Senior Cloud Infrastructure Engineer

  • Full-time

Company Description

At BlueAlly, our mission is to make technology more accessible, more certain, and more impactful for every organization.

From cloud to cybersecurity, infrastructure to application modernization, we thrive on cutting-edge technologies and services. Elevate the impact of technology across your enterprise with world-class expertise that produces game-changing insights. Turn complex decisions into clear opportunities with a trusted guide to technology that ensures the next digital advance will be your decisive advantage. Trade IT complexity for capability with solutions that elevate possibilities, and advance with certainty, knowing you have BlueAlly as your ally in next. BlueAlly. Conquer Complexity.

Job Description

About the Role

BlueAlly is hiring a Senior Consultant to design, implement, and migrate Microsoft cloud infrastructure for clients across state and local government, education, healthcare, utilities and cooperatives, nonprofits, and midmarket enterprise.

This role spans Microsoft Entra ID, Microsoft 365, Microsoft Intune, Microsoft Purview, Microsoft Defender, and Azure infrastructure. You will deliver across concurrent client engagements, contribute technical input to solution scoping and estimation, and act as a trusted technical point of contact for client stakeholders from IT administrators through executive sponsors.

We are looking for someone who can operate with incomplete information, make defensible assumptions, document them, and keep an engagement moving.

Responsibilities

Solution Design and Delivery

  • Assess client environments and requirements, and design solutions that meet stated business and technical objectives.
  • Lead or participate in Microsoft tenant migrations: tenant-to-tenant, on-premises to cloud, hybrid coexistence, and third-party platform sources.
  • Configure and remediate Microsoft Entra ID, including Conditional Access, MFA, Privileged Identity Management, self-service password reset with password writeback, B2B and B2C, cross-tenant synchronization, hybrid identity, and ADFS-to-SAML modernization.
  • Deploy passwordless authentication, including Windows Hello for Business using cloud Kerberos trust and FIDO2 security keys.
  • Deploy and modernize endpoint management: Microsoft Intune, Windows Autopilot, Configuration Manager coexistence and transition, compliance policies, configuration profiles, update rings, application packaging, and OneDrive Known Folder Move.
  • Implement Microsoft Purview data protection: sensitivity labels, data loss prevention, retention and records management, and eDiscovery.
  • Deploy Microsoft Defender for Endpoint, Defender for Cloud, and Defender for Identity, including migration from third-party EDR platforms.
  • Manage and troubleshoot escalated issues across identity, data protection, and device management.

Azure Infrastructure

  • Perform Azure Migrate assessments and execute server and workload migrations, including wave planning, cutover scheduling, and application-owner validation.
  • Design and implement Azure networking, including VPN Gateway, Application Gateway and WAF, Bastion, and Front Door.
  • Implement Azure Backup and Azure Site Recovery to meet client recovery objectives.
  • Size and deploy Azure compute and storage, including Azure Files and storage account configuration.
  • Deliver Azure Virtual Desktop and Windows 365 proofs of value and production deployments.

Documentation and Enablement

  • Produce design documents, as-built documentation, runbooks, and migration plans.
  • Deliver knowledge transfer sessions and administrator training at project closeout.
  • Track time accurately against estimated hours and communicate variance early.
  • Stay current on Microsoft platform changes and share practice-level best practices internally.

Qualifications

Required Qualifications

  • Five or more years delivering Microsoft cloud infrastructure in a consulting, managed services provider, or enterprise engineering capacity.
  • Demonstrated ownership of at least three end-to-end Microsoft 365 or Azure migration projects, including planning, execution, and cutover.
  • Deep hands-on experience with Microsoft Entra ID and Microsoft 365 workloads, including Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams.
  • Deep hands-on experience with Microsoft Intune and Windows endpoint management.
  • Working knowledge of Azure IaaS: virtual machine sizing, storage, core networking, and backup.
  • Practical experience with Microsoft Purview data protection and the Microsoft Defender suite.
  • PowerShell and Microsoft Graph proficiency for automation, reporting, and bulk operations.
  • Ability to manage multiple concurrent client engagements and shifting priorities.
  • Excellent written and verbal communication; able to lead a client-facing technical discussion independently.

Preferred Qualifications

  • Azure Virtual Desktop or Windows 365 deployment experience.
  • Hypervisor migration experience, such as VMware to Hyper-V or VMware to Azure.
  • Third-party migration tooling: AvePoint Fly, Quest, BitTitan, or ShareGate.
  • macOS, iOS, and Android management.
  • Delivery experience in regulated or public-sector environments: HIPAA, CJIS, FERPA, SOC 2, or NERC CIP.
  • Microsoft Sentinel exposure.
  • Familiarity with Microsoft Copilot, Power Platform, and AI governance concepts.

Certifications

Preferred, not required. Candidates without current certifications who demonstrate equivalent hands-on depth will be considered, and BlueAlly supports certification attainment after hire.

  • SC-300: Microsoft Certified: Identity and Access Administrator Associate
  • MD-102: Microsoft 365 Certified: Endpoint Administrator Associate
  • MS-102: Microsoft 365 Certified: Administrator Expert
  • AZ-104: Microsoft Certified: Azure Administrator Associate
  • SC-400: Microsoft Certified: Information Protection and Compliance Administrator Associate
  • AZ-305: Microsoft Certified: Azure Solutions ‘. tect Expert
  • AZ-140: Microsoft Certified: Azure Virtual Desktop Specialty

Work Conditions

  • Remote-first, United States based. Preference for candidates in the Eastern or Central time zone.
  • Periodic evening and weekend work is required to support migration cutovers and client maintenance windows.
  • Target billable utilization of 80%.

Additional Information

About BlueAlly
BlueAlly is a leading provider of IT services and solutions, helping organizations conquer IT complexity across cloud, cybersecurity, infrastructure, data, and application modernization. Headquartered in Atlanta,Georgia, with delivery teams across the United States and globally, BlueAlly serves clients ranging from mid-market enterprises to large public-sector and commercial organizations.

Founded in 2011, BlueAlly delivers across the full technology lifecycle — from strategy and design through implementation, managed services, and continuous optimization. The company is recognized on CRN's Tech Elite 150 and MSP 500 lists and partners deeply with leading technology vendors. As enterprise AI moves from pilot to production, BlueAlly is investing in the people, platforms, and practices required to deliver AI Factory outcomes for our clients — and this role is at the center of that investment.

Equal Employment Opportunity
BlueAlly is an Equal Opportunity Employer. We are committed to building a diverse and inclusive workforce and to making employment decisions based on merit, qualifications, and business need. BlueAlly does not discriminate in employment on the basis of race, color, religion, sex (including pregnancy), national origin, age, disability, genetic information, sexual orientation, gender identity or expression, marital status, veteran status, or any other protected characteristic under applicable federal, state, or local law.

BlueAlly provides reasonable accommodations to qualified applicants and employees with disabilities. If you require an accommodation to participate in the application or interview process, please contact our People team.

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Privacy Notice