3rd Line Support Engineer
IT Service Desk – 3rd Line Engineer
Reports To: 3rd Line Team Leader (Head of IT Infrastructure)
Location: Wilmslow / Hybrid / Remote
Hours of Work: Mon–Fri, staggered start/finish times between 8am and 6pm. Occasional work outside these hours may be required to support change windows or incidents; TOIL applies.
The Role
The IT Service Desk is the single point of contact for all IT services, requests, and incidents. It's a busy, dynamic, fast-paced team supporting Citation Group's multiple business units across the UK, Canada, and Australia.
As a member of the 3rd Line Team, you will be responsible for building, managing, and maintaining company infrastructure across a multi-tenant, multi-country Microsoft 365 and Azure environment. The role of the IT Support team is to ensure colleagues have the technology they need to achieve business objectives — whether in the office or working remotely.
Alongside day-to-day ticket resolution, you'll work on infrastructure projects and change initiatives — from platform migrations to identity and security improvements — balancing planned project work with reactive support.
We're looking for customer-focused engineers to join our IT department, supporting colleagues both in the office and remotely across the UK (and coordinating with Canada/Australia counterparts).
This role suits someone with 3+ years of experience in a similar role.
Duties
Include but not limited to:
- 3rd line support of technology-related incidents within agreed SLAs
- Contributing to infrastructure projects and change initiatives alongside day-to-day ticket work
- Resolution of escalated colleague service requests or incidents as assigned within SLA, logged and tracked via service desk
- Building, configuring, and maintaining Azure infrastructure — virtual machines, networking, storage, and app services
- Supporting Azure governance activities — naming/tagging standards, Azure Policy, RBAC, and PIM
- Performing systems administration activities such as performance tuning and data management across Azure and on-prem infrastructure
- Managing identity and access — user/group administration, Conditional Access policies, and enterprise application configuration in Entra ID
- Monitoring and reviewing quality of service delivered
- Remediating vulnerability findings (patching, configuration fixes, closing out scan results) across networks, systems, and applications
- Planning, implementing, and optimising cloud and on-prem data storage technologies
- Installing, managing, controlling, deploying, and maintaining infrastructure systems software to meet operational needs and service levels
- Installing and testing, or decommissioning and removing, systems or system components
- Supporting device provisioning and lifecycle management, including Windows and Cloud PC (Windows 365) estates
- Raising and documenting changes in line with the change management process (standard/normal/emergency changes)
- Producing and maintaining system, solution, and knowledge base documentation
- Liaising with 3rd party suppliers
- Travel to other offices as and when required
Skills
- 3+ years' experience in Microsoft Azure infrastructure and/or Entra ID identity & access administration (other specialist areas below are an advantage, not a substitute)
- Strong communication and customer service skills, putting colleagues at the heart of everything you do
- Proven organisational skills with good attention to detail
- Comfortable balancing planned project work with reactive incident/ticket demands
- Clear, thorough approach to documenting changes and solutions for others to follow
- Ability and desire to learn about the systems we support
- Ability to prioritise your own workload and manage expectations
Qualifications / Certifications (Preferred)
- ITIL Foundation
- AZ-104 — Microsoft Azure Administrator
- SC-300 — Microsoft Identity and Access Administrator
- Other relevant Microsoft or specialist certifications (e.g. AZ-500, MS-102)
Technologies & Specialisms
Knowledge and experience in several of the following is preferred.
Cloud — Microsoft Azure
- Virtual machines, storage accounts, and app services
- Networking — hub-and-spoke topology, private endpoints, DNS
- Governance — naming/tagging standards, Azure Policy, Management Groups
- Identity & access — RBAC, Privileged Identity Management (PIM), managed identities
- Key Vault and secrets management
- Backup and patching (Azure Update Manager)
Microsoft Based Technologies
- Windows Platforms – Windows 10, 11, Server 2016+
- Active Directory, Entra ID, PowerShell
- Entra ID — Conditional Access, Enterprise Applications, SSO, identity and access management (IAM)
- M365 – Exchange, Teams, SharePoint/OneDrive
- Intune Endpoint Manager
- Windows 365 / Azure Virtual Desktop (AVD)
Network & Security
- Cisco Meraki Firewalls, Switches and APs
- LAN, WLAN, DNS, VPN
- Cloudflare
Telephony
- Experience with cloud telephony platforms (e.g. RingCentral, Vonage, Amazon Connect) is beneficial but not a primary focus of the role
- MS Teams
- Mobile devices – iPhone, iPad