Azure Responsibilities
- Design, implement and manage Azure
infrastructure, including landing zones, subscriptions and management groups,
virtual machines, storage, virtual networks, VPN and ExpressRoute connectivity,
Azure Firewall, load balancers and private endpoints. - Design, deploy and manage Azure application and
integration services, including Azure API Management (APIM) for publishing,
securing and monitoring APIs; Azure Application Gateway with Web Application
Firewall (WAF) and Azure Front Door for secure application delivery; and Azure
App Service, Azure Functions and Logic Apps for hosting web applications, APIs
and integrations. - Configure and manage supporting platform
services, such as Azure SQL Database, Azure Container Apps or Azure Kubernetes
Service (AKS), Azure Service Bus and Azure Cache for Redis, including scaling,
custom domains, TLS certificates, VNet integration and private access. - Implement Azure governance using Azure Policy,
role-based access control (RBAC), resource tagging and naming standards, in
line with their and UAE Government cloud requirements. - Automate provisioning and configuration using
Infrastructure as Code (Bicep, ARM templates or Terraform) and scripting
(PowerShell, Azure CLI). - Implement backup, disaster recovery and high
availability using Azure Backup, Azure Site Recovery and availability zones,
and take part in periodic recovery testing. - Monitor performance, availability and cost using
Azure Monitor, Log Analytics and Microsoft Cost Management, and implement cost
optimization measures such as right-sizing, reservations and savings plans. - Secure the Azure environment using Microsoft
Defender for Cloud, Azure Key Vault, network security groups and secure score
recommendations.
Microsoft 365 and Identity
- Administer Microsoft 365 services, including
Exchange Online, SharePoint Online, OneDrive, Microsoft Teams and Microsoft 365
Apps, including tenant configuration, licensing and service health.
Microsoft Intune and Endpoint Management
- Manage Windows, macOS, iOS and Android devices
through Microsoft Intune, including enrollment, configuration profiles,
compliance policies and security baselines. - Implement Windows Autopilot for zero-touch device provisioning, and manage application packaging and deployment (Win32,
Microsoft Store, line-of-business apps). - Manage Windows Update for Business, update rings
and driver and feature updates, and support co-management with Configuration
Manager (SCCM) where applicable. - Implement mobile application management (MAM)
and app protection policies for bring-your-own-device (BYOD) scenarios, and
integrate Intune with Microsoft Defender for Endpoint.
Virtual Desktop Infrastructure (VDI)
- Design, deploy and manage virtual desktop
environments using Azure Virtual Desktop and/or Windows 365, including host
pools, application groups, workspaces and session hosts. - Manage golden images, FSLogix profile
containers, MSIX app attach, autoscaling plans and user experience
optimization, including Microsoft Teams optimization. - Monitor VDI performance, capacity and user experience
using Azure Virtual Desktop Insights, and troubleshoot connectivity
and session issues. - Support existing or legacy VDI platforms (e.g.,
Citrix, VMware Horizon) and plan migrations to Azure-based solutions where
appropriate.
General
- Act as the escalation point for complex
incidents, problems and changes related to Azure, Microsoft 365, Intune and
VDI, in line with their IT service management processes. - Evaluate the Microsoft roadmap and new features,
and recommend improvements to architecture, security and user experience. - Generate periodic reports on platform health,
availability, capacity, security posture (e.g., Secure Score, device
compliance), license usage and cloud costs for management. - Maintain up-to-date architecture diagrams,
configuration documentation, runbooks and standard operating procedures. - Ensure compliance with information security policies and applicable UAE and Dubai Government regulations, including DESC requirements and
healthcare data protection rules.
2. Qualifications and Experience
- Bachelor's degree in Information Technology, Computer Science or a related field.
- [7-10] years of experience in Microsoft infrastructure, including at least [5] years with Azure and Microsoft 365 in an enterprise environment.
- Proven experience designing and operating Azure infrastructure, networking, identity and security at scale.
- Hands-on experience with Azure PaaS and application delivery services, including API Management, Application Gateway (WAF), Front Door, App Service and Azure Functions.
- Strong hands-on experience with Microsoft Intune, Windows Autopilot and modern endpoint management.
- Hands-on experience deploying and managing Azure Virtual Desktop and/or Windows 365.
- Proficiency in PowerShell and Infrastructure as Code (Bicep, ARM or Terraform); experience with Azure DevOps or GitHub Actions is an advantage.
- Good understanding of Zero Trust principles, Microsoft security solutions and cloud security best practices.
- Experience with hybrid environments, including on-premises Active Directory, Windows Server and Configuration Manager.
- Experience in healthcare or government environments is preferred.
3. Preferred Certifications
- Microsoft Certified: Azure Solutions Architect Expert (AZ-305) and Azure Administrator Associate (AZ-104)
- Microsoft Certified: Azure Virtual Desktop Specialty (AZ-140)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500) and/or Identity and Access Administrator Associate (SC-300) (advantageous)
- Strong analytical and troubleshooting skills
- Architecture and solution design thinking
- Security-first and automation-first mindset
- Stakeholder management and ability to explain technical topics to non-technical audiences
- Clear written and verbal communication in English (Arabic is an advantage)
- Commitment to continuous learning as Microsoft cloud services evolve