Position Description – Senior Microsoft Modern Workplace & Azure Engineer
Role Title
Senior Microsoft Modern Workplace Engineer (Azure & Network Focus)
Department
Engineering & Infrastructure
Reports To
Head of Technology Solutions
Role Summary
This senior, hands‑on engineering role is responsible for the architecture, implementation, uplift, and operational ownership of modern Microsoft environments across Microsoft 365, Azure, Entra ID, and enterprise networking.
As a senior engineer at Tickbox, you will be a technical authority across our Modern Workplace and Azure stack — leading complex customer environments end‑to‑end. This role is a blend of deep technical capability, design leadership, and high‑level troubleshooting across identity, endpoint, cloud, and network layers.
You will operate as a final escalation point, influence engineering standards, lead migrations and security uplift projects, and mentor junior engineers — all while remaining actively hands‑on in the delivery of high‑quality, secure, and reliable solutions.
Tickbox places strong emphasis on team culture, collaboration, and engineering excellence, and this role plays a key part in uplifting capability across the practice.
Core Responsibilities
Microsoft 365 & Modern Workplace Engineering
As a Senior Modern Workplace Engineer at Tickbox, you will own the architecture, automation, integration, and operational excellence of Microsoft 365 environments. This is a deeply technical role requiring strong engineering discipline, security focus, and the ability to design at scale.
Microsoft 365 Architecture & Operations
* Architect, implement, and operate modern, secure Microsoft 365 environments across large and complex tenants, including:
o Exchange Online: hybrid mail flow, transport rules, compliance, migrations, security hardening.
o SharePoint Online & OneDrive: site architecture, lifecycle governance, DLP-driven access controls, B2B/B2C collaboration patterns.
o Microsoft Teams: enterprise voice/telephony (Direct Routing/SIP), meeting policies, retention, performance optimisation, and application governance.
o Microsoft 365 Apps for Enterprise lifecycle management, update channels, and automation of rollout rings.
Intune, Autopilot & Endpoint Engineering
* Lead the full engineering lifecycle for modern endpoint management:
o Windows Autopilot (HaaS workflows, white‑glove, hybrid join, zero‑touch onboarding).
o Advanced configuration baselines (security baselines, ASR rules, CIS/Microsoft benchmarks).
o Application packaging & deployment automation (Win32, LOB apps, dependencies, detection scripts).
o Compliance frameworks aligned to Essential Eight, with automated remediation where possible.
* Build and maintain device compliance dashboards, remediation scripts, telemetry pipelines, and governance standards ensuring fleet-wide health and security.
Entra ID (Azure AD) Identity Engineering
* Own identity architecture across:
o Conditional Access strategy (contextual access, step-up auth, session policies).
o Authentication standards (MFA, FIDO2, device-bound passkeys, password less rollout).
o Privileged Access Management (PIM), Just-In-Time access, break-glass governance.
o Identity lifecycle automation using SCIM, Entra ID Governance components, and API‑driven provisioning.
Microsoft 365 Copilot & AI‑Driven Workplace Enablement
You will play a key technical role in enabling and governing Microsoft 365 Copilot, including:
* Designing Copilot readiness strategy across:
o MIP sensitivity labels
o Purview data governance
o SharePoint permissions hygiene
o Semantic index preparation
* Ensuring tenants meet Copilot privacy, security, and data architecture requirements.
* Supporting the rollout of Copilot for M365, including:
o Plugin/connector integrations
o Prompt governance
o Security boundaries & access controls
* Working with customers to identify workflow automation and productivity uplift opportunities powered by Copilot + Power Platform.
Automation & Engineering Excellence
Automation is a core requirement of this role. You will:
* Build and maintain advanced PowerShell tooling for:
o Bulk tenant operations
o Intune configuration as code
o Identity lifecycle automation
o Audit, compliance, and reporting
o Exchange/SharePoint/Teams administration
* Develop automation pipelines using:
o PowerShell modules (Graph API, MSOnline, Exchange Online PowerShell v3, Teams PowerShell)
o Graph API & Graph SDK
o Azure Functions (serverless automation)
o DevOps repositories for version-controlled configuration
* Implement Configuration-as-Code approaches for:
o Intune JSON policies
o Conditional Access templates
o Entra ID Role/Baseline templates
o Automation scripts for security & compliance tasks
* Define and maintain engineering playbooks, runbooks, and orchestration patterns for consistent service delivery.
Power Platform (Power Automate / Power Apps / Power BI)
* Develop workflow automations that reduce manual handling across:
o User onboarding/offboarding
o License assignment
o Access approvals & governance
o Notifications & compliance workflows
* Support Copilot Studio and generative AI automation opportunities.
* Build lightweight business process applications for customers when aligned to Modern Workplace scope.
Advanced AI, Automation & Digital Productivity Skills
* Expertise enabling AI-driven productivity (Microsoft 365 Copilot, Copilot Studio, Graph connectors).
* Build custom copilots leveraging internal datasets, Graph APIs, and Microsoft Fabric integrations.
* Create enterprise automation workflows using:
o Power Automate cloud flows
o PowerShell automation modules
o Graph API orchestrations
o Azure automation/Functions
* Design data governance models that ensure Copilot safety, privacy, and access control integrity.
* Evaluate new AI capabilities, develop patterns and guardrails, and collaborate with customers on adoption strategies.
Azure Administration & Cloud Integration
* Administer and support core Azure services including:
o Virtual Networks, NSGs, routing & VPN
o Virtual Machines, storage & monitoring
o Log Analytics, Sentinel/Defender integrations
* Design and troubleshoot secure connectivity across on‑prem, Azure, and SaaS environments.
* Contribute to Tickbox's Azure landing zone standards, security posture, and cost optimisation practices.
Networking & Connectivity (Senior Level)
* Provide senior‑level engineering support for enterprise networking:
o Switching, routing, VLAN design
o Wireless infrastructure
o Firewall rule design and security hardening
* Hands‑on experience expected with:
Cisco Meraki, Palo Alto, WatchGuard, Ubiquiti
* Diagnose and resolve complex issues across:
o LAN / WAN
o Site‑to‑site & client VPN
o Cloud‑integrated network paths
* Engage with carriers and vendors to manage link performance, outages, escalations, and improvements.
Security & Compliance
* Design environments aligned with Essential Eight maturity targets and Microsoft security best practices.
* Implement and manage:
o Defender for Endpoint, Office 365, Identity
o Zero Trust and least‑privilege frameworks
* Identify security weaknesses, lead remediation initiatives, and drive continuous security uplift.
Automation & Engineering Maturity
* Develop and maintain PowerShell automation for:
o Tenant configuration
o User/device lifecycle
o Compliance/reporting
* Drive engineering standardisation and create repeatable, scalable, and maintainable workflows.
* Identify process and technology improvements to enhance reliability and reduce operational overhead.
Escalations, Leadership & Delivery
* Operate as the final escalation point for Modern Workplace, Azure, identity, and network incidents.
* Lead major incident RCA and drive preventative engineering improvements.
* Provide clear, confident guidance to customers and internal stakeholders.
* Mentor junior engineers, contribute to documentation and engineering playbooks, and uplift team capability.
Essential
* 5+ years hands‑on Microsoft 365 engineering experience (enterprise or MSP).
* Deep expertise with:
o Intune & Autopilot
o Entra ID
o Exchange Online
o Microsoft Teams
* Strong Azure administration experience with focus on identity, networking, and security.
* Solid enterprise networking experience across firewalls, routing, VPN, wireless.
* Proven track record delivering complex cloud/hybrid projects end‑to‑end.
* High‑level troubleshooting capability across identity, endpoint, cloud, and network layers.
* Ability to operate independently in high‑pressure, customer‑facing environments.
Desirable
* MSP/multi‑tenant experience.
* Exposure to security platforms such as:
o Microsoft Defender XDR
o Mimecast / Proofpoint
o Rapid7
* Automation & IaC experience:
o PowerShell
o Power Automate
* Experience contributing to architecture standards or governance frameworks.
Qualifications & Certifications
Preferred (not required but highly regarded):
* Microsoft 365 Administrator Expert
* Azure Administrator Associate
* Identity & Access Administrator Associate
* Security‑focused certifications (e.g., SC‑200/300/400)
Real‑world experience is valued highly and can substitute for formal certifications.
Key Attributes
* Calm, senior‑level problem solver with a structured approach.
* Strong communicator able to simplify complex technical issues.
* Ownership mindset — sees issues through to resolution.
* Team‑oriented and mentor‑focused.
* High standard of documentation and engineering discipline.
* Committed to quality engineering, security, and continuous improvement.
Why This Role
* Senior engineering position with meaningful impact and influence.
* Deep, hands‑on ownership of Microsoft Modern Workplace and Azure environments.
* Exposure across Modern Workplace, Azure, networking, and security.
* A supportive, collaborative team culture that values learning, professionalism, and engineering excellence.
* Work on challenging, high‑value technical problems rather than ticket churn.
-----------------------------------
Location
Melbourne, Victoria (Hybrid)
-----------------------------------
Department
Tickbox
-----------------------------------
Employment Type
Full-Time
-----------------------------------
Minimum Experience
Experienced
-----------------------------------
Compensation
$135,000 PA
-----------------------------------