Logo for SMX Services & Consulting, Inc.

Microsoft 365 Security & Governance Consultant

Role overview

Qualifications

  • Strong hands-on knowledge in Microsoft 365 security architecture
  • Experience in identity and access management including Multi-Factor Authentication
  • Familiarity with security and compliance capabilities like eDiscovery and Data Loss Prevention
  • Experience performing security assessments and remediation planning

Responsibilities

  • Evaluate security and governance configurations for Microsoft 365 environment
  • Identify security gaps and configuration weaknesses
  • Develop and communicate actionable security recommendations
  • Conduct knowledge-transfer activities and engage with stakeholders

Key facts

Hard skills

Other skills

  • Communication
  • Problem Solving

About the company

SMX Services & Consulting, Inc. logo

SMX Services & Consulting, Inc.

IT Services & IT Consulting

SMX Services & Consulting is an information technology outsourcing (ITO) provider with more than 20 years’ applied experience providing logical solutions to emerging enterprises, in a variety of industry verticals including technology, finance, banking, real estate, insurance, and retail. Based in Miami, Florida, SMX serves private, public and institutional clients, including some Fortune 500 companies, in more than 10 countries from regional offices in Houston, San Juan, Bogotá, and Caracas.

Company details

IndustryIT Services & IT Consulting
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Microsoft 365 Security & Governance Consultant

Company: SMX Services & Consulting, Inc.
Position: Microsoft 365 Security & Governance Consultant
Engagement: Government Professional Services
Work Location: Remote
Customer: Suffolk County Government, New York
Compensation: $88–$92 per hour, based on qualifications and experience
Anticipated Period of Performance: Award/PO approval through May 20, 2027, or completion of the project
Position Type: Consultant / Project-Based

Position Overview

SMX Services & Consulting, Inc. is seeking an experienced Microsoft 365 Security & Governance Consultant to support a Suffolk County Government Microsoft 365 security and governance initiative.

The consultant will serve as an independent technical advisor responsible for evaluating the security and governance posture of the County's Microsoft 365 environment, identifying security and configuration gaps, assessing identity and access controls, reviewing Active Directory trust relationships, and developing prioritized recommendations aligned with the County's migration and security objectives.

This is a remote professional-services engagement requiring a consultant who can independently assess complex Microsoft environments and communicate actionable security recommendations to both technical stakeholders and executive leadership.

Key Responsibilities

The consultant will support Microsoft 365 security and governance assessment activities, including:

Microsoft 365 Tenant Security & Configuration
  • Review tenant-wide Microsoft 365 security and governance configurations.

  • Evaluate global settings, security baselines, administrative roles, and related security controls.

  • Identify configuration weaknesses, security gaps, and opportunities to strengthen the environment.

  • Develop practical recommendations to improve the County's Microsoft 365 security posture.

Identity & Access Management
  • Assess Microsoft Entra ID identity and access configurations.

  • Review privileged and administrative roles.

  • Evaluate Multi-Factor Authentication controls.

  • Assess Conditional Access policies and configurations.

  • Review Role-Based Access Control and privilege assignments.

  • Identify excessive privileges and opportunities to strengthen least-privilege access.

Microsoft 365 Workload Security

Assess security and governance configurations associated with:

  • Microsoft Entra ID

  • Microsoft Exchange Online

  • Microsoft Teams

  • Microsoft SharePoint Online

  • Microsoft OneDrive

The consultant will identify configuration risks and provide recommendations for improving security across these Microsoft 365 services.

Auditing, Logging & Monitoring
  • Assess Microsoft 365 auditing and logging capabilities.

  • Review relevant audit logs and monitoring configurations.

  • Evaluate mailbox auditing.

  • Review Teams and SharePoint activity visibility.

  • Identify gaps affecting security monitoring, investigation, and governance.

Compliance & Information Governance

Evaluate applicable Microsoft 365 security and compliance capabilities, including:

  • eDiscovery

  • Data retention

  • Data Loss Prevention (DLP)

  • Security and compliance alerting

  • Information governance controls

Provide recommendations for improving the effective use and configuration of these capabilities.

Active Directory Trust Relationship Assessment

Analyze Active Directory forest trust relationships involving Suffolk County and associated environments, including the District Attorney and Police Department environments.

Responsibilities include:

  • Reviewing relevant forest trust relationships.

  • Identifying potential security exposure created through trust configurations.

  • Evaluating potential lateral-access risks.

  • Identifying opportunities to restrict or segment access.

  • Recommending improvements that strengthen identity and directory security.

Security Gap Analysis & Remediation Roadmap
  • Document identified security and governance gaps.

  • Assess the potential impact and priority of findings.

  • Organize recommendations into immediate, medium-term, and longer-term actions.

  • Identify issues that should be addressed before or in alignment with Microsoft 365 migration activities.

  • Develop an actionable remediation roadmap for Suffolk County.

Knowledge Transfer & Executive Communication
  • Clearly explain technical findings to County stakeholders.

  • Conduct interactive knowledge-transfer activities.

  • Present security risks and recommendations in a manner understandable to both technical personnel and leadership.

  • Support County leadership and security stakeholders in understanding remediation priorities and recommended next steps.

Desired Technical Experience

Strong hands-on knowledge in several of the following areas is highly desirable:

  • Microsoft 365 security architecture

  • Microsoft Entra ID

  • Identity and Access Management

  • Conditional Access

  • Multi-Factor Authentication

  • Privileged access and administrative role management

  • Role-Based Access Control

  • Exchange Online security

  • Microsoft Teams security and governance

  • SharePoint Online security and governance

  • OneDrive security and governance

  • Microsoft Purview or related Microsoft 365 compliance capabilities

  • eDiscovery

  • Data Loss Prevention

  • Retention and information governance

  • Microsoft 365 auditing and security monitoring

  • Active Directory

  • Active Directory forest trusts

  • Security gap assessments

  • Cybersecurity risk analysis

  • Security remediation planning

Ideal Candidate Profile

The successful candidate should be capable of working independently as the primary consultant for the engagement and should be comfortable moving between hands-on technical assessment, cybersecurity analysis, governance recommendations, and executive-level communication.

The ideal candidate will be able to evaluate an existing Microsoft environment objectively, distinguish critical security issues from longer-term improvements, and convert technical findings into a practical remediation roadmap.

Experience performing Microsoft 365 security assessments, tenant reviews, identity-security assessments, Active Directory security reviews, or Microsoft cloud governance engagements is particularly relevant.

Deliverable-Oriented Skills

Candidates should be comfortable producing professional technical and executive-facing materials that may include:

  • Security assessment findings

  • Configuration gap analysis

  • Risk-prioritized recommendations

  • Microsoft 365 security and governance observations

  • Identity and access findings

  • Active Directory trust findings

  • Remediation recommendations

  • Prioritized remediation roadmap

  • Knowledge-transfer and executive briefing materials

Security & Administrative Requirements

The selected candidate must:

  • Be willing and able to work remotely.

  • Provide evidence of a recent background check or agree to a background check performed by Suffolk County Government.

  • Agree to execute a Suffolk County Government-issued Non-Disclosure Agreement (NDA).

  • Protect County information and system-access information obtained during the engagement.

Security Clearance: No Secret or Top Secret security clearance requirement is stated for this engagement.

Hardware / Software / Licensing

This is a professional-services consulting engagement. The current requirement does not specify contractor-provided hardware or third-party software licenses.

The consultant will assess Microsoft 365 security and governance capabilities within the County's environment. Any access to County systems and Microsoft services will be subject to County authorization and applicable security requirements.

Work Arrangement

Remote: Yes. The solicitation permits all work to be performed remotely.

The consultant must nevertheless be available to coordinate with Suffolk County technical personnel, security stakeholders, and leadership as required throughout the engagement.

Compensation

Target pay range: $88–$92 per hour

Final compensation will be based on relevant Microsoft 365 security, identity, governance, Active Directory, assessment, and consulting experience.

About SMX Services & Consulting, Inc.

SMX Services & Consulting, Inc. provides information technology consulting, professional services, staffing, cybersecurity, cloud, systems engineering, and related technology services to government and commercial organizations.

SMX Services & Consulting, Inc. is an equal opportunity employer. Employment and engagement decisions are made in accordance with applicable law.

How to Apply

Qualified candidates should submit a current resume highlighting relevant experience with Microsoft 365 security and governance, Microsoft Entra ID, identity and access management, Microsoft cloud security, Active Directory security, compliance/governance, and security assessment engagements.

Please clearly identify hands-on Microsoft 365 security assessment and Active Directory trust/security experience in your resume.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Consultant Related jobs

Other jobs at SMX Services & Consulting, Inc.

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.