← Back to jobs

Remote job

Microsoft 365 Engineer

Other Full-time Permanent Europe

Job details

Not specified Salary
Europe Eligibility
Not specified Experience
Full-time Employment

About this role

Role overview

Identity-focused engineering role owning the company's identity provider: who signs in, from where, with which factors, into which applications, and how that access is granted, reviewed, and revoked. Microsoft Entra ID is the primary identity plane, with Google Workspace, Cloud Identity, and Google Cloud IAM forming a secondary domain. Microsoft 365 falls within scope for tenant, licensing, and access administration.

Responsibilities

- Administer Microsoft Entra ID: users, dynamic and assigned groups, administrative units, directory roles, service principals, workload identities, and service accounts. - Design and roll out Conditional Access, authentication methods, phishing-resistant factors, least-privilege admin models, access reviews, and entitlement management access packages. - Onboard applications over SAML 2.0 and OIDC/OAuth 2.0, manage app registrations, secrets, certificates, consent, and remediate over-permissioned or stale applications. - Build and operate SCIM 2.0 provisioning, automated joiner-mover-leaver pipelines, and Microsoft 365 settings, licensing, Exchange Online, SharePoint Online, and Power Platform administration. - Build PowerShell tooling on the Microsoft Graph SDK and Graph REST API, plus scheduled and event-driven workflows in Azure Automation Runbooks, Azure Logic Apps, or Power Automate, treating automation as production code with version control, peer review, and documented rollback. - Serve as the escalation point for identity incidents, expected to resolve rather than route them onward.

Requirements

- 3+ years administering Microsoft Entra ID in production as a primary responsibility. - Working knowledge of Microsoft 365 tenant settings, Exchange Online permissions and mail flow, Microsoft Defender, and Power Platform environments. - PowerShell proficiency with the Exchange Online module and Microsoft Graph SDK. - Experience with enterprise applications, app registrations, consent and permission models, and automated provisioning. - Familiarity with Azure Automation Runbooks, Azure Logic Apps, Power Automate, or comparable platforms. - Discipline around least privilege, secure administration, change management, and documented configurations. - Written and spoken English at B2 or higher.

Nice to have

- SC-300, MS-102, or SC-401 certification, or equivalent demonstrable expertise. - Microsoft Entra ID Governance, Privileged Identity Management, and lifecycle workflows. - Microsoft Purview, Defender for Cloud Apps, or Microsoft Sentinel experience. - Google Cloud IAM, workload identity federation, and custom roles. - Git, CI/CD practices, Pester, Bicep, or Terraform. - Access evidence produced for SOC 2, ISO 27001, or comparable audit cycles.

Benefits and work setup

- Competitive compensation. - Career growth and learning opportunities. - Flexibility and ownership in how work is delivered. - Collaborative, innovative culture with an international team. - Opportunity to contribute to impactful AI infrastructure projects.

Skills detected in the listing

GCPAzureTerraform
Detected Oct 7, 2026
Last verified Oct 8, 2026

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight