Level 3 M365 Engineer
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
By continuing, you agree to our Terms & Privacy Policy.
Job Description
Role Purpose
The Microsoft 365 (M365) Engineer is a hands-on engineering role that helps build, migrate, and operate the Microsoft 365 and Microsoft Entra ID environment as Nexgen transitions off its incumbent managed service provider into its own dedicated tenant.
Early in the programme, the role builds familiarity with the new tenancy and helps develop the IT operatingprocedures alongside the Principal M365 Consultant, then delivers the hands-on migration before moving into business-as-usual operation, hardening and support.
Because the team is small, the role is deliberately broad and helps cover the parallel security and platform functions, including administration of the Nexgen Microsoft Dynamics 365 environment, alongside its primary Microsoft discipline.
Key Responsibilities
- Support the build and configuration of the greenfield Microsoft 365 and Microsoft Entra ID tenant withthe Principal M365 Consultant, covering Exchange Online, SharePoint Online, OneDrive, Microsoft Teams, Microsoft Intune and Microsoft Defender.
- Plan and execute the migration of mailboxes, files, collaboration content, Power Platform and Power BI workloads off the incumbent tenant into the Nexgen tenant.
- Manage Microsoft Entra ID for identity, single sign-on (SSO) and Conditional Access, implement phishing-resistantmulti-factor authentication (MFA), and run Privileged Identity Management (PIM) using Microsoft Entra ID P2 add-on licensing.
- Manage the fleet as Microsoft Entra ID joined and Microsoft Intune managed, retiring remaining Windows 10 devices and enrolling workstations into the Nexgen tenant, applying Centre for Internet Security (CIS) and ACSC Essentials hardening baselines.
- Operate the endpoint protection platform (Microsoft Defender for Endpoint or CrowdStrike) and application control, restoring devices to full reporting coverage.
- Onboard remaining non-single sign-on applications to Microsoft Entra ID and roll out Microsoft Purview sensitivity labelling and Data Loss Prevention (DLP) across Microsoft 365.
- Provide day-to-day administration of Microsoft Dynamics 365, including user onboarding and licence assignment, security roles, security groups, and record and field-level permissions (administrative configuration and access management, not Dynamics development or customisation).
- Develop and maintain IT operations runbooks for the new environment, and provide day-to-day Microsoft 365 administration and end-user support after migration.
Parallel and Cross-Functional Responsibilities
- Produce evidenced Essential Eight (Level 1) and Centre for Internet Security (CIS) self-assessments for the endpoint fleet.
- Deliver backup and disaster recovery independence for Microsoft 365, covering tenant configuration through Desired State Configuration (DSC) and immutable data backups.
- Administer the Power Platform, applying data loss prevention and tenant isolation to Power Apps, Power Automate and Power BI workspaces.
- Provide endpoint and identity telemetry to the Security Operations Engineer and the Security Operations Centre (SOC) to support detection and response.
Technical Environment
- Microsoft 365 (E3 licensing with add-ons), Microsoft Entra ID with P2 for PIM, and Microsoft Intune for device management.
- Microsoft Defender for Endpoint or CrowdStrike for endpoint protection, with application control as the incumbent whitelisting tool.
- Microsoft Purview for classification, labelling and data loss prevention, and Microsoft 365 Desired State Configuration for tenant configuration management.
- Microsoft Dynamics 365 line of business applications, administered through the Power Platform admin centre, with access and permissions managed via Microsoft Entra ID security groups and Dynamics 365 security roles.
- Cloud-only Microsoft Entra ID hardened to the Australian Signals Directorate (ASD) Blueprint for Secure Cloud, feeding endpoint and identity telemetry to the Nexgen Security Information and Event Management (SIEM) platform.
Qualifications and Requirements
Required Skills and Experience
- Four or more years administering Microsoft 365 and Microsoft Entra ID (Azure AD), including Exchange Online, SharePoint Online, OneDrive and Microsoft Teams in a production environment.
- Strong Microsoft Entra ID experience covering Conditional Access, Multi-Factor Authentication (MFA), SSO and Privileged Identity Management.
- Practical Microsoft Intune experience enrolling and managing Microsoft Entra ID joined Windows 11 devices with compliance and configuration policies.
- Experience operating an endpoint protection platform and application control, and supporting endpoint telemetry.
- Scripting and automation with PowerShell and the M