
Microsoft 365 Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Europe.
• Take charge of the company's identity provider, overseeing authentication, access grants, reviews, and revocation.
• Manage Microsoft Entra ID and Microsoft 365 users, groups, directory roles, service principals, workload identities, licensing, tenant settings, and admin roles.
• Create and implement Conditional Access policies and authentication methods, incorporating phishing-resistant factors.
• Facilitate the onboarding of applications using SAML 2.0, OIDC, and OAuth 2.0.
• Oversee app registrations, permissions, admin consent, secrets, and certificates management.
• Set up SCIM 2.0 provisioning, including attribute mappings, transformations, reconciliation, and remediation.
• Automate the joiner-mover-leaver lifecycle processes, licensing, and session/token revocation.
• Ensure least-privilege administration by managing RBAC, PIM, access reviews, and entitlement management.
• Supervise service accounts and workload identities, focusing on ownership, credential rotation, permission scoping, and decommissioning.
• Troubleshoot Microsoft 365 access and permission issues across Exchange Online, SharePoint Online, and Power Platform.
• Analyze sign-in, audit, and provisioning logs utilizing Log Analytics and KQL.
• Manage cross-tenant access settings and facilitate B2B external collaboration.
• Develop production-grade automation using Microsoft Graph, Google APIs, PowerShell, Azure Automation, Logic Apps, or Power Automate.
• Act as the escalation point for identity incidents, resolving issues for operations, security, service desk, and application teams.
• Minimum of 3 years of experience administering Microsoft Entra ID in a production environment as a primary responsibility.
• Proficiency in Microsoft 365 tenant administration, covering settings, licensing, admin roles, and Service Health.
• Experience with Exchange Online, including mailbox permissions, groups, mail flow, and SPF/DKIM/DMARC.
• Familiarity with Microsoft Defender, focusing on threat policies, quarantine, and message tracing.
• Knowledge of Power Platform, including environments, DLP connector policies, and maker access.
• PowerShell experience with the Exchange Online module and Microsoft Graph SDK.
• Background in enterprise applications, app registrations, consent and permission models, and automated provisioning processes.
• Experience with Azure Automation Runbooks, Azure Logic Apps, Power Automate, or similar platforms.
• Understanding of least privilege principles, secure administration, and change management.
• Strong documentation discipline for configurations.
• Proficient in written and spoken English at a B2 level or higher.
• Applicants must have authorization to work in the country they are applying to and provide proof of employment eligibility as a condition of hire.
• Competitive compensation.
• Opportunities for career growth and professional development.
• Flexibility and a sense of ownership in your work.
• A collaborative and innovative work culture.
• Chance to engage in impactful AI projects.
• An international environment with talented teams.
Unisys
Artemys
Energy AS
Dataminr
Get handpicked remote jobs straight to your inbox weekly.