HamburgerMenu
hirist

IT Support Specialist - Cloud & Identity Administration

Hy: Tech & Consulting
3 - 6 Years
rupee18-22 LPA
Multiple Locations

Posted on: 17/09/2026

Job Description

SUPPORT SPECIALIST, IT

TIER 3 | US SHIFT | CLIENT DELIVERY

Location : Remote

Shift : US business hours.

Team : Client delivery - IT infrastructure and endpoint operations

Work tracking : DevStride (work items, sub-tasks, daily time logging)

About The Role :


The Tier 3 Support Specialist is the escalation point in our Integrated Support value stream, the person a problem reaches when Tier 1 and Tier 2 have run out of road. You own incidents end to end, you resolve the cause rather than the symptom, and you speak to the Client directly rather than through a handler.

The work splits roughly in half. One half is a live queue: user account setup, access problems, endpoint and application failures, and email security incidents, all arriving by email, becoming work items in DevStride, and needing resolution while the Client waits. The other half is standing work that never arrives as a ticket: vulnerability remediation cycles, encryption and migration projects, security awareness training, weekly reporting, and the root-cause work that stops the same ticket coming back a third time. You are also exceptional at doing support work with AI. You treat AI tooling as a force multiplier, using it to investigate faster, draft cleaner Client communication, and script away the repetitive parts, while keeping a senior engineer's judgment firmly in the loop. You know what good output looks like, you know when the AI is wrong, and you act on work you'd put your name on.

You hold admin credentials in production Microsoft 365, Azure and AWS tenants belonging to Clients in regulated industries.

What You Will Be Doing :


1. Client Support Queue :

- Own the inbound support queue end to end: triage, resolve, document and close.

- Troubleshoot directly with client staff through email, Microsoft Teams and screen sharing, including senior stakeholders.

- Schedule troubleshooting calls when issues cannot be resolved efficiently through email.

- Resolve sign-in and MFA failures, mailbox and Outlook issues, OneDrive synchronization and permissions problems.

- Troubleshoot printing, peripherals and desktop application issues.

- Handle laptop and hardware issues through replacement, setup and handover.

- Provide clear, professional and client-ready communication throughout the support lifecycle.

2. Endpoint & Vulnerability Management :


- Work the Microsoft Defender for Endpoint queue, including new CVE notifications and verified exploit alerts.

- Perform vulnerability remediation and follow through to closure.

- Patch third-party software across Windows 365 Cloud PCs and RDS session hosts, including browsers, runtimes, remote access agents and Office add-ins.

- Manage devices through Microsoft Intune, including :

1. Configuration profiles

2. Compliance policies

3. Application deployment

4. Group membership

5. Detection scripts

6. Remediation scripts

- Run fleet-wide security initiatives such as BitLocker encryption rollouts, including key custody.

- Track remediation machine by machine so closure evidence is complete and defensible to the client.

3. Cloud & Identity Administration :


- Microsoft 365 & Entra ID :

1. Manage Microsoft 365 licensing and groups.

2. Administer Conditional Access policies.

3. Manage Exchange Online and shared mailboxes.

4. Manage SharePoint and OneDrive permission structures.

5. Troubleshoot identity and access issues.

- AWS IAM :

1. Create and scope AWS users and roles.

2. Write and review IAM policy documents.

3. Apply least-privilege principles.

4. Understand permissions and identify excessive write access.

- Support services including :

1. EKS

2. ECR

3. CloudWatch

4. S3

5. Bedrock

- Azure :

1. Support Windows 365.

2. Manage and troubleshoot Azure Virtual Machines.

3. Triage Azure Monitor alerts.

4. User Accounts & Access Management :


- User accounts and access management are one of the highest-volume responsibilities in this role.

- User Onboarding :

1. Build new user accounts end to end, including Microsoft 365 mailbox and licensing, Cloud PC or device assignment, group and distribution list membership, application access, MFA enrollment, and secure credential handover.

- Access Troubleshooting :

1. Resolve access problems across Microsoft 365, AWS, RDS session hosts, SharePoint, OneDrive, and line-of-business applications.

2. Handle issues such as account lockouts, MFA re-registration, Authenticator migrations, expired credentials, permission gaps, and licensing mismatches.

- Offboarding & Access Reviews :

1. Offboard users cleanly across Microsoft 365, 1Password, GitHub, Notion and related tooling.

2. Maintain evidence that access has been revoked.

3. Run periodic access reviews.

4. Maintain defensible records of who has access to what and why.

- Handle secrets securely :

1. Access keys, recovery keys and passwords must be stored in the approved secret store and shared through it - never pasted into chat or email.

5. Email Security & Security Awareness :


- Administer the email security platform, such as Ironscales.

- Review and classify reported messages.

- Identify and act on genuine phishing attempts.

- Release false positives.

- Tune security policies as threat patterns change.

- Run and maintain the monthly security awareness training program.

- Set up campaigns and track completion.

- Follow up with users who have not completed training.

- Triage suspicious notifications and bulk-deletion alerts.

- Explain security findings to users in clear, actionable language.

- Support client audit and compliance requests with documented evidence.

6. Reporting & Delivery Hygiene :


- Produce weekly Cloud PC and storage reports.

- Maintain the monthly security awareness training cycle.

- Maintain DevStride work items and sub-tasks.

- Keep work status updated.

- Log time accurately on a daily basis.

- Attend daily stand-ups and task reviews during the US shift.

- Write status comments that clients can understand without translation.

- Keep runbooks current.

- Escalate early when an issue is outside your remit or approaching client impact.

What We Need You To Bring :


Core Support Skills - Required :


- 3+ years of experience in IT support, endpoint administration or systems administration.


- Hands-on Microsoft 365 administration, including Entra ID, Exchange Online, licensing, and security and compliance fundamentals.

- Practical Microsoft Intune experience - not just familiarity with the console, but hands-on experience deploying policies and troubleshooting them.

- Windows Server and Desktop troubleshooting experience.

- Experience with RDS or a comparable session-host environment.

- Working knowledge of AWS IAM, including reading and writing policy documents and understanding permissions.

- Azure experience/familiarity across Windows 365, Virtual Machines, and alerting.

- Experience administering an email security or phishing-response platform such as Ironscales, Proofpoint, Mimecast, or Microsoft Defender for Office 365.

- Excellent written English.

- Comfortable conducting live troubleshooting calls with client users and senior stakeholders.

Development & Automation Skills - Required :


- This role sits close enough to engineering that scripting is part of the job rather than a bonus.

- Strong working knowledge of PowerShell - must be able to write and modify scripts, not simply execute them.

- Working knowledge of one general-purpose programming language, typically Python or JavaScript / Node.js.

- Microsoft Graph API experience, including authentication flows, permissions, calling endpoints, and troubleshooting API errors such as HTTP 403.

- Strong ability to read and write JSON configuration, including IAM policy documents.

- Experience with Git and GitHub for version control.

- Ability to automate repetitive operational tasks end to end, including handling failure scenarios.

AI Capability - Required :


- We use AI tooling heavily across the team and expect candidates to already be comfortable using it for real work.

- Regular working use of LLM assistants such as ChatGPT or Claude for real operational tasks.

- Ability to write effective prompts and break complex tasks into steps that an AI model can execute.

- Understanding of how AI tools connect to real systems through MCP connectors, agentic workflows, and APIs and integrations.

- Strong judgment when verifying AI-generated output before taking action.

- Understanding of data privacy and security when using AI tools.

- Ability to identify situations where client data must not be entered into an unapproved AI tool.

- Helpful if you can support colleagues with installing and troubleshooting AI tools.

Nice To Have :


- Familiarity with DevStride, Jira, ServiceNow or similar work-tracking systems.

- Microsoft certifications such as MD-102, MS-102, or AZ-104.

- AWS certifications such as AWS SysOps Administrator or AWS Solutions Architect - Associate.

- Experience running security awareness training programs such as Ironscales, KnowBe4, or similar platforms.

- Experience building internal tools or small automation solutions that have been adopted by other teams.

HOW WE WORK :

We are a small team with direct communication and low ceremony. You will have real ownership early and real access early. Because of the shift, your overlap with the wider team will be limited to a few hours each day. We therefore expect you to work independently and raise issues that genuinely require a second opinion. In return, we expect honest work tracking, accurate daily time logging, clear communication, proactive escalation, strong ownership, and problems to be raised before they become visible to the client.

EXPERIENCE : 3+ Years

WORK MODE : Remote

SHIFT : US Business Hours

The job is for:

May work from home
info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...