Objectives and Responsibilities of the Senior Microsoft 365 & Messaging Infrastructure Architect
We are seeking a highly experienced Senior Microsoft 365 & Messaging Infrastructure Architect responsible for enterprise-wide Microsoft 365 operations, identity lifecycle management, email security, SSO integrations, and hybrid infrastructure governance. The role demands deep technical expertise across M365, Email Gateway, SSO, DNS, Certificates, and Security platforms.
Primary Technology Stack
Microsoft 365 / Office 365 Infrastructure & Open Office / Zoho Office (Advantage)
- Enterprise administration of Microsoft 365
- Identity lifecycle: ID creation / deletion / modifications
- License management & optimization
- Mailbox restoration & recovery
- DL & Security group administration
- Exchange Online health monitoring & log analysis via Exchange Online
- Transport rules as per business requirements
- Litigation hold, retention, archiving & deletion policies
- Monthly audit reporting (OWA, ActiveSync, POP, IMAP enabled mailboxes)
- Email migrations (On-prem - Cloud)
SharePoint, OneDrive & Teams
- Administration of SharePoint Online & OneDrive
- Site & portal creation and governance
- Retention & compliance policies
- Administration of Microsoft Teams (Teams governance, policies, integrations)
- Live Townhall / Board meetings (Webcast management)
Identity & Access Management (IAM)
- Enterprise administration of Microsoft Entra ID
- Conditional Access policy design & enforcement
- Directory Sync server management
- SSO, MFA, and SSPR governance
- Domain & identity reconsolidation programs
- Application SSO integration (SaaS-based apps)
Security, Compliance & Data Protection
- Administration of Azure Information Protection & RMS
- Mobile Device Management (iOS & Android)
- Office 365 Audit log & alert monitoring
- Security rule creation & access restriction frameworks
- Certificate Authority & certificate deployment for application servers
Email Gateway & Threat Protection
- Management of Mimecast Email Security
- Malware, phishing, spoofing & zero-day protection (ATP)
- SMTP relay (On-Prem & Cloud)
- Email DLP rule configuration per business process
- Email restriction & policy governance
- SPF, MX, DKIM, A, and CNAME record management
Infrastructure & Supporting Platforms
- AD server patch management
- Certificate Authority server management
- DNS management via Amazon Route 53
- SFTP Server administration
- ManageEngine tools:
- ManageEngine ADAudit Plus
- CASB platform administration
- Integration and governance of:
- Zoom
- TEAMS
- Microsoft Teams Rooms (MTR) integration with Telepresence
- Executive live webcast & townhall event technology management
Key Responsibilities
- Own end-to-end M365 tenant health & security posture
- Define governance model for Identity & Collaboration
- Perform compliance & audit readiness activities
- Lead migrations, domain consolidation & modernization initiatives
- Optimize licensing & cost management
- Monitor zero-day threats & email attack surface
- Provide monthly executive reports (security, mailbox usage, protocol exposure)
Qualifications:
- Degree in Computer Science, Engineering, or a related field.
- 12 - 15 years of Microsoft365 architecture experience
- Expertise in windows PowerShell scripting
- Expert in Conditional access, App protection, and Defender cloud app Security,
- Advance knowledge of Microsoft Graph API, Power app, and automation
- Experience with Intune Endpoint Management for iOS | Windows
- Expert knowledge of Microsoft graph API, Power app, and automation