Senior MSP Engineer — Projects & Escalations (Remote)

Please login or register as jobseeker to apply for this job.

TYPE OF WORK

Any

SALARY

$1800-$2400/mo

HOURS PER WEEK

40

DATE UPDATED

Aug 1, 2026

JOB OVERVIEW

Read the application steps at the bottom before you send anything. There are three items and all three are quick. Applications missing any of them will not be reviewed.

We're a small MSP based in Colorado. Our clients are mostly in healthcare, manufacturing, and compliance-focused companies who rely on us as their full IT department. 6 people on the team. We're growing and we need an experienced L3 engineer who can own project execution and take escalations off the rest of the team.

We're looking for someone who can take a project scope, think through the best approach, propose a solutions, write a project plan and run with it. Onboard a new client into our full service stack. Pick up a ticket that has already stumped another tea ---------- mber and drive it to resolution. Harden a Microsoft 365 tenant for a client pursuing SOC 2 compliance. Document everything thoroughly so the next person doesn't have to start from scratch.

We value first principles thinking and expert troubleshooting. When you encounter a situation you haven't seen before, we expect you to research it, think it through, suggest your approach, and execute once we align. You won't be following checklists. You'll be solving real problems across a diverse client base.

What you'll be doing

Escalations. You are the technical backstop for the team. Tickets that clear L1 and L2 land with you. Root cause, resolve, and write it up so it doesn't come back.

Project execution. Full client onboardings: RMM deployment, M365 tenant baselining, security hardening, service stack tooling, documentation buildout.

Microsoft 365 security and identity work. Conditional access policies, Entra ID configuration, compliance policies, DLP, MFA. This is the core of what we do and the deepest part of the role.

Intune and endpoint management. Enrollment, compliance policies, app deployment, Autopilot. Migrating endpoints from RMM-only management to Intune-managed. Apple Business Manager and Jamf for macOS environments.

Migration projects. Tenant-to-tenant, Google to M365, SharePoint, Quickbooks to QBO

Network and firewall configuration. IP schema design, VLANs, security policies, VPN setup, typically remote while a local tech racks hardware. Fortinet is our standard. UniFi for switching and wireless.

Automation and scripting. Building and maintaining scripts to streamline internal processes and client environments. You'll also work with AI development tools on internal systems projects.

Documentation of everything you touch in our internal knowledge base.

No two weeks look the same.

What we're looking for

3 to 5 years in an MSP environment at an L3 level. You've managed multiple client tenants simultaneously, worked within a PSA and ticketing system, and understand the pace and context-switching that comes with supporting a diverse client base.

Advanced Microsoft 365 administration and security experience. This is the most important qualification for this role. Not mailbox management. We mean conditional access design, Entra ID, identity governance, compliance policies, and knowing why a policy is scoped the way it is.

Real Intune proficiency. Enrollment, compliance baselines, app deployment, Autopilot. Comfortable migrating endpoints from RMM-only management into Intune-managed environments.

Cybersecurity proficiency. Conditional access policy design, security baselines, MFA enforcement, identity protection. Experience with HIPAA, SOC 2, or other compliance frameworks is important. We serve regulated industries and our clients depend on us to get this right.

Automation and scripting experience. PowerShell, bash, or similar. You look for ways to automate repetitive work in tools like your RMM, PSA, or other platform APIs. Experience with AI coding tools or workflow automation platforms is a strong plus.

Migration experience across different scenarios (tenant-to-tenant, Google Workspace, IMAP).

Networking is helpful, not required. If you have hands-on firewall configuration experience, especially Fortinet, that moves you up the list. If you don't, we'll pair you with our network lead and bring you along.

Strong documentation habits. If you didn't document it, it didn't happen.

Excellent written and spoken English. You'll be communicating with US-based tea ---------- mbers in Teams throughout the day and occasionally joining client calls.

First principles thinker. When something breaks or a project hits an unexpected turn, you research, reason through it, and come back with a recommended path forward.

Self-directed. You'll receive a scope of work and we expect you to execute it, flag blockers, and submit milestones for review without being managed step by step.

Hours

First 90 days: you work our hours. Full US Mountain Time business hours, roughly 8:00 AM to 5:00 PM MT. This is not negotiable and it is how we get you trained, integrated, and trusted with client environments.

After 90 days: minimum 4 hours of daily overlap with Mountain Time, with the rest of your schedule flexible.

Apply only if the first 90 days works for you.

Required within 90 days of hire:

Microsoft SC-300 (Identity and Access Administrator) and MD-102 (Endpoint Administrator). We cover exam fees and study materials. If you already hold either or both, that puts you ahead.

Nice to have
Experience with any of our toolstack: NinjaRMM, HaloPSA, Huntress, ImmyBot, CIPP, Hudu
Apple Business Manager and Jamf for macOS endpoint management
Fortinet NSE certification or equivalent
AI coding tools, workflow automation (n8n, Power Automate, or similar), or building internal tooling. We're an AI-forward team and actively building in this space
What we offer

Full-time remote. $1,500 to $2,000/month depending on experience and certifications. Permanent pay increases tied to certifications earned. Exam fees and study materials covered. Interesting project work across a diverse client base. A team that communicates well and trusts you to own your work.

This role starts with a 60-day trial period so we can both make sure it's a good fit.

How to apply

We're hiring immediately and will begin interviews within days of posting.

Send us these three things.

1. Your resume.

2. A short intro video, one to two minutes. Just you on camera telling us who you are and the kind of work you do. If you already have an intro video recorded, use that one. We are not judging production quality. We only want to hear how you explain things before we get on a call.

3. Short written answers to the three questions below. A paragraph each is plenty. We are reading for how you think, not for length.

Question 1. You're onboarding a 50-person company from Google Workspace to Microsoft 365. What do you do in your first two weeks, in what order, and what are the gotchas you watch for?

Question 2. You're hardening a Microsoft 365 tenant for a client pursuing SOC 2. Which conditional access policies do you put in place first, and why in that order?

Question 3. A ticket is escalated to you. Users at one client intermittently can't authenticate to Microsoft 365, and the L2 has already confirmed it isn't a password or MFA registration issue. How do you work it?

Answer in your own words, from your own experience. If you haven't done one of these, say so and tell us how you would approach it. We would much rather read honest reasoning than a polished answer that isn't yours.

VIEW OTHER JOB POSTS FROM:
SHARE THIS POST
facebook linkedin
  BENCHMARKS  
Loading Time: Base Classes  0.0007
Controller Execution Time ( Jobseekers / Job )  0.0181
Total Execution Time  0.0194
  GET DATA  
No GET data exists
  MEMORY USAGE  
1,525,232 bytes
  POST DATA  
No POST data exists
  URI STRING  
jobseekers/job/Senior-MSP-Engineer-Projects-Escalations-Remote-1700770
  CLASS/METHOD  
jobseekers/job
  DATABASE:  onlinejobs (Jobseekers:$db)   QUERIES: 13 (0.0123 seconds)  (Hide)
0.0004   SELECT *
                                
FROM exrates
                                WHERE rate_name 
'USD-PHP' 
0.0004   SELECT *
FROM `employer_jobs`
WHERE `job_id` = 1700770
 LIMIT 1 
0.0008   SELECT *
FROM `employers`
WHERE `employer_id` = 778814
 LIMIT 1 
0.0009   SELECT COUNT(*) AS `numrows`
FROM `t_thread` `t`
LEFT JOIN `t_thread_misc` `miscON `t`.`id` = `misc`.`thread_id`
WHERE `t`.`job_id` = 1700770
AND `misc`.`idIS NULL 
0.0005   SELECT e.business_namee.logoe.websitee.rebill_datee.date_added member_datehitsDATEDIFF('2026-08-09',ej.date_added) duration_daysDATEDIFF('2026-08-09',e.rebill_date) duration_rebillej.*, e.deactivate FROM employers eemployer_jobs ej WHERE e.employer_id ej.employer_id AND
                                   ((
e.user_level >= '500' AND ej.date_added <= e.rebill_date)
                                   OR 
e.employer_id '' OR (ej.date_approved <> '2000-01-01' and DATEDIFF('2026-08-09',ej.date_added) <= 14 ))
                                   AND 
e.deactivate != AND ej.deleted AND job_id '1700770' 
0.0008   SELECT *
FROM `employer_jobs_skills` `ejs`
LEFT JOIN `skills_categories` `scON `ejs`.`skill_id` = `sc`.`id`
WHERE `job_id` = 1700770 
0.0012   UPDATE employer_jobs SET hit_counts '***Aug-01-2026=642***Aug-02-2026=98***Aug-03-2026=82***Aug-04-2026=60***Aug-05-2026=36***Aug-06-2026=32***Aug-07-2026=31***Aug-08-2026=9***Aug-09-2026=1' WHERE job_id'1700770'  
0.0005   UPDATE employer_jobs SET monthly_hits '***Aug-2026=990' WHERE job_id'1700770'  
0.0013   SELECT date_sent FROM jobseeker_sent_emails WHERE jobseeker_id '' AND job_id '1700770' AND status LIKE 'sent%' ORDER BY id DESC  
0.0003   SELECT *
FROM `employer_jobs_skills` `ejs`
LEFT JOIN `skills_categories` `scON `ejs`.`skill_id` = `sc`.`id`
WHERE `job_id` = 1700770 
0.0045   SELECT COUNT(*) AS `numrows`
FROM `employer_jobs`
WHERE `employer_id` = '778814'
AND `date_added` >= '2022-06-08' 
0.0004   select from teasers 
0.0003   SELECT FROM skill_categories WHERE skill_cat_id='' 
  HTTP HEADERS  (Show)
  SESSION DATA  (Show)
  CONFIG VARIABLES  (Show)