Über
Exchange Online, Teams, SharePoint Online, tenant configuration, and licensing. Maintain hybrid identity and access —
Active Directory, Entra ID, sync, SSO, MFA, Conditional Access, and privileged access practices. Operate messaging and mail flow —
Exchange Online, hybrid connectors where applicable, transport rules, and retention. Perform security operations and compliance —
Microsoft Defender, Purview, audit/eDiscovery, and related telemetry. Automate administration and reporting —
PowerShell scripting; build repeatable runbooks and scripts. Monitor system/service health —
Capacity and performance monitoring; coordinate change and maintenance windows. Support endpoint/server hygiene —
Patching, vulnerability remediation, and configuration baselines in collaboration with platform teams. Participate in on-call rotation —
Manage incidents through triage, remediation, and post-incident review. Create and maintain documentation —
Diagrams, knowledge articles; mentor less experienced staff; act as a liaison across IT teams. SECURITY & INCIDENT RESPONSE Core Triage Monitor and triage security incidents from GreyMatter or SIEM/SOC platforms, prioritizing by severity and business impact. Act as first responder for Microsoft 365 and identity-related alerts — suspicious sign-ins, compromised accounts, anomalous behavior. Investigation & Analysis Analyze alerts and correlated events across Microsoft 365, Entra ID, and on-prem systems to determine scope, impact, and root cause. Use Microsoft Defender, Purview, and audit logs to perform forensic review and validate threats. Response & Remediation Execute containment and remediation
—
account disablement, session/token revocation, Conditional Access enforcement per security procedures. Coordinate with internal security teams and external SOC providers to escalate and resolve incidents efficiently. REQUIREMENTS Bachelor's degree in MIS/CS or equivalent experience. 3-5 years of IT experience with strong Windows client/server fundamentals. Hands-on administration of Microsoft 365 and hybrid identity (Active Directory + Entra ID). Strong PowerShell scripting and troubleshooting skills. Experience triaging and responding to security incidents using alerting, audit, and logging data. Ability to execute tasks in a high-pressure environment and participate in on-call rotation. Preferred Qualifications Experience with SIEM/SOC workflows and ticketing (e.g., ServiceNow). Experience with Exchange hybrid configurations and mail routing. Industry certifications in Microsoft 365/Azure security and identity or equivalent.
Sprachkenntnisse
- English
Hinweis für Nutzer
Dieses Stellenangebot stammt von einer Partnerplattform von TieTalent. Klick auf „Jetzt Bewerben”, um deine Bewerbung direkt auf deren Website einzureichen.