Infrastructure & Cloud Engineer – Role OverviewThis role sits within the Infrastructure team, supporting the identity, security, endpoint, messaging, Microsoft 365 and cloud platforms that underpin the wider IT estate. It is aplatform-ownership and 3rd-line technical role, acting as the key escalation point for the Service Desk and owning complex issue resolution.
The role holder will have primary ownership ofConditional Access, cloud security investigations and breach response, CIS hardening, Microsoft Azure, Azure Virtual Desktop (AVD), SharePoint Online and Intune. The position combines deep technical troubleshooting, estate-wide platform ownership and infrastructure/security project delivery.
Key Responsibilities1. Identity, Security & Compliance
- Administer the Microsoft 365 suite, including Exchange Online, Teams, SharePoint Online, OneDrive and security/compliance services.
- Own and maintain theConditional Access policy estate across Active Directory/Entra ID, including policy documentation and secure management of exceptions.
- Lead cloud security investigations using sign-in, risk and audit logs.
- Own theMicrosoft Defender estate, including XDR incidents, Defender for Office 365 policies, Defender for Endpoint onboarding/alerting and Defender for Identity sensor health.
- Run vulnerability scans and manage remediation plans across server and endpoint estates.
- Act as the primary technical owner for cloud security incidents and breach response.
- MaintainCIS hardening standards and track progress against security benchmarks.
- Resolve escalated identity issues including licensing, MFA and cross-tenant access.
- Administer on-premises Active Directory, including OU structure, Group Policy and Azure AD Connect/Entra Connect synchronisation, resolving sync issues between AD and Entra ID.
2. Azure, AVD & Microsoft 365 Administration
- Administer the Microsoft Azure environment, including subscriptions, resource groups, storage, networking and resource/cost management.
- Support and administer theAzure Virtual Desktop (AVD) estate, including host pools, session hosts, scaling, image management and application group assignments.
- Support legacyAmazon WorkSpaces where required as part of the migration to AVD.
- Administer SharePoint Online, including site structures, permissions, access groups, storage/quota management and governance of site sprawl.
- Monitor Azure, AVD/WorkSpaces and SharePoint health and capacity, coordinating patching and maintenance with minimal user disruption.
- Ensure identity, Conditional Access and licensing are correctly configured across platforms.
- Own infrastructure and security improvement projects, including rollouts, migrations, tooling, scoping and milestone reporting.
3. Endpoint, Messaging & 3rd-Line Support
- OwnIntune device management and deployment, including enrolment profiles, compliance policies, configuration profiles and application packaging/deployment.
- SupportSOTI configuration and deployment alongside Intune.
- Act as the technical escalation point for complex Service Desk issues requiring platform-level access, advanced diagnostics or architectural change.
- Resolve complex email delivery and rejection issues usingExchange Online and Mimecast message tracing.
- Troubleshoot advanced Outlook and mailbox issues, including profiles, permissions, access and delegation.
- Own and maintain branch/depot distribution lists and the wider mail estate structure, including group nesting to Manager and Assistant Manager level.
- Create and maintain Service Desk runbooks covering Azure, AVD/WorkSpaces, SharePoint, Intune and messaging, enabling routine issues to be resolved at first line.
General Responsibilities- Represent the Company professionally and work in line with its values and ISO quality standards.
- Comply with all relevant Health & Safety requirements and use PPE where required.
- Provide flexibility to support critical security incidents and technical escalations outside normal working hours when necessary.
- Undertake other reasonable duties as required.
Key Working RelationshipsInternal: Infrastructure Lead, Head of IT, Service Desk, HR, branch/depot managers and other key stakeholders.
External: Microsoft/Entra support, AWS support, Mimecast, security/compliance auditors and other technology partners.
Skills & Knowledge- Strong hands-on experience withMicrosoft 365, Active Directory, Entra ID, Conditional Access, SharePoint Online and Microsoft Defender/XDR.
- Experience investigating sign-in logs, risk events and audit logs.
- Proven experience contributing to or leadingsecurity incident and breach response.
- CIS hardening or equivalent security-baseline experience.
- Microsoft Azure administration, including subscriptions, resource groups, storage and networking.
- StrongIntune experience covering enrolment, compliance, configuration profiles and application deployment.
- PowerShell scripting and automation.
- AD/Entra group and attribute administration, including synchronisation.
- Advanced Exchange Online and email-security troubleshooting, including message tracing and delivery faults.
- Outlook/mailbox administration covering profiles, permissions and delegation.
- Experience creating clear technical runbooks and process documentation for Service Desk/1st-line teams.