Overview
Operate, secure and continuously improve the Institute's Microsoft 365 platform across Exchange Online and hybrid Exchange, Proofpoint and Microsoft email security, Entra ID and Active Directory, Intune, Teams, SharePoint Online and OneDrive. Work within a multidisciplinary infrastructure team, report to the Manager IT Infrastructure Services, provide second- and third-level escalation, and support the platform on a swing shift.
What you'll do
- Administer Exchange Online and hybrid Exchange, including user, shared, resource and room mailboxes, permissions, delegation, archiving, retention and retained on-premises Exchange servers.
- Own mail flow, including connectors, accepted and remote domains, transport and journaling rules, message tracing, queue monitoring, delivery failures and non-delivery reports.
- Manage SPF, DKIM and DMARC, progress domains toward enforcing DMARC policy, and govern third-party sending services.
- Maintain hybrid coexistence and execute mailbox migration and consolidation with cutover planning, validation and rollback.
- Monitor service health and queues, respond to service advisories, and assess Microsoft changes and deprecations.
- Administer Proofpoint, Exchange Online Protection and Microsoft Defender for Office 365, including filtering, anti-phishing, anti-spam, safe links, safe attachments, quarantine, allow and block lists, and gateway routing.
- Investigate phishing, spoofing and business email compromise using message trace and header analysis, and coordinate with information security.
- Report on threat volume, quarantine activity, false positives and user-reported messages, and tune policy based on evidence.
- Administer Entra ID and on-premises Active Directory, including users, groups, administrative units, enterprise applications, single sign-on, app registrations, service principals, organizational units, Group Policy where applicable and directory hygiene.
- Manage hybrid identity synchronization, conditional access, MFA, authentication methods, privileged identity management and access reviews.
- Execute joiner, mover and leaver workflows, including account state, group membership, mailbox provisioning and licensing.
- Administer Intune, including enrolment profiles, device configuration and compliance policies, app protection policies, application deployment, update rings, Windows Autopatch where used, Autopilot and co-management with Configuration Manager.
- Maintain device compliance signaling into conditional access and coordinate shared tenant configuration with endpoint and Apple engineering teams.
- Administer Teams, SharePoint Online and OneDrive for Business, including governance, provisioning, permissions, sharing controls, storage quotas, lifecycle policies, external and guest access, meetings and calling policies, and Teams telephony where deployed.
- Resolve escalated meetings, file access and sharing issues and support business teams in adopting collaboration capabilities.
- Perform mailbox hygiene and cleanup, archive enablement, retention application, quota and growth management, orphaned and shared mailbox review, and deleted-item and mailbox recovery.
- Administer distribution lists, mail-enabled security groups and Microsoft 365 groups, including creation, membership, ownership, moderation, delivery restrictions and stale, ownerless or duplicate group review.
- Administer Microsoft 365 licenses, including SKU assignment, reclaim, assignment-error resolution and assigned-versus-consumed reporting.
- Execute leaver processing, including shared mailbox conversion, delegation, litigation or retention hold, OneDrive handover and scheduled removal.
- Fulfil service requests through the ITSM tool to agreed SLA and engage Microsoft and Proofpoint support where required.
- Develop PowerShell and Microsoft Graph automation for recurring administration, bulk change, reporting, distribution list updates, mailbox cleanup, licensing and joiner/leaver processing.
- Build scheduled reports on mailbox growth, license consumption, group hygiene, mail flow, threat volume, device compliance and identity hygiene.
- Administer Microsoft Purview capability in scope, including retention policies and labels, data loss prevention, eDiscovery and audit log search.
- Maintain runbooks and technical documentation, operate tested change control and rollback, and provide technical guidance and mentoring to less experienced engineers.
What you'll need
- Bachelor’s degree in computer science, Information Technology, Engineering or a closely related field, or equivalent professional experience.
- 7+ years of experience administering Microsoft 365 in an enterprise environment, including at least 4 years with substantial Exchange Online and hybrid Exchange responsibility.
- Hands-on ownership of hybrid mail flow, including connectors, transport rules, message tracing and delivery-failure resolution.
- Hands-on administration of Proofpoint or a comparable product such as Mimecast or Cisco Email Security, including policy, quarantine and URL and attachment defense.
- Experience implementing and operating SPF, DKIM and DMARC, including progression of a domain to an enforcing DMARC policy.
- Hands-on administration of Entra ID and on-premises Active Directory in a hybrid configuration, including Entra Connect or cloud sync, sync error resolution, conditional access and MFA.
- Hands-on administration of Microsoft Intune, including device configuration and compliance policies, application deployment and update rings.
- Administration of Microsoft Teams, SharePoint Online and OneDrive for Business, including governance, permissions and external sharing controls.
- Experience operating mailbox lifecycle administration at scale, including cleanup, archiving, quota management, shared mailbox conversion and leaver processing.
- Experience administering distribution lists, mail-enabled security groups and Microsoft 365 groups, including membership management and periodic hygiene review.
- Experience with Microsoft 365 license administration, including group-based licensing, SKU assignment and reclaim, and license reporting.
- Strong PowerShell scripting ability with practical use of Microsoft Graph for bulk administration, automation and reporting.
- Experience with Microsoft Purview in scope, including retention, data loss prevention, eDiscovery and audit log search.
- Experience supporting a globally distributed user base across multiple time zones from an offshore or global capability center.
- Professional proficiency in spoken and written English sufficient to support a multi-national user base and communicate with senior stakeholders.
Nice to have
- Certification such as Microsoft 365 Certified: Administrator Expert (MS-102), Messaging Administrator Associate (MS-203), Identity and Access Administrator (SC-300) or Endpoint Administrator Associate (MD-102).
- Experience in an environment subject to external audit, where messaging and collaboration controls must be evidenced rather than asserted.
- ITIL 4 Foundation, or equivalent demonstrated knowledge of incident, change and problem practice.
Details
- Location: GIA Services Private Limited, Navi, Mumbai.
- Work schedule: Swing shift.
- Reporting line: Manager IT Infrastructure Services.
- Provide second- and third-level escalation for complex messaging, identity and endpoint issues.
- Support a globally distributed user base across multiple time zones from an offshore or global capability center.
- Fulfil service requests through the ITSM tool to agreed SLA.
Read the full description and apply on the company’s own careers page.