IT Infra Engineer (Identity and Security)
About the job IT Infra Engineer (Identity and Security)
Key Responsibilities:
Identity & Access Governance
- Design and architect Entra ID (Azure AD) solutions, focusing on Conditional Accesspolicies, Privileged Identity Management (PIM), and Identity Protection to enforce least-privileged access.
- Manage complex Identity Lifecycle processes, ensuring seamless and secureintegration between on-premises Active Directory and cloud-native identity providers.
- Implement and maintain Passwordless authentication and Multi-Factor Authentication(MFA) strategies to eliminate credential-based vulnerabilities.
Security Engineering & Threat Protection
- Work with security team to engineer and operate the Microsoft Defender for Endpointand Defender for Office 365 suites (EPP/EDR) to proactively hunt for threats andremediate vulnerabilities across the fleet.
- Deploy and manage Microsoft Purview for information protection, Data Loss Prevention(DLP), and eDiscovery, ensuring sensitive corporate data remains governed andcompliant.
- Develop automated response playbooks using PowerShell and Microsoft Graph API toneutralize security incidents in real-time
Identity & Access Governance
- Design and architect Entra ID (Azure AD) solutions, focusing on Conditional Accesspolicies, Privileged Identity Management (PIM), and Identity Protection to enforce least-privileged access.
- Implement and maintain Passwordless authentication and Multi-Factor Authentication(MFA) strategies to eliminate credential-based vulnerabilities.
- Lead the identity and access design for enterprise-wide rollouts, ensuring robustauthentication mechanisms are baked into every deployment.
- Act as the primary technical liaison for Cybersecurity Audits, providing data-drivenevidence of compliance regarding identity lifecycles and access control.
- Mentor the team on security best practices, conducting knowledge-sharing sessions onthe latest Entra features and identity threat landscapes.
Automation & Observability
- Automation: Engineer for scalability by building reusable automation and utilizingPowerShell scripting and related tools like PowerBI, Dynatrace and Axonius to monitor
service health and reporting to derive insights.
- Scripting & API: Use PowerShell, Bash, and Python to automate repetitive tasks andinteract with the Microsoft Graph API for custom reporting.
- Fleet Analytics: Utilize KQL and Endpoint Analytics to monitor device health, batterywear, and application performance across the entire estate.
- Self-Service: Develop and maintain "Self-Service" portals for both staff and students toempower users and reduce helpdesk ticket volume.
General Responsibilities
- Engage stakeholders to translate business requirement into design and services to meetthe intended availability, capacity, resiliency, security and continuity requirements.
- Forecast budget needed to support the project initiatives and maintenance contracts.
- Ensure client's related Technical Architecture are in compliance with IM8 and Agency's ITPolicies and Standards.
- Manage day-to-day delivery and support of application infrastructure services andcollaborate with other government agencies and central services teams to facilitate anddeliver government-wide services.
Leadership & Strategic Compliance
- Lead the security design for enterprise-wide software rollouts, ensuring "Security by
- Design" is baked into every deployment.
- Act as the primary technical liaison for Cybersecurity Audits, providing data-drivenevidence of compliance with global security standards (e.g., ISO 27001, SOC2).
- Mentor the team on security best practices, conducting regular knowledge-sharingsessions on the latest M365 security features and threat landscapes.
What We Are Looking For:
- Identity Expertise: Technical mastery of both on-premises Active Directory and cloud-native Entra ID, including B2B/B2C scenarios, App Registrations, and EnterpriseApplications.
- Security Stack Mastery: Proven experience implementing the full Microsoft 365
- Defender suite and Microsoft Purview, encompassing DLP, EDR, EPP, and identitysecurity capabilities.
- Automation-First Mindset: Proficiency in PowerShell and MS Graph API forcomprehensive security and identity auditing, as well as automated threat remediation.
- Analytical Rigor: Ability to synthesize complex security and identity logs into actionablerisk recommendations for executive leadership.
- Preferred Certifications: SC-100 (Microsoft Cybersecurity Architect), SC-300 (MicrosoftIdentity and Access Administrator), MS-500 (Microsoft 365 Security Administration), andCISSP or an equivalent security-focused accreditation.
- Proactive and dedicated individual with good leadership and multi-tasking capabilitiesas well as the ability to work independently without the need for close supervision.
- Experienced in contract and vendor management.
- Good communication skills, both oral and written, with the ability to pitch ideas andcommunicate effectively with stakeholders.
- Team player with strong organization and people handling skills