Gemological Institute of America→
M365 Platform Messaging Engineer - Day Shift at Gemological… · GIA…
Job Description
M365 Platform Messaging Engineer - Day Shift
Location: GIA Services Private Limited (Navi, Mumbai)
The M365 Platform Engineer is responsible for the operation, security and continuous improvement of the Institute's Microsoft 365 platform. The role supports Exchange Online and hybrid Exchange messaging, the email security gateway estate including Proofpoint, Microsoft Teams, SharePoint Online and OneDrive for Business, and Microsoft Intune for endpoint configuration and compliance. It also administers the hybrid identity estate across Entra ID and on-premises Active Directory, covering directory synchronization, conditional access, authentication methods and directory hygiene.Day-to-day platform administration is a substantial and deliberate part of the role. This includes regular mailbox hygiene and cleanup, archive and retention application, quota and growth management, administration of distribution lists, mail-enabled security groups and Microsoft 365 groups including membership additions and removals and review of stale or ownerless groups, and license assignment, correction and reclaim across joiners, movers and leavers. The expectation is that this work is automated through PowerShell and Microsoft Graph wherever it recurs, so that volume is absorbed by script rather than by headcount.
The engineer administers the tenant to a documented standard, keeps the gateway and native Microsoft security controls complementary rather than conflicting, and manages service change so that Microsoft's release and deprecation cadence is absorbed deliberately rather than encountered. Working within a multidisciplinary infrastructure team and reporting to the Manager IT Infrastructure Services, the role acts as second and third level escalation for complex messaging, identity and endpoint issues, provides technical guidance to less experienced engineers, and documents thoroughly enough that the platform does not depend on one person.
Key Responsibilities / Deliverables
Exchange Online, Hybrid Messaging and Mail Flow
· Administer Exchange Online and hybrid Exchange, including user, shared, resource and room mailboxes, mailbox permissions and delegation, archiving and retention, and the on-premises Exchange servers retained for hybrid management.
· Own mail flow end to end, including connectors, accepted and remote domains, transport and journaling rules, message tracing, queue monitoring, and resolution of delivery failures and non-delivery reports.
· Manage email authentication and anti-spoofing, including SPF, DKIM and DMARC, progress the domain toward enforcing DMARC policy, and govern third-party services that send on the Institute’s behalf.
· Maintain hybrid coexistence, including directory and free/busy interoperability, cross-premises mail flow and the hybrid configuration, and execute mailbox migration and consolidation with cutover planning, validation and rollback.
· Monitor service health and message queues, respond to Microsoft service advisories, and assess announced changes and deprecations against the tenant configuration before they take effect.
Email Security – Proofpoint and Microsoft Defender for Office 365
· Administer the email security gateway estate, including Proofpoint, covering policy routes, filtering and spam policy, allow and block lists, URL and attachment defense, quarantine and end-user digests.
· Administer Exchange Online Protection and Microsoft Defender for Office 365, including anti-phishing, anti-spam, safe links, safe attachments and quarantine, keeping gateway and native controls complementary rather than duplicated or conflicting.
· Maintain inbound and outbound routing between the gateway and Exchange Online, including connector restriction and IP allow-listing so that mail cannot bypass the gateway.
· Investigate reported phishing, spoofing and business email compromise, including message trace and header analysis, release or purge of delivered messages, and coordinated action with the information security function.
· Report on threat volume, quarantine activity, false positives and user-reported messages, and tune policy on the evidence rather than on complaint volume.
Entra ID and Hybrid Active Directory Administration
· Administer Entra ID, including users, assigned and dynamic groups, administrative units, enterprise applications, single sign-on, app registrations and service principals.
· Administer on-premises Active Directory within the hybrid model, including organizational unit and group structure, Group Policy where applicable, and directory hygiene covering stale, duplicate and orphaned objects.
· Manage hybrid identity synchronization, including Entra Connect or cloud sync, sync scope and filtering, attribute flow, resolution of sync and duplicate-attribute errors, and password hash sync, pass-through authentication or federation as deployed.
· Administer conditional access, multi-factor authentication and authentication methods, and support privileged identity management and access reviews in coordination with information security.
· Execute the identity side of joiner, mover and leaver workflow, including account state, group membership, mailbox provisioning and license consequences.
Microsoft Intune and Endpoint Platform Administration
· Administer Microsoft Intune, including enrolment profiles, device configuration and compliance policies, app protection policies and application deployment.
· Maintain Windows endpoint baselines, update rings and feature and quality update policy, including Windows Autopatch where used, and report compliance against them.
· Maintain device compliance signaling into conditional access, so that access decisions are made on verified device state rather than assumption.
· Support Windows Autopilot provisioning and co-management with Configuration Manager where in place.
· Coordinate shared Intune tenant configuration with the endpoint and Apple engineering teams, so that policy scoped by one team does not conflict with another.
Teams, SharePoint Online and OneDrive
· Administer Microsoft Teams, including teams and channel governance, messaging, meeting and calling policies, external and guest access, and Teams telephony where deployed.
· Administer SharePoint Online and OneDrive for Business, including site provisioning, permissions models, sharing controls, storage quotas and lifecycle policy.
· Define and maintain collaboration governance, including naming standards, provisioning workflow, external sharing posture and the lifecycle of inactive teams and sites.
· Resolve escalated issues affecting meetings, file access and sharing, and support business teams in adopting collaboration capability.
Mailbox, Distribution List and License Lifecycle Administration
· Perform regular mailbox hygiene and cleanup on a defined cadence, including oversized and inactive mailboxes, archive enablement and retention application, quota and growth management, review of orphaned and shared mailboxes, and recovery of deleted items and mailboxes.
· Administer distribution lists, mail-enabled security groups and Microsoft 365 groups, including creation, membership additions and removals, ownership, moderation and delivery restrictions, and periodic review of stale, ownerless or duplicate groups.
· Support Microsoft 365 license administration, including correct SKU assignment at joiner and mover, reclaim from leavers and inactive accounts, resolution of assignment errors, and regular reporting of assigned against consumed licenses.
· Execute leaver processing for messaging and collaboration, including conversion to shared mailbox, delegation, litigation or retention hold, OneDrive handover and removal to the agreed schedule.
· Fulfil messaging, identity and collaboration service requests through the ITSM tool to agreed SLA, and act as second and third level escalation for complex issues, engaging Microsoft and Proofpoint support where required.
Automation, Reporting, Compliance and Documentation
· Develop and maintain PowerShell and Microsoft Graph automation for recurring administration, including distribution list membership updates, mailbox cleanup, license assignment and reclaim, joiner and leaver processing and bulk change, treating repeated manual administration as a defect to be scripted out.
· Build and publish scheduled reporting on mailbox size and growth, license consumption and reclaim, group and distribution list hygiene, mail flow and threat volume, device compliance and identity hygiene.
· Administer Microsoft Purview capability in scope, including retention policies and labels, data loss prevention, eDiscovery and audit log search, and maintain compliance evidence for internal and external audit.
· Update and maintain runbooks and technical documentation, operate change control with tested rollback, and provide technical guidance and mentoring to less experienced engineers.
JOB COMPETENCIES (Skills & Abilities)
· Messaging depth: Advanced, practical Exchange Online and hybrid Exchange administration, including mail flow, connectors, transport rules, message tracing and migration.
· Email security capability: Hands-on command of an enterprise email security gateway, specifically Proofpoint, alongside Exchange Online Protection and Defender for Office 365, and the judgement to keep the two layers complementary rather than duplicated.
· Threat orientation: Understands how mail-borne attacks actually work — spoofing, impersonation, credential phishing and business email compromise — and configure authentication, hygiene and detection accordingly rather than by template.
· Hybrid identity command: Practical administration of Entra ID and on-premises Active Directory as a single hybrid estate, including synchronization, attribute flow, conditional access, authentication methods and directory hygiene.
· Endpoint platform capability: Working command of Intune device configuration, compliance policy, application deployment, update rings and the compliance signal that conditional access depends on.
· Collaboration administration: Working command of Teams, SharePoint Online and OneDrive, including governance, permissions models and external sharing posture.
· Automation mindset: Strong PowerShell and Microsoft Graph proficiency, applied to distribution list changes, mailbox cleanup, license assignment and bulk administration, so that recurring work is scripted rather than repeated.
· Lifecycle discipline: Treats mailbox hygiene, group review and license reclaim as a standing cadence with evidence, not as a cleanup exercise triggered by a storage alert or an invoice.
· License and cost awareness: Understands Microsoft 365 SKUs and entitlement, keeps assignment correct at joiner and mover, and pursues reclaim so that spend tracks actual use.
· Judgement: Balances collaboration openness against data protection, and can defend where the line has been drawn to both business and security stakeholders.
· Change absorption: Tracks Microsoft’s release and deprecation cadence, assesses impact ahead of time, and plans rather than reacts.
· Operational discipline: Runbook-driven execution, adherence to change control, and structured validation before and after change.
· Problem solving: Strong analytical skills with proven ability to identify root cause across mail flow, gateway, identity, device, client and network layers.
· Security: Works with the information security function on phishing response, conditional access, privileged access and compliance evidence, rather than treating security as a separate queue.
· Service orientation: Handles a high volume of routine requests — distribution list changes, mailbox access, license assignment — without letting them displace platform work, and automates them where the pattern repeats.
· Documentation and knowledge transfer: Clear, maintainable runbooks and technical documentation that reduce single-person dependency on a platform the whole organization uses.
· Communication: Excellent written and verbal communication in English, with the ability to explain a messaging, sharing or access restriction to a frustrated business user without escalation.
· Accountability and autonomy: Owns the platform end to end, prioritizes across a broad surface, and makes sound technical decisions with limited information.
MINIMUM QUALIFICATIONS (Knowledge & Experience)
· Bachelor’s degree in computer science, Information Technology, Engineering or a closely related field, or equivalent professional experience. (Required)
· 7+ years of experience administering Microsoft 365 in an enterprise environment, including at least 4 years with substantial Exchange Online and hybrid Exchange responsibility. (Required)
· Demonstrated hands-on ownership of mail flow, including connectors, transport rules, message tracing and resolution of delivery failures in a hybrid configuration. (Required)
· Demonstrated hands-on administration of an enterprise email security gateway, specifically Proofpoint or a comparable product such as Mimecast or Cisco Email Security, including policy, quarantine and URL and attachment defense. (Required)
· Demonstrated experience implementing and operating SPF, DKIM and DMARC, including progression of a domain to an enforcing DMARC policy. (Required)
· Demonstrated hands-on administration of Entra ID and on-premises Active Directory in a hybrid configuration, including Entra Connect or cloud sync, sync error resolution, conditional access and MFA. (Required)
· Demonstrated hands-on administration of Microsoft Intune, including device configuration and compliance policies, application deployment and update rings. (Required)
· Demonstrated administration of Microsoft Teams, SharePoint Online and OneDrive for Business, including governance, permissions and external sharing controls. (Required)
· Demonstrated experience operating mailbox lifecycle administration at scale, including cleanup, archiving, quota management, shared mailbox conversion and leaver processing. (Required)
· Demonstrated experience administering distribution lists, mail-enabled security groups and Microsoft 365 groups, including membership management and periodic hygiene review. (Required)
· Demonstrated experience with Microsoft 365 license administration, including group-based licensing, SKU assignment and reclaim, and license reporting. (Required)
· Strong PowerShell scripting ability with practical use of Microsoft Graph for bulk administration, automation and reporting. (Required)
· Experience with Microsoft Purview in scope, including retention, data loss prevention, eDiscovery and audit log search. (Required)
· Experience supporting a globally distributed user base across multiple time zones from an offshore or global capability center. (Required)
· Professional proficiency in spoken and written English, sufficient to support a multi-national user base and to communicate with senior stakeholders. (Required)
· Certification such as Microsoft 365 Certified: Administrator Expert (MS-102), Messaging Administrator Associate (MS-203), Identity and Access Administrator (SC-300) or Endpoint Administrator Associate (MD-102). (Preferred)
· Experience in an environment subject to external audit, where messaging and collaboration controls must be evidenced rather than asserted. (Preferred)
· ITIL 4 Foundation, or equivalent demonstrated knowledge of incident, change and problem practice. (Preferred)
Disclaimer: This job description indicates in general terms, the type and level of work performed as well as the typical responsibilities of employees in this classification and it may be changed by management at any time. Other duties may also apply. Nothing in this job description changes the at-will employment relationship existing between the Company and its employees.