Microsoft 365 & Security Infrastructure Administrator
Role details
Job location
Tech stack
Job description
We're looking for a Microsoft 365 & Security Infrastructure Administrator who loves building things properly. This role sits at the heart of our cybersecurity strategy, taking a clear security vision and engineering it into a scalable, automated Microsoft cloud platform that's secure by design. It's a hands-on, high-impact role with real ownership and influence
Reporting To: Head of Cybersecurity (Accountable) Role Status: Technical Lead (Responsible) Mission: To translate strategic vision into a scalable, "secure-by-design" technical reality using modern Microsoft cloud principles
The Core Mandate
- Vision to Reality: While the Head of Cybersecurity defines the "Why" and "Vision," this role defines the technical "What" and engineers the "How."
- Scalability First: Move from case-by-case, reactive fixes to a fully automated, policy-driven management-at-scale model.
Key Outcomes for Success
- Scalable Infrastructure: Transition from ad-hoc management to a fully automated, policy-driven environment.
- Proactive Security: Remediating security gaps before they are exploited, with a focus on long-term stability.
- Metrics-Driven Operations: Establishing a regular cadence of high-signal reporting on platform health and risk reduction.
- Zero-Touch Operations: Fully operational, secure automated provisioning reducing manual intervention.
Essential Responsibilities (The "What" and "How")
- Identity, Access & Segregation (EntraID): Optimizing structure via Administrative Units and enforcing strict segregation of duties.
- Endpoint Security & Device Management (Intune): Configuring MDM/MAM and automated deployment for all device types.
- Platform Hardening & Security Baselines: Implementing "Secure-by-Design" baselines across the M365 stack, including Copilot.
- Azure Tenant & Modern Cloud Governance: Enforcing Data Residency, Zero Trust principles, and Infrastructure as Code (Terraform).
- SharePoint & Collaboration Governance: Technical delivery of site lifecycles and external sharing controls.
- Compliance, Audit & Documentation: Maintaining technical standards and "code-based" evidence for audit readiness.
- Reporting, Analytics & Metrics: Defining and delivering KPIs to measure implementation effectiveness and platform health.
Requirements
- Proactive Solution-Finder: Prioritizes long-term system integrity over short-term fixes.
- Data-Driven & Analytical: Defines success through measurable KPIs and clear executive reporting.
- Modern Cloud Mentality: Committed to staying current with Microsoft's evolving cloud and AI landscape.