Find your next role
Strengthen your profile
SMX Services & Consulting, Inc.
IT Services & IT Consulting
See how your profile stacks up against this role.
We compared the job requirements to your profile to show where you're strong and where you fall short.
Company: SMX Services & Consulting, Inc.
Position: Microsoft 365 Security & Governance Consultant
Engagement: Government Professional Services
Work Location: Remote
Customer: Suffolk County Government, New York
Compensation: $88–$92 per hour, based on qualifications and experience
Anticipated Period of Performance: Award/PO approval through May 20, 2027, or completion of the project
Position Type: Consultant / Project-Based
SMX Services & Consulting, Inc. is seeking an experienced Microsoft 365 Security & Governance Consultant to support a Suffolk County Government Microsoft 365 security and governance initiative.
The consultant will serve as an independent technical advisor responsible for evaluating the security and governance posture of the County's Microsoft 365 environment, identifying security and configuration gaps, assessing identity and access controls, reviewing Active Directory trust relationships, and developing prioritized recommendations aligned with the County's migration and security objectives.
This is a remote professional-services engagement requiring a consultant who can independently assess complex Microsoft environments and communicate actionable security recommendations to both technical stakeholders and executive leadership.
The consultant will support Microsoft 365 security and governance assessment activities, including:
Review tenant-wide Microsoft 365 security and governance configurations.
Evaluate global settings, security baselines, administrative roles, and related security controls.
Identify configuration weaknesses, security gaps, and opportunities to strengthen the environment.
Develop practical recommendations to improve the County's Microsoft 365 security posture.
Assess Microsoft Entra ID identity and access configurations.
Review privileged and administrative roles.
Evaluate Multi-Factor Authentication controls.
Assess Conditional Access policies and configurations.
Review Role-Based Access Control and privilege assignments.
Identify excessive privileges and opportunities to strengthen least-privilege access.
Assess security and governance configurations associated with:
Microsoft Entra ID
Microsoft Exchange Online
Microsoft Teams
Microsoft SharePoint Online
Microsoft OneDrive
The consultant will identify configuration risks and provide recommendations for improving security across these Microsoft 365 services.
Assess Microsoft 365 auditing and logging capabilities.
Review relevant audit logs and monitoring configurations.
Evaluate mailbox auditing.
Review Teams and SharePoint activity visibility.
Identify gaps affecting security monitoring, investigation, and governance.
Evaluate applicable Microsoft 365 security and compliance capabilities, including:
eDiscovery
Data retention
Data Loss Prevention (DLP)
Security and compliance alerting
Information governance controls
Provide recommendations for improving the effective use and configuration of these capabilities.
Analyze Active Directory forest trust relationships involving Suffolk County and associated environments, including the District Attorney and Police Department environments.
Responsibilities include:
Reviewing relevant forest trust relationships.
Identifying potential security exposure created through trust configurations.
Evaluating potential lateral-access risks.
Identifying opportunities to restrict or segment access.
Recommending improvements that strengthen identity and directory security.
Document identified security and governance gaps.
Assess the potential impact and priority of findings.
Organize recommendations into immediate, medium-term, and longer-term actions.
Identify issues that should be addressed before or in alignment with Microsoft 365 migration activities.
Develop an actionable remediation roadmap for Suffolk County.
Clearly explain technical findings to County stakeholders.
Conduct interactive knowledge-transfer activities.
Present security risks and recommendations in a manner understandable to both technical personnel and leadership.
Support County leadership and security stakeholders in understanding remediation priorities and recommended next steps.
Strong hands-on knowledge in several of the following areas is highly desirable:
Microsoft 365 security architecture
Microsoft Entra ID
Identity and Access Management
Conditional Access
Multi-Factor Authentication
Privileged access and administrative role management
Role-Based Access Control
Exchange Online security
Microsoft Teams security and governance
SharePoint Online security and governance
OneDrive security and governance
Microsoft Purview or related Microsoft 365 compliance capabilities
eDiscovery
Data Loss Prevention
Retention and information governance
Microsoft 365 auditing and security monitoring
Active Directory
Active Directory forest trusts
Security gap assessments
Cybersecurity risk analysis
Security remediation planning
The successful candidate should be capable of working independently as the primary consultant for the engagement and should be comfortable moving between hands-on technical assessment, cybersecurity analysis, governance recommendations, and executive-level communication.
The ideal candidate will be able to evaluate an existing Microsoft environment objectively, distinguish critical security issues from longer-term improvements, and convert technical findings into a practical remediation roadmap.
Experience performing Microsoft 365 security assessments, tenant reviews, identity-security assessments, Active Directory security reviews, or Microsoft cloud governance engagements is particularly relevant.
Candidates should be comfortable producing professional technical and executive-facing materials that may include:
Security assessment findings
Configuration gap analysis
Risk-prioritized recommendations
Microsoft 365 security and governance observations
Identity and access findings
Active Directory trust findings
Remediation recommendations
Prioritized remediation roadmap
Knowledge-transfer and executive briefing materials
The selected candidate must:
Be willing and able to work remotely.
Provide evidence of a recent background check or agree to a background check performed by Suffolk County Government.
Agree to execute a Suffolk County Government-issued Non-Disclosure Agreement (NDA).
Protect County information and system-access information obtained during the engagement.
Security Clearance: No Secret or Top Secret security clearance requirement is stated for this engagement.
This is a professional-services consulting engagement. The current requirement does not specify contractor-provided hardware or third-party software licenses.
The consultant will assess Microsoft 365 security and governance capabilities within the County's environment. Any access to County systems and Microsoft services will be subject to County authorization and applicable security requirements.
Remote: Yes. The solicitation permits all work to be performed remotely.
The consultant must nevertheless be available to coordinate with Suffolk County technical personnel, security stakeholders, and leadership as required throughout the engagement.
Target pay range: $88–$92 per hour
Final compensation will be based on relevant Microsoft 365 security, identity, governance, Active Directory, assessment, and consulting experience.
SMX Services & Consulting, Inc. provides information technology consulting, professional services, staffing, cybersecurity, cloud, systems engineering, and related technology services to government and commercial organizations.
SMX Services & Consulting, Inc. is an equal opportunity employer. Employment and engagement decisions are made in accordance with applicable law.
Qualified candidates should submit a current resume highlighting relevant experience with Microsoft 365 security and governance, Microsoft Entra ID, identity and access management, Microsoft cloud security, Active Directory security, compliance/governance, and security assessment engagements.
Please clearly identify hands-on Microsoft 365 security assessment and Active Directory trust/security experience in your resume.
After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.
Marcus Rivera
Chief Revenue Officer

Anthropic

Mercor

Groundswell

Groundswell

Groundswell

SMX Services & Consulting, Inc.

SMX Services & Consulting, Inc.

SMX Services & Consulting, Inc.