Responsibilities
Exchange
Online, email security and delivery
- Manage Exchange Online, including hybrid
- Exchange, mail flow, connectors and migrations.
- Configure email security: SPF, DKIM, DMARC,
- Defender for Office 365 and anti-phishing policies.
- Own resolution of email delivery issues: bounces and NDRs, delayed or missing mail, messages wrongly sent to junk or quarantine, and inbound/outbound blocking.
- Investigate with message trace, message headers, quarantine and Exchange admin center reports.
- Monitor sender reputation and handle blocklist delisting (e.g. Microsoft, Spamhaus) and third-party mail gateway or relay issues.
- Manage DNS records for mail (MX, SPF, DKIM, DMARC, Autodiscover) and review DMARC reports to prevent spoofing and delivery failures.
Teams,
SharePoint and OneDrive
- Administer Teams, including policies, governance, Teams Phone and meeting rooms.
- Design SharePoint Online and OneDrive structure, permissions, sharing and lifecycle policies.
Security
policies, identity and compliance
- Design, implement and maintain Microsoft 365 security policies aligned to Microsoft and CIS security baselines.
- Configure Defender for Office 365 policies: Safe Links, Safe Attachments, anti-phishing, anti-spam and anti-malware.
- Enforce Conditional Access policies: MFA for all users, blocking legacy authentication, and location and device-compliance rules.
- Set external sharing, guest access and Teams/SharePoint security policies.
- Configure audit logging, alert policies and app protection policies for Outlook and Teams on mobile devices.
- Administer Entra ID: hybrid identity (Entra Connect), Conditional Access, MFA and PIM.
- Implement Microsoft Purview: data loss prevention, sensitivity labels, retention and eDiscovery.
- Monitor and improve Microsoft Secure Score and respond to security alerts.
Operations
- Automate administration and reporting with PowerShell and Microsoft Graph.
- Manage licences, service health, change management and vendor support cases.
- Keep documentation, runbooks and user guidance up to date.
Required Qualifications
- 7+ years in Microsoft infrastructure, including 5+ years administering Microsoft 365 at enterprise scale (1,000+ users).
- Proven experience leading Exchange and tenant-to-tenant migrations.
- Deep knowledge of Exchange Online, Teams, SharePoint Online and OneDrive.
- Strong Entra ID, Conditional Access and hybrid identity experience.
- Hands-on experience with Purview compliance and Defender for Office 365.
- Strong PowerShell skills, including Microsoft Graph.
- Experience leading projects, mentoring engineers and working with senior stakeholders.
- Proven track record troubleshooting complex email delivery issues using message trace, headers, NDR codes and DNS mail records.
- Hands-on experience designing and implementing Microsoft 365 security policies (Defender for Office 365, Conditional Access, sharing and audit policies) in an enterprise tenant.
Preferred Qualifications
Area Certification
Microsoft 365
MS-102
Microsoft 365 Administrator Expert
Teams
MS-700
Teams Administrator
Identity
SC-300
Identity and Access Administrator
Security / compliance
SC-401
Information Security Administrator, or SC-200