Department: Information Technology
Location: Delhi
Job Type: Permanent (Full-Time)
No. of Positions: 1
Experience: 5-8 Years
Position/Designation: Senior Engineer- IT Systems, Identity, Security

About the Role:

We are looking for a hands-on Microsoft 365 & Security Engineer to own and modernize the organization's corporate identity, Microsoft 365 environment, endpoint-management platform, and core cybersecurity controls.
The role will help transition the organization from a partially managed IT environment toward a standardized, secure, and scalable digital workplace supporting approximately 300 managed knowledge workers initially and ultimately a global workforce of 1,000+ users.
This is primarily a hands-on engineering role, focused on implementation, configuration, troubleshooting, security controls, and continuous improvement rather than policy-only or people-management activities.

Key Responsibilities:

Microsoft 365
  • Own administration, configuration, and continuous improvement of Microsoft 365, Exchange Online, Microsoft Teams, SharePoint Online, OneDrive for Business, and Microsoft 365 Groups.
  • Manage Microsoft 365 licensing and service configurations.
  • Support migration away from local storage and unmanaged file-sharing practices toward governed Microsoft platforms.
Identity & Access Management
  • Own and implement Microsoft Entra ID, Multi-Factor Authentication, Conditional Access, Single Sign-On, Enterprise Applications, and role-based access control.
  • Manage privileged administrator accounts, user lifecycle management, guest-user governance, access reviews, authentication policies, service accounts, and break-glass accounts.
  • Support legacy-authentication removal and development of secure authentication standards.
  • Establish the technical foundation for automated Joiner/Mover/Leaver processes.
Endpoint Management
  • Design and manage endpoint standards through Microsoft Intune.
  • Manage Windows enrollment, Windows Autopilot, compliance policies, configuration profiles, application deployment, update rings, and Windows Update for Business.
  • Implement BitLocker, device restrictions, endpoint security policies, and remote device actions.
  • Support corporate and BYOD endpoint policies.
  • Support a primarily Windows environment with limited macOS and Linux endpoints.
Endpoint Security
  • Manage and continuously improve endpoint security using Sophos Endpoint / Intercept X / EDR and Microsoft Defender technologies where adopted.
  • Manage Intune Endpoint Security, Windows Security, BitLocker, attack-surface-reduction controls, and security baselines.
  • Work with external MDR/SOC providers where required.
Security Engineering
  • Implement technical controls covering MFA, device compliance, Zero Trust principles, privileged access, identity protection, endpoint hardening, data protection, approved application access, vulnerability remediation, secure remote access, and administrative account separation.
  • Participate in cybersecurity incident response.
  • Support investigation, escalation, and remediation of security incidents.
SaaS & SSO
  • Work with the Enterprise Applications Engineer to integrate SaaS applications with Entra ID.
  • Implement SAML/OIDC-based SSO and configure SCIM where supported.
  • Support elimination of shared accounts and centralization of authentication.
  • Implement application access policies and conduct periodic access reviews.
Compliance
  • Provide technical implementation and evidence for ISO/IEC 27001, India DPDP Act requirements, GDPR requirements, internal security standards, customer security assessments, and security audits.
  • Work with Legal, management, and external consultants on technical compliance requirements rather than independently owning legal compliance.
Documentation
  • Maintain accurate architecture diagrams, tenant configuration records, administrator inventories, Conditional Access documentation, Intune configuration documentation, SOPs, recovery procedures, security-control evidence, identity standards, and endpoint standards.

Key Deliverables:

  • Achieve 90%+ enrollment of targeted corporate endpoints into approved endpoint management.
  • Enforce MFA for all applicable corporate users.
  • Implement and maintain a Conditional Access baseline.
  • Identify and secure privileged and administrator accounts.
  • Document corporate device and endpoint standards.
  • Ensure endpoint encryption is enforced.
  • Standardize Joiner/Mover/Leaver access processes.
  • Progressively move high-value SaaS applications toward SSO.
  • Improve the organization's Microsoft tenant security posture.
  • Reduce dependency on local storage and unmanaged file-sharing practices.
  • Rationalize Microsoft licensing and improve utilization.
  • Document security incident and escalation procedures.
  • Support MDR/SOC integration.
  • Maintain technical evidence required for ISO 27001 and other applicable security assessments.

Qualifications:

  • B.Tech / B.E. / BCA / MCA / B.Sc. IT / Computer Science or equivalent qualification.
  • Strong relevant professional experience may substitute for a specific degree.
  • Hands-on experience in Microsoft 365 administration, identity and access management, endpoint management, and cybersecurity is preferred.

Technical Skills:

Microsoft
  • Microsoft 365 Admin Center.
  • Microsoft Entra ID.
  • Microsoft Intune.
  • Exchange Online.
  • SharePoint Online.
  • OneDrive.
  • Microsoft Teams administration.
  • Microsoft 365 Groups.
Identity & Access
  • MFA.
  • Conditional Access.
  • SAML 2.0.
  • OAuth 2.0.
  • OpenID Connect.
  • SSO.
  • SCIM.
  • RBAC.
  • Privileged access concepts.
  • User lifecycle management.
Endpoint
  • Windows 10/11.
  • Microsoft Intune.
  • Windows Autopilot.
  • BitLocker.
  • Application packaging and deployment.
  • Endpoint compliance.
  • Windows Update management.
Security
  • Hands-on experience with at least one of Sophos Central / Sophos Endpoint or Microsoft Defender for Endpoint.
  • EDR and antivirus technologies.
  • Endpoint hardening.
  • Vulnerability management.
  • Zero Trust principles.
  • Security baselines.
  • Incident handling.
Automation
  • PowerShell.
  • Microsoft Graph.
  • Basic scripting and API concepts.
  • Exposure to Zapier, Make, or n8n will be an advantage.
The candidate does not need to be a software developer but should have practical knowledge of scripting, APIs, automation, and system integration concepts.

Preferred Technical Skills:

  • Microsoft Purview.
  • Defender for Office 365.
  • Defender for Identity.
  • Entra ID P2.
  • Privileged Identity Management.
  • Windows Hello for Business.
  • Azure Monitor / Log Analytics.
  • SIEM concepts.
  • Microsoft Sentinel.
  • macOS management through Intune.
  • MDM/MAM.
  • DLP.
  • Information classification.

Preferred Certifications:

  • Microsoft 365 Certified: Administrator Expert.
  • Microsoft Certified: Identity and Access Administrator Associate.
  • Microsoft Certified: Endpoint Administrator Associate.
  • Microsoft Certified: Security Operations Analyst.
  • Microsoft Certified: Information Protection and Compliance Administrator.
  • Equivalent Microsoft security certifications.
Certifications are desirable but should not substitute for hands-on technical ability.

Soft Skills:

  • Strong analytical and troubleshooting skills.
  • Systematic and process-oriented approach.
  • Ability to independently troubleshoot identity and endpoint issues.
  • Strong understanding of security and access implications.
  • Ability to challenge insecure existing practices constructively.
  • Strong documentation skills.
  • Good communication with technical and non-technical stakeholders.
  • Ability to coordinate effectively with vendors and consultants.
  • Comfortable supporting a geographically distributed organization.
  • Strong ownership and accountability.
  • Ability to work independently in a hands-on engineering environment.
  • Willingness to learn and continuously improve technical and security practices.