Overview
Operate, secure and continuously improve the Institute's Microsoft 365 platform across Exchange Online and hybrid Exchange, Proofpoint and Microsoft Defender for Office 365, Entra ID and Active Directory, Intune, Teams, SharePoint Online and OneDrive. Act as a second- and third-level escalation point, automate recurring administration, manage service change and document the platform while reporting to the Manager IT Infrastructure Services.
What you'll do
- Administer Exchange Online and hybrid Exchange, including user, shared, resource and room mailboxes, permissions, delegation, archiving, retention and retained on-premises Exchange servers.
- Own end-to-end mail flow, including connectors, accepted and remote domains, transport and journaling rules, message tracing, queue monitoring, delivery failures and non-delivery reports.
- Manage SPF, DKIM and DMARC, progress domains toward enforcing DMARC policy and govern third-party sending services.
- Maintain hybrid coexistence, directory and free/busy interoperability, cross-premises mail flow and hybrid configuration; execute mailbox migration and consolidation with cutover planning, validation and rollback.
- Monitor service health and message queues, respond to Microsoft service advisories and assess releases and deprecations against the tenant configuration.
- Administer Proofpoint, including policy routes, filtering, spam policy, allow and block lists, URL and attachment defense, quarantine and end-user digests.
- Administer Exchange Online Protection and Microsoft Defender for Office 365, including anti-phishing, anti-spam, Safe Links, Safe Attachments and quarantine.
- Maintain gateway-to-Exchange Online routing, connector restriction and IP allow-listing so mail cannot bypass the gateway.
- Investigate phishing, spoofing and business email compromise through message tracing and header analysis; release or purge messages and coordinate with information security.
- Report on threat volume, quarantine activity, false positives and user-reported messages, and tune policy based on evidence.
- Administer Entra ID users, assigned and dynamic groups, administrative units, enterprise applications, single sign-on, app registrations and service principals.
- Administer on-premises Active Directory, including organizational units, group structure, applicable Group Policy and directory hygiene.
- Manage hybrid identity synchronization, sync scope and filtering, attribute flow, sync and duplicate-attribute errors, and deployed password hash sync, pass-through authentication or federation.
- Administer conditional access, multifactor authentication and authentication methods, and support privileged identity management and access reviews with information security.
- Execute the identity side of joiner, mover and leaver workflows, including account state, group membership, mailbox provisioning and license consequences.
- Administer Intune enrolment profiles, device configuration and compliance policies, app protection policies and application deployment.
- Maintain Windows baselines, update rings, feature and quality update policies and Windows Autopatch where used, and report compliance.
- Maintain device compliance signaling into conditional access.
- Support Windows Autopilot provisioning and Configuration Manager co-management where in place.
- Coordinate shared Intune tenant configuration with endpoint and Apple engineering teams.
- Administer Teams, including team and channel governance, messaging, meeting and calling policies, external and guest access, and Teams telephony where deployed.
- Administer SharePoint Online and OneDrive for Business, including site provisioning, permissions, sharing controls, storage quotas and lifecycle policy.
- Maintain collaboration governance, including naming standards, provisioning workflow, external sharing posture and inactive team and site lifecycle.
- Resolve escalated meeting, file access and sharing issues and support business teams adopting collaboration capability.
- Perform scheduled mailbox hygiene and cleanup, including oversized and inactive mailboxes, archive enablement, retention, quota and growth management, orphaned and shared mailbox review, and deleted-item and mailbox recovery.
- Administer distribution lists, mail-enabled security groups and Microsoft 365 groups, including creation, membership, ownership, moderation, delivery restrictions and stale, ownerless or duplicate group review.
- Administer Microsoft 365 licenses, including SKU assignment, reclaim, assignment-error resolution and assigned-versus-consumed reporting.
- Execute leaver processing for messaging and collaboration, including shared mailbox conversion, delegation, litigation or retention hold, OneDrive handover and scheduled removal.
- Fulfil messaging, identity and collaboration requests through the ITSM tool to agreed SLA, escalate complex issues and engage Microsoft and Proofpoint support where required.
- Develop and maintain PowerShell and Microsoft Graph automation for recurring administration, bulk change, reporting, distribution list updates, mailbox cleanup, license assignment and joiner and leaver processing.
- Build scheduled reports on mailbox size and growth, license consumption and reclaim, group and distribution list hygiene, mail flow and threat volume, device compliance and identity hygiene.
- Administer Microsoft Purview capability in scope, including retention policies and labels, data loss prevention, eDiscovery and audit log search, and maintain compliance evidence.
- Maintain runbooks and technical documentation, operate tested change control and rollback, and provide technical guidance and mentoring to less experienced engineers.
What you'll need
- Bachelor's degree in computer science, Information Technology, Engineering or a closely related field, or equivalent professional experience.
- 7+ years of experience administering Microsoft 365 in an enterprise environment, including at least 4 years with substantial Exchange Online and hybrid Exchange responsibility.
- Hands-on ownership of hybrid mail flow, including connectors, transport rules, message tracing and delivery-failure resolution.
- Hands-on administration of Proofpoint or a comparable enterprise email security gateway such as Mimecast or Cisco Email Security, including policy, quarantine, and URL and attachment defense.
- Experience implementing and operating SPF, DKIM and DMARC, including progression of a domain to an enforcing DMARC policy.
- Hands-on administration of Entra ID and on-premises Active Directory in a hybrid configuration, including Entra Connect or cloud sync, sync error resolution, conditional access and MFA.
- Hands-on administration of Microsoft Intune, including device configuration and compliance policies, application deployment and update rings.
- Administration of Microsoft Teams, SharePoint Online and OneDrive for Business, including governance, permissions and external sharing controls.
- Experience operating mailbox lifecycle administration at scale, including cleanup, archiving, quota management, shared mailbox conversion and leaver processing.
- Experience administering distribution lists, mail-enabled security groups and Microsoft 365 groups, including membership management and periodic hygiene review.
- Experience with Microsoft 365 license administration, including group-based licensing, SKU assignment and reclaim, and license reporting.
- Strong PowerShell scripting ability with practical use of Microsoft Graph for bulk administration, automation and reporting.
- Experience with Microsoft Purview in scope, including retention, data loss prevention, eDiscovery and audit log search.
- Experience supporting a globally distributed user base across multiple time zones from an offshore or global capability center.
- Professional proficiency in spoken and written English sufficient to support a multinational user base and communicate with senior stakeholders.
Nice to have
- Certification such as Microsoft 365 Certified: Administrator Expert (MS-102), Messaging Administrator Associate (MS-203), Identity and Access Administrator (SC-300) or Endpoint Administrator Associate (MD-102).
- Experience in an environment subject to external audit, where messaging and collaboration controls must be evidenced rather than asserted.
- ITIL 4 Foundation, or equivalent demonstrated knowledge of incident, change and problem practice.
Details
- Location: GIA Services Private Limited (Navi, Mumbai).
- Day shift.
- Reports to the Manager IT Infrastructure Services.
- Provides second- and third-level escalation for complex messaging, identity and endpoint issues.
Read the full description and apply on the company’s own careers page.