Project Engineer III - (Microsoft Cloud Specialization)
Job Type
Full-time
Description

  

The Project Engineer III - (Microsoft Cloud Specialization) is a senior, hands-on engineer who assesses, designs, and delivers technology solutions for primarily small and mid-sized customers, including larger organizations with internal IT teams. The primary focus is Microsoft 365, Microsoft Entra ID, Microsoft Intune, Windows Autopilot, Azure, endpoint management, and automation. The role is not limited to Microsoft cloud solutions and requires strong networking, on-premises infrastructure, and hybrid-environment skills.

The engineer performs pre-sales assessments and solution architecture for existing customers, then owns the technical execution and quality of assigned projects within approved Statements of Work (SOWs) and project plans. Working with Project Managers, Sales and account teams, support and security teams, vendors, and client stakeholders, the engineer also helps establish standards and reusable solutions across the customer base and for the internal team. Project Managers retain responsibility for project governance, schedule, budget, resources, change control, status reporting, and acceptance.

SPECIFIC RESPONSIBILITIES: Other duties may be assigned to meet business needs.

• Existing-customer assessments and pre-sales architecture: Assess existing customer environments, identify technical gaps and improvement opportunities, and develop practical solution architectures and recommendations. Collaborate with Sales, account teams, and engineering leadership on options, technical designs, SOWs, effort estimates, dependencies, and risks before project approval.

• Project planning, delivery, and coordination: Own assigned technical workstreams from implementation planning through completion. Define prerequisites, task sequencing, maintenance windows, estimates, and rollback plans; execute approved scope; and keep the Project Manager informed through accurate tasks, time entries, status, risks, and completion evidence. Escalate scope, schedule, budget, quality, or client-impact concerns promptly.

• Microsoft 365 and identity: Design, implement, and migrate Microsoft 365 and Microsoft Entra environments, including tenant configuration, Exchange Online and hybrid migrations, Teams, SharePoint, OneDrive, Entra Join, hybrid identity, Entra Connect Sync or Cloud Sync, authentication, Conditional Access, MFA, passwordless access, and identity governance.

• Modern endpoint and application management: Design and implement Intune and Windows Autopilot solutions, including enrollment and join strategies, deployment profiles and device preparation, configuration and compliance policies, device filters and assignments, application packaging and deployment, Windows Update for Business or Windows Autopatch where licensed, and workstation lifecycle support.

• Azure infrastructure and virtual desktop: Design and implement Azure virtual machines, virtual networks, storage, private and site-to-site connectivity, monitoring, backup, and recovery. Deliver Azure Virtual Desktop and Windows 365 solutions when included in customer requirements and project scope.

• Networking and on-premises infrastructure: Design, implement, and troubleshoot routing, switching, VLANs, wireless, firewalls, VPNs, DNS/DHCP, Windows Server, Active Directory, virtualization, storage, and backup/recovery. Work across Meraki/Cisco, Ruckus, HP, and other supported platforms, including cross-vendor migrations and integration with Microsoft cloud services.

• Deployment and lifecycle automation: Build repeatable, low-touch desktop and cloud workflows using PowerShell, Microsoft Graph, Intune scripts and remediations, Azure CLI, Bicep or Terraform, Git, and platform APIs. Automate device registration, provisioning, dynamic group and policy assignments, application delivery, validation, redeployment, wipe, retirement, and infrastructure configuration wherever practical.

• Security and governance: Apply least privilege, RBAC, privileged access controls, Azure Policy, logging, and secure configuration standards across cloud and on-premises environments. Implement endpoint security baselines, BitLocker, Windows LAPS, Defender integration, and Purview information-protection controls as applicable.

• Testing, cutover, and quality assurance: Obtain technical peer review of designs and material changes. Execute controlled changes with approved access, communication, backups, and rollback procedures. Record pre/post-change evidence for functionality, enrollment, applications, security, updates, connectivity, monitoring, recovery, and user experience; resolve findings and support customer IT review before acceptance.

• Documentation and operational handoff: Maintain accurate as-built diagrams, configuration records, scripts, application-package details, test evidence, change records, support procedures, and known limitations. Review documentation and transfer knowledge to internal support and customer IT teams so they can operate and troubleshoot the completed solution.

• Technical standards and solution development: Evaluate technologies, develop reference architectures and deployment standards, and pilot reusable solutions for use across all customer environments and internally. Work with engineering leadership and support teams to validate, approve, maintain, and consistently apply those standards.

Technical leadership and mentoring: Lead customer technical discussions, explain designs and tradeoffs clearly, mentor Project Engineers I and II, and serve as a senior escalation resource for complex cloud, endpoint, networking, and on-premises project issues. Share lessons learned and provide practical training to strengthen the team. 

Requirements

  

REQUIRED QUALIFICATIONS:

• Bachelor's degree in Computer Science, Information Technology, or a related field preferred; equivalent relevant experience and professional certifications may substitute.

• Minimum 8 years of progressive IT engineering experience, including 5+ years of substantial hands-on responsibility for Microsoft cloud, identity, endpoint management, or hybrid infrastructure projects.

• Advanced hands-on experience with Microsoft 365 and Microsoft Entra ID, including Exchange Online, Teams, SharePoint/OneDrive, identity synchronization, authentication, Conditional Access, MFA, and hybrid identity.

• Advanced Intune and Windows endpoint experience, including Windows 10/11, Entra Join and hybrid join, Windows Autopilot and device preparation, enrollment, policy and compliance management, application packaging, updates, endpoint security, and device lifecycle management.

• Demonstrated automation skills using PowerShell, Microsoft Graph, Intune scripts and remediations, platform APIs, Git-based workflows, and reusable deployment and validation tooling; experience with Azure CLI and Bicep or Terraform.

• Strong Azure skills across compute, networking, storage, identity, RBAC, Azure Policy, monitoring, backup, and recovery, with practical Azure Virtual Desktop or Windows 365 experience aligned to assigned customer solutions.

• Solid networking knowledge and hands-on troubleshooting across TCP/IP, routing, switching, VLANs, wireless, firewalls, VPNs, DNS, and DHCP. Work across Meraki/Cisco, Ruckus, HP, and other supported platforms and resolve issues beyond the Microsoft cloud layer.

• Strong on-premises and hybrid infrastructure knowledge, including Windows Server, Active Directory, Group Policy, certificates, virtualization, storage, backup/recovery, and integration with cloud services.

• Ability to conduct existing-customer pre-sales assessments, develop solution architectures and SOWs, communicate technical options and risks, and contribute to reusable standards and solutions for customers and internal teams.

• Demonstrated project-delivery discipline: estimates, implementation/rollback plans, peer review, documented testing, cutovers, accurate as-built records, and knowledge transfer. Explain and validate decisions with customer IT staff; manage multiple technical workstreams and escalate risks before committed milestones are affected.

• Ability to travel for customer assessments and project work, typically locally within the Chicago metropolitan area; work planned after-hours implementation windows and respond to project-specific escalations when necessary.

CERTIFICATION EXPECTATIONS:

Certification requirement: Must hold at hire at least one current Microsoft certification directly aligned with the role. Continued development should include additional credentials aligned with the engineer's assigned technology responsibilities.

Primary

• Microsoft 365 Certified: Endpoint Administrator Associate (MD-102) - strongly preferred for Intune, Windows Autopilot, endpoint deployment, application delivery, security policy, and desktop lifecycle automation.

• Microsoft Certified: Azure Solutions Architect Expert (AZ-305, with required AZ-104 prerequisite) - for assigned architecture-level Azure responsibilities.

Core

• Microsoft Certified: Azure Administrator Associate (AZ-104).

• Microsoft Certified: Identity and Access Administrator Associate (SC-300).

• Microsoft Certified: Windows Server Administrator Associate (AZ-802).

• Microsoft Certified: Azure Virtual Desktop Specialty (AZ-140).

Secondary

• Microsoft 365 Certified: Teams Administrator Associate (MS-700).

• Microsoft Certified: Information Security Administrator Associate (SC-401) - when assigned Microsoft Purview, information protection, DLP, retention, or related compliance responsibilities.

Service-management development

• ITIL Foundation (current version) preferred.

Equivalent current certifications and demonstrated hands-on experience will be considered. Certification expectations will be reviewed as Microsoft retires, replaces, or introduces role-based credentials.

Salary Description
$120,000 - $150,000/annually