Skip to main content
Posted August 20, 2026

Infrastructure Engineer, M365 & Identity

PwrQ Holdings LLC
Waco, Minnesota, United States 76707 Full Time
Reference: 286600974

Description:

Position Summary:

 We are seeking a Infra Engineer III, M365 & Identity to own Forgent's Microsoft identity and productivity  platform across all sites. This role is the single point of accountability for Entra ID, Conditional Access, Privileged  Identity Management, and the full suite of Microsoft 365 security and compliance capabilities unlocked by our  E5 licensing.    


You will be joining at a pivotal moment — Forgent is migrating from a fragmented multi-entity Microsoft 365  environment to a single governed platform with a July 1 go-live deadline. This role will be critical to ensuring  that deadline is met, and that identity and access are properly governed across the entire organization from day one.  


Key Responsibilities:

Identity & Access Governance

  • Own and operate Entra ID (Azure Active Directory) across all Forgent entities — users, groups, roles, and licensing 
  • Design and enforce Conditional Access policies aligned to Zero Trust principles — risk-based access, phishing-resistant authentication, and named location controls
  • Implement and manage Privileged Identity Management — just-in-time role activation, access reviews, and least-privilege enforcement for all admin roles 
  • Manage Self-Service Password Reset with password writeback in the hybrid Active Directory and Entra ID environment
  • Own Entra Connect and hybrid identity sync health — ensure clean, reliable synchronization between on-premises Active Directory and Entra ID
  • Lead Entra ID Governance — access reviews, entitlement management, and lifecycle workflows across all entities    

Security & Threat Protection 

  • Deploy and manage Defender for Identity — sensor deployment on all domain controllers, alert triage, and integration with Defender XDR for unified identity threat detection
  • Configure and maintain Microsoft Purview Data Loss Prevention policies — protect sensitive data across Exchange Online, SharePoint, Teams, and endpoints 
  • Manage Intune compliance and configuration policies — enforce device compliance requirements for Conditional Access integration
  • Serve as the identity subject matter expert for security incidents involving compromised accounts, privilege escalation, or unauthorized access    

Single Sign-On & Application Integration 

  • Own and operate enterprise Single Sign-On across all corporate applications using Entra ID as the identity provider 
  • Configure and manage SSO integrations — SAML 2.0, OAuth 2.0, and OpenID Connect — for all business-critical applications across all entities
  • Onboard new applications to the Entra ID application gallery and enterprise app catalog, ensuring consistent authentication and access policies
  • Implement and manage application-level Conditional Access policies — enforce multi-factor authentication, device compliance, and risk-based controls per application
  • Manage application provisioning and de-provisioning using SCIM where supported, ensuring users are automatically granted and revoked access based on role
  • Maintain an authoritative inventory of all SSO-integrated applications, their owners, and their access policies
  • Serve as the escalation point for authentication failures, SSO configuration issues, and application access problems across the organization    

Microsoft 365 Administration 

  • Own M365 licensing administration — seat allocation, license assignment automation, and renewal planning across all entities 
  • Manage the M365 Admin Center, including service health monitoring, tenant configuration, and policy enforcement
  • Support the broader Microsoft 365 E5 feature rollout — coordinate with the Messaging & Collaboration Engineer on Teams, Exchange Online, and OneDrive configurations that depend on identity policies
  • Maintain and document tenant configuration standards, Conditional Access runbooks, and identity governance procedures   

Qualifications:

 Required

  • 7–10 years of experience in Microsoft identity and enterprise Microsoft 365 engineering
  • Deep hands-on expertise with Entra ID — user and group management, Conditional Access, hybrid identity, and B2B collaboration
  • Proven experience implementing and operating Privileged Identity Management in a production enterprise environment
  • Strong understanding of hybrid identity — Entra Connect, password hash sync, pass-through authentication, and Active Directory Federation Services
  • Experience with Microsoft Purview, including Data Loss Prevention policy design and compliance reporting
  • Hands-on experience with Defender for Identity sensor deployment and alert management
  • Solid understanding of Intune device compliance and its integration with Conditional Access
  • Strong documentation skills — ability to produce runbooks, policy guides, and change management documentation
  • Hands-on experience configuring enterprise Single Sign-On integrations using SAML 2.0, OAuth 2.0, and OpenID Connect
  • Experience managing application provisioning and de-provisioning via SCIM    

Preferred

  • Experience with Entra ID Governance — access reviews, entitlement management, and lifecycle workflows
  • Familiarity with Microsoft Sentinel for identity-related log ingestion and alerting
  • Experience supporting a Microsoft 365 E5 deployment or licensing transition
  • Knowledge of multi-entity or post-acquisition Microsoft 365 consolidation
  • Microsoft certifications — SC-300 (Identity and Access Administrator), MS-102 (Microsoft 365 Administrator) 

Core Competencies & Behaviors: 

  • Own identity and access governance for an entire NYSE-listed enterprise from day one — this is a greenfield opportunity, not a maintenance role
  • Work on a high-visibility Microsoft 365 E5 platform launch with a clear roadmap and leadership support
  • Operate at the intersection of identity, security, and compliance — a role that matters to every person in the company
  • Collaborative team environment with a Sr. Manager who came from an enterprise Microsoft background
  • Competitive compensation, benefits, and the ability to shape how identity is done across a growing multi-site organization  

 Working Conditions:

The typical work environment is a standard office setting. Frequently required to sit for extended periods of time at computer.    


Disclaimer: 

The statements above are intended to describe the general nature and level of work being performed. They are  not an exhaustive list of all responsibilities, duties, or skills required. Forgent Power reserves the right to modify, interpret, or apply this job description as needed.  Click or tap here to enter text.  


Equal Employment Opportunity Statement:

Forgent Power is an equal opportunity employer. We are committed to creating an inclusive environment for all employees. Employment decisions are made without regard to race, color, religion, sex, national origin, age,  disability, veteran status, or any other protected class. 

Requirements:






Equal employment opportunity, including veterans and individuals with disabilities.

PI286600974

Sign up for Job Alerts