Senior Systems Engineer, Microsoft

Harvey Harvey · AI Frontier · Remote · IT

This role is for a Senior Systems Engineer at Harvey, a legal AI company. The engineer will be responsible for owning and managing the company's Microsoft platform, including Intune, M365, and Entra ID, across production, development, and demo environments. Key responsibilities include architecting device management policies, deploying and managing M365 tenants, collaborating on identity and access management, and building/maintaining demo and test environments. The role requires strong expertise in Microsoft systems, automation (IaC, PowerShell, Graph API), and security best practices, with a focus on providing a seamless and secure experience for employees, particularly legal professionals.

What you'd actually do

  1. Own end-to-end Microsoft 365 and Intune architecture across corporate production, dev, and demo environments, including tenant strategy, governance, and lifecycle management.
  2. Build, automate, and maintain multi-tenant demo and test environments with seeded data, realistic users, and scripted resets for Engineering, Product, and Sales teams.
  3. Standardize and streamline Intune device management: Autopilot, enrollment, configuration and compliance policies, Win32/MSIX app packaging and deployment, patching, and reporting for Windows and macOS endpoints. Manage iOS and Android MDM as needed.
  4. Own laptop deployment configuration, including establishing golden Windows images, standard baselines, and endpoint hardening policies in partnership with the Security team.
  5. Implement reusable infrastructure-as-code and automation (PowerShell, Microsoft Graph, Bicep/Terraform, CI/CD) for environment provisioning and policy enforcement.

Skills

Required

  • 7+ years of experience in IT systems engineering
  • Deep expertise in Microsoft Intune and M365 administration at scale
  • Hands-on experience managing multi-tenant Microsoft environments
  • Proven success building automated demo and test labs
  • Strong PowerShell and Microsoft Graph API skills
  • Solid infrastructure-as-code experience (Bicep or Terraform) and CI/CD pipelines
  • Deep Intune experience: Autopilot, Win32/MSIX packaging, configuration and compliance policies, BitLocker/FileVault, patching, and endpoint analytics across both macOS and Windows
  • Experience with Entra ID (Azure AD), including conditional access, SSO, identity governance, and integration with third-party identity providers such as Okta
  • Solid understanding of security frameworks and best practices (Zero Trust, least privilege, conditional access, MFA)
  • Strong communication and stakeholder management skills

Nice to have

  • Microsoft certifications: 365 Enterprise Administrator Expert, Identity and Access Administrator, Modern Desktop Administrator, or Azure Administrator/Architect
  • Experience managing Microsoft infrastructure in a legal or professional services environment where data sensitivity and compliance are paramount
  • Familiarity with JAMF and experience managing hybrid macOS/Windows fleets
  • MECM/SCCM co-management and cloud-native endpoint migration experience
  • Azure subscriptions, networking, and monitoring

What the JD emphasized

  • Microsoft platform
  • Intune
  • M365
  • Entra ID
  • demo environments
  • test environments
  • identity and access management
  • Okta
  • security
  • legal professionals
  • data sensitivity
  • compliance