Microsoft 365 & Power Platform Infrastructure Engineer
Licensed sponsor London Area, United Kingdom Contract Posted 1 hour ago
Microsoft 365 & Power Platform Infrastructure Engineer
Contract 6+ Months(Inside IR35)
Canary Wharf, UK
Hybrid (2 days a week)
Key responsibilities
- Develop the Low-Level Design, build specification and configuration documentation for the Windows and Microsoft 365 components identified in the Power BI HLD.
- Create secure build standards, operational runbooks, patching and evergreening procedures, monitoring requirements, housekeeping tasks and support documentation. Including integration into core infrastructure
- Implement separate Power Bl gateway clusters for Production and Non-Production, spanning GB and US data centers, including local node resilience and controlled DR activation.
- Engineer Microsoft EntraID groups, service principals, application permissions and role-based access required for tenant, workspace, application, gateway and deployment administration.
- Configure and validate Microsoft Fabric / Power Bl tenant and workspace controls across DEV, SIT, UAT and PROD, ensuring separation between Test and Production tenants.
- Implement Microsoft Purview sensitivity labelling, audit configuration and relevant Microsoft 365 compliance controls for Power Bl artefacts and exported content.
- Engineer Power Automate and Power Apps platform configuration as required.
- Work with Network and Security teams to define and validate proxy, firewall, DNS, Zscaler and Forcepoint requirements for user, gateway and cloud-service connectivity.
- Support vulnerability remediation, SCB validation, software patching, certificate and credential lifecycle management and controlled production change.
- Provide knowledge transfer and third-line support to Infrastructure Operations and other BAU support teams during service transition and early-life support.
Key skills and experience
- Strong Windows Server 2022 engineering, build, hardening, patching and troubleshooting experience.
- Hands-on experience deploying and supporting Microsoft on-premises data gateway in enterprise or highly
- Solid Microsoft 365 administration experience, including Microsoft Entra ID, Microsoft Purview, Power Bl / Fabric administration and Microsoft 365 audit capabilities.
- Experience with Active Directory, group management, service accounts, Windows authentication, Group Policy and domain-joined server design.
- Experience implementing RBAC, least privilege, service principals, Auth 2.0 and segregated production/non-production administration.
- Strong understanding of Power Bl tenant settings, capacities, workspaces, apps, gateway connections, deployment controls and platform monitoring.
- Experience producing High-Level and Low-Level Designs, build guides, security configuration baselines, test plans, implementation plans and operational runbooks
- Practical understanding of enterprise networking, outbound proxy design, firewalls, DNS, TLS, certificate trust and network segregation.
- Experience integrating Windows and cloud platforms with enterprise monitoring and SIEM tooling such as Splunk and Dynatrace.
- Experience delivering highly available infrastructure across multiple data centres and documenting/test-driving disaster recovery procedures.
- Strong understanding of change, incident, problem, release and service-transition processes within a regulated enterprise.
- Ability to collaborate across Infrastructure, M365, IAM, Network, Security, Analytics, Architecture, DevOps and Service Management teams.
Desirable skills
- PowerShell scripting and automation for Windows Server, Microsoft Entra EntraID or Power Bl administration.
- Experience with Power Automate, Power Apps and Power Platform administration.
- Experience with Microsoft Fabric administration and Fabric capacity monitoring.
- Knowledge of Jenkins, Bitbucket, Nexus, REST APIs and CI/CD deployment patterns for Microsoft cloud services.
- Experience with Delinea or equivalent privileged-access and secrets-management tooling.
- Experience with Zscaler, Forcepoint, SailPoint, Qualys, Tanium or Trellix in an enterprise environment.
- Experience working in financial services or another highly regulated industry.
- Knowledge of DirectQuery, semantic models and row-level security sufficient to support platform connectivity and access troubleshooting.
Expected deliverables
- Low-Level Design and build specification for Windows Server gateway nodes and Microsoft 365 platform configuration.
- Production and non-production gateway clusters built, tested and documented.
- Entra ID groups, administrative roles, service principals and access model implemented and evidenced.
- Power BI / Fabric tenant, workspace, Purview, audit and monitoring settings configured and documented.
- Network, proxy, firewall, DNS and security dependencies validated with relevant teams.
- HA, DR, patching, upgrade, recovery, monitoring and operational runbooks completed.
- Test evidence, as-built documentation, CMDB inputs and BAU handover completed.