Systems Engineer II - Microsoft
Space Coast Credit UnionAbout the role
At Space Coast Credit Union (SCCU), our members are at the heart of everything we do. Since 1951, we’ve been committed to delivering financial services founded on integrity and a people-first philosophy.
As a Microsoft Systems Engineer you will design, build, implement, and maintain Space Coast Credit Union’s enterprise Microsoft platforms.
You'll play a vital role that serves as a hands on technical SME—driving solution design, vendor evaluation, complex implementation, and Tier III troubleshooting—while aligning with SCCU security, compliance, and business objectives.
- Member-Focused Mission: Be part of a not-for-profit organization that reinvests in its members.
- Hybrid and Flexible Schedule Options: This position is Hybrid with 2 days per week required in office.
- Career Growth: We prioritize internal promotions and offer on-the-job training.
Purpose:
The Microsoft Systems Engineer will design, build, implement, and maintain Space Coast Credit Union’s enterprise Microsoft platforms. This includes:
• Administering and optimizing On Premises Active Directory—with an emphasis on replication topology, Sites & Services, multi forest trust models, and CIS benchmark hardening.
• Engineering hybrid identity with Azure AD Connect / Entra Cloud Sync (Password Hash Sync, Pass through Authentication, and staging/swing migration), Hybrid Join, and Microsoft Entra ID SSO (SCIM, SAML 2.0, OAuth/OIDC, and Just In Time provisioning).
• Owning full lifecycle deployment of Intune MDM/MAM, Windows Autopilot, GPO to Intune configuration/compliance profile conversion, and endpoint protection with Microsoft Defender for Endpoint.
• Architecting, administering, and troubleshooting Proofpoint PPS/TAP secure mail gateways (DMARC / DKIM / SPF, malware & impersonation defense, smart host connectors, DLP, encryption).
• Supporting Microsoft 365 (Exchange Online, SharePoint Online, OneDrive, Teams) and Azure IaaS/PaaS resources for resilient collaboration and messaging.
Principal Duties and Responsibilities:
• Active Directory Engineering – Administer multi site, multi forest AD DS; design replication, schema/forest upgrades, delegated OU structures, and PKI/CA integration.
• Hybrid Identity & Entra ID – Plan, deploy, and maintain Azure AD Connect / Cloud Sync, Hybrid Join, Conditional Access, PIM, and SSO integrations (SCIM, SAML, OAuth/OIDC).
• Intune / Autopilot / Endpoint Security – Build and maintain Intune tenant, migrate legacy GPOs to Intune, create Autopilot deployment rings, publish compliance & configuration profiles, implement Defender for Endpoint and Proactive Remediations.
• Proofpoint Administration – Install, configure, and tune PPS/TAP clusters; manage policies, mail flow connectors, quarantine, and threat intel; troubleshoot end to end message delivery.
• Microsoft 365 Services – Administer Exchange Online (hybrid mail flow, EOP), SharePoint Online, OneDrive, and Teams retention/eDiscovery.
• Automation & Scripting – Develop PowerShell / Graph scripts for deployment, reporting, and proofpoint/intune automation; maintain CI/CD pipelines where applicable.
• Technical Support – Provide Tier III response and on call escalation for identity, device management, mail security, and collaboration platforms.
• Project Participation – Lead or contribute to IT projects, create charters, timelines, and deliverables, and coordinate with cross functional teams.
• Documentation – Produce and maintain high level/low level designs, runbooks, SOPs, and change control artifacts.
• Security & Compliance – Enforce SCCU security baselines and FFIEC/NCUA requirements; participate in audits and risk assessments.
• Vendor Liaison – Act as primary contact with Microsoft, Proofpoint, and other vendors for support cases, roadmap alignment, and licensing.
• Continuous Improvement – Track emerging Microsoft and Proofpoint capabilities; recommend and pilot new features to enhance resilience, security, and user experience.
JOB KNOWLEDGE, SKILLS & ABILITIES
• Proven hands on expertise designing and implementing:
o Azure AD Connect / Cloud Sync topologies, Hybrid Join, federation models.
o Intune MDM/MAM, Windows Autopilot, and GPO to Intune migration.
o Proofpoint PPS & TAP secure mail gateways, including DMARC/DKIM/SPF tuning.
o Entra ID SSO, SCIM provisioning, SAML 2.0, OAuth/OIDC, and Conditional Access.
• Strong PowerShell / Graph automation skills; ability to create JSON/Win32 and Proactive Remediation scripts.
• Excellent analytical and root cause troubleshooting skills for multi discipline issues (identity, mail flow, endpoint, security).
• Ef
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s