Posted on: 03/06/2026
Job Title : Senior Microsoft Engineer
Location : Thane, Mumbai
Type : Full-Time
Department : IT Services and Security
It is Work from Office & 24X7 Rotational Shift
Key Responsibilities :
1. Microsoft Intune, Endpoint Security & Device Governance
- Design, deploy, and manage Microsoft Intune for endpoint management, device compliance, application protection, and security policy enforcement.
- Configure and maintain device enrollment profiles, compliance policies, configuration profiles, security baselines, and endpoint protection policies.
- Implement Mobile Device Management and Mobile Application Management controls for corporate and BYOD environments.
- Manage Windows, macOS, iOS, and Android device policies using Intune.
- Design and administer Intune RBAC, including role assignments, scope tags, administrative boundaries, and delegated access models.
- Implement endpoint security controls, including disk encryption, firewall policies, attack surface reduction rules, endpoint privilege controls, and Defender integration.
- Support conditional access enforcement based on device compliance, risk posture, and user identity.
2. Microsoft Purview, Compliance & Data Governance
- Design, configure, and manage Microsoft Purview solutions for data security, compliance, and governance.
- Implement and manage Data Loss Prevention policies, including Exchange, SharePoint, OneDrive, Teams, Endpoint DLP, and cloud app integrations.
- Configure and manage Sensitivity Labels, retention labels, retention policies, information protection, and data classification policies.
- Support data discovery, classification, labeling, and protection initiatives across Microsoft 365 and Azure environments.
3. Microsoft Entra ID, Identity Security & Zero Trust
- Design and manage Microsoft Entra ID identity architecture, including users, groups, roles, applications, enterprise apps, and service principals.
- Implement and optimize Conditional Access policies, MFA, Identity Protection, Privileged Identity Management, and access reviews.
- Support hybrid identity integration using Entra Connect / Azure AD Connect.
- Design and implement least-privilege access models using Entra ID roles, administrative units, privileged access groups, and RBAC principles.
- Manage identity governance controls such as entitlement management, access packages, lifecycle workflows, and periodic access reviews.
- Support Zero Trust architecture by enforcing identity-driven access, device trust, application control, and risk-based authentication.
- Investigate identity-related alerts, suspicious sign-ins, risky users, risky workloads, and privilege escalation events.
4. Azure Cloud Security & Platform Administration
- Support secure design, deployment, and administration of Azure cloud environments.
- Configure and manage Azure resources, subscriptions, management groups, resource groups, policies, and role-based access controls.
- Implement Azure RBAC, Azure Policy, management group governance, tagging standards, and cloud access control models.
- Assist in securing Azure workloads, including virtual machines, storage accounts, key vaults, networking, app services, and databases.
- Implement governance and monitoring controls across Azure subscriptions to improve visibility, compliance, and operational control.
- Work with security teams to review cloud misconfigurations, excessive permissions, exposed resources, and policy violations.
Required Experience
- 4+ years of hands-on experience in enterprise IT, Microsoft cloud, security or infrastructure engineering roles.
- Strong hands-on experience with Microsoft Purview, including DLP, sensitivity labels, retention policies, data classification, and compliance features.
- Strong hands-on experience with Microsoft Intune, including endpoint management, device compliance, security baselines, app protection, and RBAC.
- Strong knowledge of Microsoft Entra ID, including Conditional Access, MFA, PIM, Identity Protection, access reviews, and hybrid identity.
- Good understanding of Zero Trust security principles, least privilege access, endpoint governance, and identity-based security.
- Experience working with enterprise clients in implementation, migration, governance, or security improvement projects.
Must-Have Requirements :
- Hands-on experience implementing and managing Microsoft Purview DLP policies, including Endpoint DLP.
- Hands-on experience with Microsoft Intune RBAC, including role assignments, scope tags, device compliance, and app/device policy enforcement.
- Strong knowledge of Microsoft Entra ID Conditional Access, MFA, PIM, and Identity Protection.
- Practical experience with Azure RBAC, Azure Policy, Defender for Cloud, and Azure monitoring tools.
- Strong documentation, troubleshooting, and client-facing communication skills.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1641472