M365 & Security Infrastructure Administrator

CV-LibraryLondonpermanentPosted: 28 September 2026
Apply Now
Alfa AI is a recruiting company advertising this vacancy on behalf of a customer.

Want to be the person who turns a cybersecurity strategy into a secure, automated Microsoft estate? This is a deep technical, hands-on role based in London on a hybrid basis. You will be the technical lead for our tenant's foundation, taking the "Why" from our Head of Cybersecurity and turning it into a concrete technical specification (the "What") and a deployment path (the "How").

We are moving away from ad-hoc, case-by-case management toward scalable, policy-driven operations built on modern Microsoft cloud administration principles. We need a proactive problem solver who puts long-term system integrity ahead of short-term fixes.

What you will do

* Identity and access (Entra ID): optimize structure with Administrative Units and scoped administration, run advanced Conditional Access, implement PIM for just-in-time access, govern service principals, managed identities and AI agent identities such as Copilot agents, and automate joiner/mover/leaver processes.

* Endpoint security (Intune): lead MDM and MAM across Windows, macOS, iOS and Android, maintain compliance policies, set up Windows Autopilot, macOS Automated Device Enrollment and Apple Business Manager, and harden endpoints with BitLocker, FileVault, Firewall and ASR rules.

* Platform hardening: maintain security baselines across Exchange Online, SharePoint, OneDrive, Teams, Viva and Copilot, secure mail flow and OME, audit SPF, DKIM and DMARC, tune anti-phishing, malware and DLP, and prevent configuration drift.

* Azure tenant governance: manage data residency (including AI/Copilot), RBAC, management groups and subscription governance, automating with Terraform and PowerShell so every change is version-controlled and documented.

* SharePoint and collaboration: deliver site templates and lifecycle, and control external sharing and guest access.

* Compliance and documentation: keep configurations audit-ready for GDPR, PCI and internal reviews, and maintain technical documentation for M365 and Intune.

* Reporting: define high-signal KPIs and build automated dashboards showing the health and security posture of the estate.

What you will bring

* Expert, hands-on Entra ID and Intune experience, including Conditional Access and Workload Identities

* Practical experience with PIM, Defender for Cloud Apps and AI/Copilot technical governance

* Deep Exchange Online knowledge: mail flow, transport rules, DMARC, DKIM and SPF

* Hands-on management of Windows 10/11, macOS, iOS and Android

* Proficiency with Terraform for automated tenant management

* Advanced administration of Exchange Online, SharePoint Online and Teams

* Experience translating frameworks such as NIST CSF and CIS into technical configurations

Nice to have

* Windows Autopilot and Apple Business Manager

* PowerShell automation across Intune and M365

* Microsoft Purview implementation

How you work

You bridge strategy and execution, fix root causes rather than symptoms, and automate by instinct. You stay current with Microsoft's evolving cloud and AI landscape, explain technical risk clearly to technical and non-technical stakeholders, and prove impact with data.

Why it matters

Your work will make every device accessing corporate data compliant, bring zero-touch provisioning to life, and keep the estate audit-ready at any time. Please note we are unable to offer visa sponsorship for this role

Similar Jobs

M365 & Security Infrastructure Administrator at CV-Library in London