M365 Engineer
VFX Financial
23h ago
0DevPortugalhimalayas
M365-EngineeringIAMEndpoint-Security-EngineeringMicrosoft-Identity-EngineerTech-and-EngineeringM365-EngineerM365-Systems-EngineerM365-Solutions-EngineerMicrosoft-365-EngineerM365-Security-EngineerOffice-365-EngineerM365-Technical-ConsultantM365-SpecialistMicrosoft-365-EngineeringSenior
Job Description
About VFXVFX Financial is one of the UK’s fastest-growing FinTechs, helping complex organisations move, manage, and protect money across borders. Built for specialist sectors, multi-jurisdiction structures, and high-compliance environments, we support businesses whose needs go beyond standard banking. We’re selective about who we work with because exceptional service requires focus and commitment.With six international offices, five regulatory licences, and an 83% CAGR over the past three years, we’re scaling rapidly and earning industry recognition along the way — including the Financial Times FT1000: Europe’s Fastest Growing Companies 2026, CNBC UK’s Top Fintech Companies 2025, Wealth & Finance FinTech Awards 2026, and the Business Growth Award from Business Awards UK.Behind it all is a team of ambitious VFXers united by collective ownership, a focus on growth, and a shared passion for solving complex problems.About the RoleThe M365 Engineer owns VFX's Microsoft identity and endpoint environment. The role is weighted as follows: approximately 50% identity security (Entra ID, Conditional Access, PIM), 30% endpoint management and security (Intune, Autopilot, EDR), 10% automation and scripting, and 10% M365 platform support. SharePoint Online, Teams, eDiscovery, and advanced Purview configuration are within scope as secondary responsibilities, not the primary focus.We use CrowdStrike Falcon for endpoint detection and response, identity threat protection, and security monitoring, alongside our managed SOC operating model. The engineer will work with CrowdStrike tooling in day-to-day operations; full onboarding and training on the CrowdStrike environment is provided. However, this is not a CrowdStrike-specialist role—the core hire will be a strong Microsoft identity and endpoint engineer.This role can be hybrid at our office in Portimao or fully remote across Portugal.Key ResponsibilitiesIdentity & Access ManagementOwn Entra ID: architecture, user and group lifecycle, hybrid Active Directory integration, and directory governanceDesign, implement, and maintain Conditional Access policies enforcing Zero Trust access principlesManage Privileged Identity Management: just-in-time access, role activation workflows, and regular access reviewsWork with our identity threat detection platform (CrowdStrike Falcon Identity Protection) to monitor for anomalies and respond to identity-based threats — training providedManage external identities, B2B collaboration policies, and cross-tenant access settingsOwn periodic access reviews; ensure IAM controls remain current and evidenced for auditEndpoint Security & Device ManagementOwn the full lifecycle of Windows and mobile device management via Microsoft Intune and Autopilot — provisioning, configuration, compliance, patching, and decommissioningDefine and enforce device configuration profiles, security baselines, and compliance policiesWork with our EDR platform (CrowdStrike Falcon) — triage alerts, investigate incidents, and drive remediation alongside the SOC; full training providedManage mobile application management controls to protect corporate data on personal and managed devicesMonitor endpoint health and security posture; proactively identify and remediate vulnerabilities and configuration driftAutomation & ScriptingDevelop and maintain PowerShell automation for identity lifecycle, compliance remediation, configuration drift detection, and operational self-healingBuild reusable automation solutions; maintain internal runbooks and operational documentationM365 Platform SupportAdminister Exchange Online, SharePoint Online, and Microsoft Teams — security configuration, DLP policies, retention labels, and service healthManage Microsoft 365 tenant configuration, licensing, and compliance centre settingsSupport data protection requirements — eDiscovery, retention policies, and information protection labels — in collaboration with the DPOLead technical investigation and remediation for M365 platform incidents, working within VFX's incident-management processRequirementsEssentialTypically 5+ years in Microsoft cloud, identity, or endpoint engineering, with demonstrable production ownership of Entra ID and IntuneDeep working knowledge of Entra ID: Conditional Access, PIM, identity governance, hybrid environmentsHands-on expertise with Microsoft Intune, Autopilot, and MDM/MAM policy managementProficiency in PowerShell scripting for identity lifecycle and compliance automationSolid understanding of Zero Trust architecture and practical implementation experienceExperience working with endpoint detection and response tooling in a production environmentProfessional proficiency in EnglishPreferredExperience with CrowdStrike Falcon Identity Protection or equivalent identity threat detection tooling (training provided at VFX)Familiarity with SIEM platforms; we use CrowdStrike Falcon LogScaleKnowledge of NIST or CIS control frameworks applied to identity and endpointExperience with Micr
