Infrastructure Engineer — Identity, Office 365, Security & Cloud Platforms
Infrastructure & Cloud Engineer – Role Overview
This role sits within the Infrastructure team, supporting the identity, security, endpoint, messaging, Microsoft 365 and cloud platforms that underpin the wider IT estate. It is a platform-ownership and 3rd-line technical role, acting as the key escalation point for the Service Desk and owning complex issue resolution.
The role holder will have primary ownership of Conditional Access, cloud security investigations and breach response, CIS hardening, Microsoft Azure, Azure Virtual Desktop (AVD), SharePoint Online and Intune. The position combines deep technical troubleshooting, estate-wide platform ownership and infrastructure/security project delivery.
Key Responsibilities
1. Identity, Security & Compliance
- Administer the Microsoft 365 suite, including Exchange Online, Teams, SharePoint Online, OneDrive and security/compliance services.
- Own and maintain the Conditional Access policy estate across Active Directory/Entra ID, including policy documentation and secure management of exceptions.
- Lead cloud security investigations using sign-in, risk and audit logs.
- Own the Microsoft Defender estate, including XDR incidents, Defender for Office 365 policies, Defender for Endpoint onboarding/alerting and Defender for Identity sensor health.
- Run vulnerability scans and manage remediation plans across server and endpoint estates.
- Act as the primary technical owner for cloud security incidents and breach response.
- Maintain CIS hardening standards and track progress against security benchmarks.
- Resolve escalated identity issues including licensing, MFA and cross-tenant access.
- Administer on-premises Active Directory, including OU structure, Group Policy and Azure AD Connect/Entra Connect synchronisation, resolving sync issues between AD and Entra ID.
2. Azure, AVD & Microsoft 365 Administration
- Administer the Microsoft Azure environment, including subscriptions, resource groups, storage, networking and resource/cost management.
- Support and administer the Azure Virtual Desktop (AVD) estate, including host pools, session hosts, scaling, image management and application group assignments.
- Support legacy Amazon WorkSpaces where required as part of the migration to AVD.
- Administer SharePoint Online, including site structures, permissions, access groups, storage/quota management and governance of site sprawl.
- Monitor Azure, AVD/WorkSpaces and SharePoint health and capacity, coordinating patching and maintenance with minimal user disruption.
- Ensure identity, Conditional Access and licensing are correctly configured across platforms.
- Own infrastructure and security improvement projects, including rollouts, migrations, tooling, scoping and milestone reporting.
3. Endpoint, Messaging & 3rd-Line Support
- Own Intune device management and deployment, including enrolment profiles, compliance policies, configuration profiles and application packaging/deployment.
- Support SOTI configuration and deployment alongside Intune.
- Act as the technical escalation point for complex Service Desk issues requiring platform-level access, advanced diagnostics or architectural change.
- Resolve complex email delivery and rejection issues using Exchange Online and Mimecast message tracing.
- Troubleshoot advanced Outlook and mailbox issues, including profiles, permissions, access and delegation.
- Own and maintain branch/depot distribution lists and the wider mail estate structure, including group nesting to Manager and Assistant Manager level.
- Create and maintain Service Desk runbooks covering Azure, AVD/WorkSpaces, SharePoint, Intune and messaging, enabling routine issues to be resolved at first line.
General Responsibilities
- Represent the Company professionally and work in line with its values and ISO quality standards.
- Comply with all relevant Health & Safety requirements and use PPE where required.
- Provide flexibility to support critical security incidents and technical escalations outside normal working hours when necessary.
- Undertake other reasonable duties as required.
Key Working Relationships
Internal: Infrastructure Lead, Head of IT, Service Desk, HR, branch/depot managers and other key stakeholders.
External: Microsoft/Entra support, AWS support, Mimecast, security/compliance auditors and other technology partners.
Skills & Knowledge
- Strong hands-on experience with Microsoft 365, Active Directory, Entra ID, Conditional Access, SharePoint Online and Microsoft Defender/XDR.
- Experience investigating sign-in logs, risk events and audit logs.
- Proven experience contributing to or leading security incident and breach response.
- CIS hardening or equivalent security-baseline experience.
- Microsoft Azure administration, including subscriptions, resource groups, storage and networking.
- Strong Intune experience covering enrolment, compliance, configuration profiles and application deployment.
- PowerShell scripting and automation.
- AD/Entra group and attribute administration, including synchronisation.
- Advanced Exchange Online and email-security troubleshooting, including message tracing and delivery faults.
- Outlook/mailbox administration covering profiles, permissions and delegation.
- Experience creating clear technical runbooks and process documentation for Service Desk/1st-line teams.