JobTarget Logo

Infrastructure Engineer, M365 & Identity in Waco, Minnesota at PwrQ Holdings LLC

NewJob Function: Engineering
PwrQ Holdings LLC
Waco, Minnesota, 76707, United States
Posted on
New job! Apply early to increase your chances of getting hired.

Explore Related Opportunities

Job Description

Description:

Position Summary:

We are seeking a Infra Engineer III, M365 & Identity to own Forgent's Microsoft identity and productivity platform across all sites. This role is the single point of accountability for Entra ID, Conditional Access, Privileged Identity Management, and the full suite of Microsoft 365 security and compliance capabilities unlocked by our E5 licensing.

You will be joining at a pivotal moment — Forgent is migrating from a fragmented multi-entity Microsoft 365 environment to a single governed platform with a July 1 go-live deadline. This role will be critical to ensuring that deadline is met, and that identity and access are properly governed across the entire organization from day one.

Key Responsibilities:

Identity & Access Governance

  • Own and operate Entra ID (Azure Active Directory) across all Forgent entities — users, groups, roles, and licensing
  • Design and enforce Conditional Access policies aligned to Zero Trust principles — risk-based access, phishing-resistant authentication, and named location controls
  • Implement and manage Privileged Identity Management — just-in-time role activation, access reviews, and least-privilege enforcement for all admin roles
  • Manage Self-Service Password Reset with password writeback in the hybrid Active Directory and Entra ID environment
  • Own Entra Connect and hybrid identity sync health — ensure clean, reliable synchronization between on-premises Active Directory and Entra ID
  • Lead Entra ID Governance — access reviews, entitlement management, and lifecycle workflows across all entities

Security & Threat Protection

  • Deploy and manage Defender for Identity — sensor deployment on all domain controllers, alert triage, and integration with Defender XDR for unified identity threat detection
  • Configure and maintain Microsoft Purview Data Loss Prevention policies — protect sensitive data across Exchange Online, SharePoint, Teams, and endpoints
  • Manage Intune compliance and configuration policies — enforce device compliance requirements for Conditional Access integration
  • Serve as the identity subject matter expert for security incidents involving compromised accounts, privilege escalation, or unauthorized access

Single Sign-On & Application Integration

  • Own and operate enterprise Single Sign-On across all corporate applications using Entra ID as the identity provider
  • Configure and manage SSO integrations — SAML 2.0, OAuth 2.0, and OpenID Connect — for all business-critical applications across all entities
  • Onboard new applications to the Entra ID application gallery and enterprise app catalog, ensuring consistent authentication and access policies
  • Implement and manage application-level Conditional Access policies — enforce multi-factor authentication, device compliance, and risk-based controls per application
  • Manage application provisioning and de-provisioning using SCIM where supported, ensuring users are automatically granted and revoked access based on role
  • Maintain an authoritative inventory of all SSO-integrated applications, their owners, and their access policies
  • Serve as the escalation point for authentication failures, SSO configuration issues, and application access problems across the organization

Microsoft 365 Administration

  • Own M365 licensing administration — seat allocation, license assignment automation, and renewal planning across all entities
  • Manage the M365 Admin Center, including service health monitoring, tenant configuration, and policy enforcement
  • Support the broader Microsoft 365 E5 feature rollout — coordinate with the Messaging & Collaboration Engineer on Teams, Exchange Online, and OneDrive configurations that depend on identity policies
  • Maintain and document tenant configuration standards, Conditional Access runbooks, and identity governance procedures

Qualifications:

Required

  • 7–10 years of experience in Microsoft identity and enterprise Microsoft 365 engineering
  • Deep hands-on expertise with Entra ID — user and group management, Conditional Access, hybrid identity, and B2B collaboration
  • Proven experience implementing and operating Privileged Identity Management in a production enterprise environment
  • Strong understanding of hybrid identity — Entra Connect, password hash sync, pass-through authentication, and Active Directory Federation Services
  • Experience with Microsoft Purview, including Data Loss Prevention policy design and compliance reporting
  • Hands-on experience with Defender for Identity sensor deployment and alert management
  • Solid understanding of Intune device compliance and its integration with Conditional Access
  • Strong documentation skills — ability to produce runbooks, policy guides, and change management documentation
  • Hands-on experience configuring enterprise Single Sign-On integrations using SAML 2.0, OAuth 2.0, and OpenID Connect
  • Experience managing application provisioning and de-provisioning via SCIM

Preferred

  • Experience with Entra ID Governance — access reviews, entitlement management, and lifecycle workflows
  • Familiarity with Microsoft Sentinel for identity-related log ingestion and alerting
  • Experience supporting a Microsoft 365 E5 deployment or licensing transition
  • Knowledge of multi-entity or post-acquisition Microsoft 365 consolidation
  • Microsoft certifications — SC-300 (Identity and Access Administrator), MS-102 (Microsoft 365 Administrator)

Core Competencies & Behaviors:

  • Own identity and access governance for an entire NYSE-listed enterprise from day one — this is a greenfield opportunity, not a maintenance role
  • Work on a high-visibility Microsoft 365 E5 platform launch with a clear roadmap and leadership support
  • Operate at the intersection of identity, security, and compliance — a role that matters to every person in the company
  • Collaborative team environment with a Sr. Manager who came from an enterprise Microsoft background
  • Competitive compensation, benefits, and the ability to shape how identity is done across a growing multi-site organization

Working Conditions:

The typical work environment is a standard office setting. Frequently required to sit for extended periods of time at computer.

Disclaimer:

The statements above are intended to describe the general nature and level of work being performed. They are not an exhaustive list of all responsibilities, duties, or skills required. Forgent Power reserves the right to modify, interpret, or apply this job description as needed. Click or tap here to enter text.

Equal Employment Opportunity Statement:

Forgent Power is an equal opportunity employer. We are committed to creating an inclusive environment for all employees. Employment decisions are made without regard to race, color, religion, sex, national origin, age, disability, veteran status, or any other protected class.

Requirements:

Job Location

Waco, Minnesota, 76707, United States

Frequently asked questions about this position

Similar Jobs In Waco, Minnesota

Urgently Hiring

Heavy Equipment Operator

Rachel Contracting
Duluth, Minnesota
Hot Job

Assembler

Kinperium-Hiniker, LLC
Mankato, Minnesota
New

Sr. Full Stack Builder

Salute Inc.
Minneapolis, Minnesota
New

Installer

INTEREUM HOLDINGS LLC
Plymouth, Minnesota
New

Lead Production Technician

City of Red Wing
Red Wing, Minnesota

Apply Now