The M365 E5 Security Administrator will be responsible for managing and engineering security solutions within the Microsoft 365 suite. Key tasks will include configuring and maintaining access policies, overseeing endpoint security measures, and implementing data protection strategies across M365 services.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Responsibilities
- Identity & Access (Entra ID): Configure and maintain Conditional Access policies, Multi-Factor Authentication (MFA), Privileged Identity Management (PIM), and Identity Protection rules.
- Endpoint Security (Microsoft Defender for Endpoint & Intune): Manage EDR policies, device compliance rules, Attack Surface Reduction (ASR) rules, and automated remediation on Windows/mobile devices.
- Email & Collaboration (Defender for Office 365): Oversee Safe Links, Safe Attachments, anti-phishing, anti-spam policies, and quarantine triage.
- Data Protection & Governance (Purview): Implement and monitor Data Loss Prevention (DLP) policies, Sensitivity Labels, and Information Barrier policies across M365 services.
- Cloud Apps (Defender for Cloud Apps): Monitor shadow IT, manage OAuth app permissions, and enforce session policies.
- Perform Tier 2/3 incident response, triage, investigation, and root-cause analysis on alerts originating from Defender XDR and Sentinel.
- Continuously review Microsoft Secure Score and address recommendations.
- Handle escalated support tickets regarding access issues and compromised accounts.
Requirements
- 3+ years of hands-on experience administering Microsoft 365 security features, specifically within an E5/Defender XDR environment.
- 3+ years of experience configuring and operating Microsoft Sentinel.
- Strong proficiency in writing KQL (Kusto Query Language) queries for logs, investigations, and analytics rules.
- Experience with Microsoft Intune (MDM/MAM) for Windows endpoint management.
- Solid understanding of PowerShell for M365 scripting and security automation.
- Hands-on knowledge of networking basics (DNS, Firewalls, VPNs) and cloud identity fundamentals (Entra ID, SAML, SSO).
Desirable Certifications
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Information Protection and Governance Administrator Associate (SC-400)
- Microsoft Certified: Security Operations Analyst Associate (SC-200) (Highly Desirable)
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
Location
Riyadh, Saudi Arabia