenship & Eligibility
- U.S. citizenship is required.
- Must be U.S.-based and able to work on-site in Washington, DC.
- Must be able to pass a federal background investigation and suitability determination for access to the customer’s systems and facilities.
What it looks like
We are looking for a Senior Microsoft Cloud Engineer to run and secure an enterprise Microsoft 365, Azure, and Microsoft Security environment for a federal customer in Washington, DC. You will operate, harden, and advance the tenant, lead on identity and Zero Trust, and keep the environment secure, resilient, and audit-ready. This is a senior, hands-on role for someone who can operate independently and advise stakeholders. Candidates must be U.S. citizens, U.S.-based, and able to work on-site in DC.
In this role you will:
- Identity and access: administer Microsoft Entra ID, Conditional Access, privileged access, and least-privilege models; manage MFA including provider transitions, third-party MFA, and Smart Card and FIDO2 authentication.
- Endpoints at scale: manage Windows, macOS, and iOS devices through Microsoft Intune and Autopilot across 700+ endpoints, including compliance and policy delivery.
- Security operations: run Microsoft Defender, Sentinel, and Purview; manage Sentinel data sources and monitor ingestion and log-quality health; support incident response readiness.
- Collaboration and Azure: support Exchange Online, Microsoft Teams, and SharePoint Online, and provide Azure infrastructure, networking, and hybrid integration.
- Automation: build and lock down PowerShell and Microsoft Graph automation across the relevant APIs.
- Reporting and cost: build Power BI dashboards for systems health, compliance, spend and forecast, and utilization; configure Azure budgets with early overage alerting.
- Compliance and continuity: align configurations to NIST SP 800-53, NIST SP 800-207 Zero Trust, and FedRAMP Moderate; keep the tenant audit-ready and support incident and disaster recovery.
- Change and advisory: work through formal change management, maintain documentation, SOPs, and runbooks, and serve as a senior technical advisor to the team.
What we are looking for
- Current Microsoft certifications (hard requirement): you must currently hold, and have maintained for about five years, the following active certifications. Expired certifications, or certifications never used professionally, will not qualify.
- Microsoft 365 Certified: Administrator Expert
- Microsoft Certified: Cybersecurity Architect Expert
- Microsoft Certified: Azure Solutions Architect Expert
- Microsoft 365 Certified: Endpoint Administrator Associate
- Microsoft Certified: Identity and Access Administrator Associate
- Microsoft Certified: Windows Server Hybrid Administrator Associate
- Microsoft 365 Certified: Teams Administrator Associate
- Microsoft Certified: Information Security Administrator Associate
- Senior, independent operator: able to run an enterprise Microsoft cloud environment with minimal supervision and sound technical judgment.
- Deep hands-on experience: across Entra, Intune and Autopilot, Defender, Sentinel, Purview, Exchange Online, and Azure.
- Strong communication: able to advise stakeholders and collaborate across network, cybersecurity, and cloud teams.
Nice-to-have
- Experience in a federal or highly regulated environment.
- Hybrid Active Directory, M365, and Entra tiered-security experience.
- Experience preparing for audits, assessments, and compliance reviews.
- Two to four short technical writing samples you personally authored (documentation, design docs, PowerShell, SOPs).
Qualifications / Experience
- Proven senior-level experience operating enterprise Microsoft 365, Azure, and Microsoft Security platforms.
- All eight Microsoft certifications listed above, currently active and maintained roughly five years.
- Experience implementing Zero Trust, least privilege, and Conditional Access at enterprise scale.
- Strong documentation, change-management, and stakeholder-communication skills.
What we care about
- You, the person. Bring your whole, authentic self, not a version you think we want to see.
- Your passions, professional and personal, even if they have nothing to do with the job.
- Your honest thoughts on technology, teamwork, and how you approach problems.
Location & On-site Requirement
- On-site in Washington, DC. This is not a remote role.
- Applicants must be U.S. citizens, U.S.-based, and able to work on-site in DC.
- Applicants must live in, or be willing to relocate to, the DC metro area.
Work Authorization
We participate in E-Verify. Upon hire, we provide the federal government with your Form I-9 information to confirm you are authorized to work in the U.S. XCell is a federal contractor, and all positions require work to be performed within the United States.
Benefits
Ready to Join XCell?
Submit your application for Senior Microsoft Cloud Operations Engineer below.