Department: Information Technology
Location: Delhi
Job Type: Permanent (Full-Time)
No. of Positions: 1
Experience: 5-8 Years
Position/Designation: Senior Engineer- IT Systems, Identity, Security
About the Role:
We are looking for a hands-on Microsoft 365 & Security Engineer to own and modernize the organization's corporate identity, Microsoft 365 environment, endpoint-management platform, and core cybersecurity controls.
The role will help transition the organization from a partially managed IT environment toward a standardized, secure, and scalable digital workplace supporting approximately 300 managed knowledge workers initially and ultimately a global workforce of 1,000+ users.
This is primarily a hands-on engineering role, focused on implementation, configuration, troubleshooting, security controls, and continuous improvement rather than policy-only or people-management activities.
Key Responsibilities:
Microsoft 365
- Own administration, configuration, and continuous improvement of Microsoft 365, Exchange Online, Microsoft Teams, SharePoint Online, OneDrive for Business, and Microsoft 365 Groups.
- Manage Microsoft 365 licensing and service configurations.
- Support migration away from local storage and unmanaged file-sharing practices toward governed Microsoft platforms.
Identity & Access Management
- Own and implement Microsoft Entra ID, Multi-Factor Authentication, Conditional Access, Single Sign-On, Enterprise Applications, and role-based access control.
- Manage privileged administrator accounts, user lifecycle management, guest-user governance, access reviews, authentication policies, service accounts, and break-glass accounts.
- Support legacy-authentication removal and development of secure authentication standards.
- Establish the technical foundation for automated Joiner/Mover/Leaver processes.
Endpoint Management
- Design and manage endpoint standards through Microsoft Intune.
- Manage Windows enrollment, Windows Autopilot, compliance policies, configuration profiles, application deployment, update rings, and Windows Update for Business.
- Implement BitLocker, device restrictions, endpoint security policies, and remote device actions.
- Support corporate and BYOD endpoint policies.
- Support a primarily Windows environment with limited macOS and Linux endpoints.
Endpoint Security
- Manage and continuously improve endpoint security using Sophos Endpoint / Intercept X / EDR and Microsoft Defender technologies where adopted.
- Manage Intune Endpoint Security, Windows Security, BitLocker, attack-surface-reduction controls, and security baselines.
- Work with external MDR/SOC providers where required.
Security Engineering
- Implement technical controls covering MFA, device compliance, Zero Trust principles, privileged access, identity protection, endpoint hardening, data protection, approved application access, vulnerability remediation, secure remote access, and administrative account separation.
- Participate in cybersecurity incident response.
- Support investigation, escalation, and remediation of security incidents.
SaaS & SSO
- Work with the Enterprise Applications Engineer to integrate SaaS applications with Entra ID.
- Implement SAML/OIDC-based SSO and configure SCIM where supported.
- Support elimination of shared accounts and centralization of authentication.
- Implement application access policies and conduct periodic access reviews.
Compliance
- Provide technical implementation and evidence for ISO/IEC 27001, India DPDP Act requirements, GDPR requirements, internal security standards, customer security assessments, and security audits.
- Work with Legal, management, and external consultants on technical compliance requirements rather than independently owning legal compliance.
Documentation
- Maintain accurate architecture diagrams, tenant configuration records, administrator inventories, Conditional Access documentation, Intune configuration documentation, SOPs, recovery procedures, security-control evidence, identity standards, and endpoint standards.
Key Deliverables:
- Achieve 90%+ enrollment of targeted corporate endpoints into approved endpoint management.
- Enforce MFA for all applicable corporate users.
- Implement and maintain a Conditional Access baseline.
- Identify and secure privileged and administrator accounts.
- Document corporate device and endpoint standards.
- Ensure endpoint encryption is enforced.
- Standardize Joiner/Mover/Leaver access processes.
- Progressively move high-value SaaS applications toward SSO.
- Improve the organization's Microsoft tenant security posture.
- Reduce dependency on local storage and unmanaged file-sharing practices.
- Rationalize Microsoft licensing and improve utilization.
- Document security incident and escalation procedures.
- Support MDR/SOC integration.
- Maintain technical evidence required for ISO 27001 and other applicable security assessments.
Qualifications:
- B.Tech / B.E. / BCA / MCA / B.Sc. IT / Computer Science or equivalent qualification.
- Strong relevant professional experience may substitute for a specific degree.
- Hands-on experience in Microsoft 365 administration, identity and access management, endpoint management, and cybersecurity is preferred.
Technical Skills:
Microsoft
- Microsoft 365 Admin Center.
- Microsoft Entra ID.
- Microsoft Intune.
- Exchange Online.
- SharePoint Online.
- OneDrive.
- Microsoft Teams administration.
- Microsoft 365 Groups.
Identity & Access
- MFA.
- Conditional Access.
- SAML 2.0.
- OAuth 2.0.
- OpenID Connect.
- SSO.
- SCIM.
- RBAC.
- Privileged access concepts.
- User lifecycle management.
Endpoint
- Windows 10/11.
- Microsoft Intune.
- Windows Autopilot.
- BitLocker.
- Application packaging and deployment.
- Endpoint compliance.
- Windows Update management.
Security
- Hands-on experience with at least one of Sophos Central / Sophos Endpoint or Microsoft Defender for Endpoint.
- EDR and antivirus technologies.
- Endpoint hardening.
- Vulnerability management.
- Zero Trust principles.
- Security baselines.
- Incident handling.
Automation
- PowerShell.
- Microsoft Graph.
- Basic scripting and API concepts.
- Exposure to Zapier, Make, or n8n will be an advantage.
The candidate does not need to be a software developer but should have practical knowledge of scripting, APIs, automation, and system integration concepts.
Preferred Technical Skills:
- Microsoft Purview.
- Defender for Office 365.
- Defender for Identity.
- Entra ID P2.
- Privileged Identity Management.
- Windows Hello for Business.
- Azure Monitor / Log Analytics.
- SIEM concepts.
- Microsoft Sentinel.
- macOS management through Intune.
- MDM/MAM.
- DLP.
- Information classification.
Preferred Certifications:
- Microsoft 365 Certified: Administrator Expert.
- Microsoft Certified: Identity and Access Administrator Associate.
- Microsoft Certified: Endpoint Administrator Associate.
- Microsoft Certified: Security Operations Analyst.
- Microsoft Certified: Information Protection and Compliance Administrator.
- Equivalent Microsoft security certifications.
Certifications are desirable but should not substitute for hands-on technical ability.
Soft Skills:
- Strong analytical and troubleshooting skills.
- Systematic and process-oriented approach.
- Ability to independently troubleshoot identity and endpoint issues.
- Strong understanding of security and access implications.
- Ability to challenge insecure existing practices constructively.
- Strong documentation skills.
- Good communication with technical and non-technical stakeholders.
- Ability to coordinate effectively with vendors and consultants.
- Comfortable supporting a geographically distributed organization.
- Strong ownership and accountability.
- Ability to work independently in a hands-on engineering environment.
- Willingness to learn and continuously improve technical and security practices.