Back to Jobs

Microsoft 365 Administrator, Level 3 (Part-Time)

Confidential employer

Posted 8/28/2026Rate visible after sign-upSource: Curated from source
About the Role

Part-Time Microsoft 365 IT Technician - Level 3
Architecture & Security Operations

About the role
RankStudio is hiring a part-time Level 3 Microsoft 365 IT Technician to own architecture and security operations for a growing portfolio of small biotech and pharma client environments. This is a hands-on, senior technical role - not a ticket-support seat. You will design and implement M365 architecture, own security operations end-to-end, and build the automation that keeps client environments compliant and secure. You will work independently under the direction of RankStudio's CEO, who serves as the senior technical advisor across all engagements.

This role is designed for an experienced practitioner with an existing day job, freelance practice, or flexible schedule who wants meaningful architecture work at a boutique AI consulting firm. It is not a full-time seat, and it is not a bridge to full-time employment.

What you will own:
.Architecture - Design Microsoft 365 tenant configurations, security baselines, and compliance postures for biotech and pharma clients across 5-15 client environments. You own the design; the CEO reviews it.
Security operations - Own vulnerability management, i ---------- response, and security posture monitoring across client tenants. Not alert triage as a ticket-taker - SecOps as the responsible technician.
Infrastructure as code - Build and maintain Bicep, ARM, or Terraform templates for repeatable tenant deployments. Version-controlled in GitHub. Reviewed for consistency across client environments.
PowerShell automation - Write PowerShell scripts and Microsoft Graph SDK workflows from scratch for tenant configuration, user lifecycle, license management, security policy deployment, and compliance reporting. This is a build role, not a run-existing-scripts role.
Microsoft Purview architecture - Design and deploy sensitivity labels, DLP policies, retention schedules, eDiscovery workflows, and Insider Risk Management for regulated clients (21 CFR Part 11, HIPAA).
Entra ID architecture - Design conditional access frameworks, PIM configurations, access review cycles, and identity governance for client tenants.
Intune deployment architecture - Design BYOD and corporate device management approaches including App Protection Policies for regulated data on personal devices. Deploy compliance policies, configuration profiles, and app management workflows.
Defender for Endpoint and Defender for O365 - Own policy design, tuning, and i ---------- response ownership. Not queue watching.
Documentation - Author architecture decision records, runbooks, and configuration baselines that other technicians can operate from.

Required experience:
4+ years hands-on M365 tenant administration, at least 2 of which in a managed services or multi-tenant consulting context.
PowerShell scripting from scratch - you can sit down and write a working script for an M365 admin task without starting from a template or AI-generated skeleton. You use documentation and AI tools to accelerate your work, but the underlying capability is yours.
Infrastructure as code exposure - you have deployed at least one production environment (Azure resources, M365 baselines, or comparable) via Bicep, ARM, Terraform, or M365 DSC, and can explain the trade-offs of the tool you used.
Hands-on Intune - you have deployed compliance policies, configuration profiles, and App Protection Policies (MAM without enrollment) in production.
Hands-on Entra ID / Azure AD - you have designed conditional access frameworks, deployed PIM, and run access reviews in production.
Working Purview knowledge - you have deployed sensitivity labels, DLP policies, or retention schedules in production. Purview forensics-only experience (eDiscovery for hard-deleted data) does not qualify.
Security operations ownership - you have owned vulnerability remediation, security i ---------- response, or compliance posture for at least one production environment as the responsible technician, not as a ticket-response contributor.
Excellent written English - has good writing and communications skills
Reliable home internet (50 Mbps minimum) and a personal computer capable of running M365 admin centers and a virtual desktop.

Strongly preferred:
Microsoft certifications - MS-102, SC-300, SC-400, AZ-104, AZ-500, MD-102. Full stack not required; two or three genuine, in-date certs are stronger signal than a long list of stale ones.
Past role at a Microsoft Partner or MSP serving SMB or mid-market clients across multiple tenants.
Experience with M365 backup tooling - Veeam M365, AvePoint, Druva, or Spanning.
Healthcare or life sciences client experience - 21 CFR Part 11, HIPAA, or GxP compliance context.
Ticketing systems- Freshdesk, Zendesk, ConnectWise, or HaloPSA administration (as the person configuring the tool, not the person filling tickets in it).
Workflow automation exposure - n8n, Power Automate, or Logic Apps for admin task automation.

Disqualifiers:
Primary career experience is ticket / desk / support work, even if the resume shows M365 admin-center exposure. This role is architecture and SecOps ownership. Section titles matter: "IT Service Desk Analyst," "Technical Support Engineer," "Help Desk Technician" as the dominant career pattern will not fit, regardless of how the current job is titled.
Cannot write PowerShell without templates or AI-generated skeletons. AI-assisted scripting is expected. Inability to write from scratch is disqualifying - the role requires building automation others will run.
No production infrastructure-as-code experience. Training or self-study on IaC is not sufficient.
No hands-on Intune configuration profile or App Protection Policy deployment. Reading Microsoft Learn on Intune is not the same as deploying it.
Purview knowledge limited to eDiscovery forensics. The role requires deploying labels, DLP, and retention — governance, not just search.
Cannot commit to consistent weekly hours during Pacific business hours overlap. The role is asynchronous but requires reliable availability during the overlap window.
Requires this role as primary income. The compensation and hours are structured for candidates with an existing income base.

Engagement and pay
Independent contractor agreement
100% Remote
Part-time commitment: 20 hours per week, flexible scheduling with required overlap during Pacific business hours (specific overlap window to be agreed with the CEO).
Fixed monthly retainer: USD 900 to 1,000 per month, paid in USD via Wise.

Track this external role

Sign in to save this listing and apply through the original source.

Sign in to SaveReport JobOpen Original Listing