Senior Intune and System IT Engineer

Loading...

Senior Intune and System IT Engineer

Details

  • Work Location Type:
    Hybrid
  • Office:
    Bengaluru
  • Type of Employment:
    Full Time Permanent
  • Reference Number:
    TEC2408

About Us

At FDJ UNITED, we don't just follow the game, we reinvent it.

FDJ UNITED is one of Europe’s leading betting and gaming operators, with a vast portfolio of iconic brands and a reputation for technological excellence. With more than 5,000 employees and a presence in around fifteen regulated markets, the Group offers a diversified, responsible range of games, both under exclusive rights and open to competition. We set new standards, proving that entertainment and safety can go hand in hand. Here, you’ll work alongside a team of passionate individuals dedicated to delivering the best and safest entertaining experiences for our customers every day.

We’re looking for bold people who are eager to succeed and ready to level-up the game. If you thrive on innovation, embrace challenges, and want to make a real impact at all levels, FDJ UNITED is your playing field.

Join us in shaping the future of gaming. Are you ready to LEVEL-UP THE GAME?

Responsibilities:

 

  • Collaborate with other Corporate IT senior engineers, solution architects, domain experts and Helpdesk staff to test, deploy, communicate and support end user impacting changes into our Corporate IT
  • Work in autonomy to translate business requirements into technical solutions, leveraging our existing ecosystem and licenses everywhere possible
  • Automate tasks or empower end users with self-service capabilities, in respect of our security policies, to reduce maintenance and support overhead across the team
  • Define and maintain both a technical and end-user documentation on owned systems to facilitate maintenance and troubleshooting tasks.
  • Ensure that you adhere to the Governance, Risk & Compliance (GRC) obligations for your role.
  • Identify and raise any non-compliance incidents promptly to your line manager.
  • Challenge processes, policies and projects that will negatively impact compliance within the Group.
  • Complete all mandatory compliance training assigned to you.
  • Reach out to the Compliance Teams if unsure of any of your compliance obligations or the requirements are unclear.
  • As an "Identity" specialist:
    • Identity & Access Management: Manage company identities within Microsoft Entra, encompassing employee identities and service accounts to ensure secure and efficient access control.
    • Conditional Access Policies: Develop and maintain Conditional Access Policies in accordance with Zero-Trust principles, such as enforcing phishing-resistant authentication mechanism, compliant device, blocking legacy protocols, etc.
    • Permissions Management: Discover and remediate and monitor permission risks for our corporate identity and resources, including in third party cloud environment
    • Privileged Access Management: Implement and maintain PAM and Secrets management solutions, such as providing just-in-time access to critical resources, secure remote access using secure gateways, automated secret rotation, monitoring of privileged sessions, etc.
    • IAM Solutions: Implement and manage the Identity and Access Management solutions within Microsoft Entra. Responsibilities include identity governance (joiner, mover, leaver processes), role mining, access recertification campaigns, and creating Access packages.
    • B2B Security: Define and maintain secure B2B trust relationships with partners, ensuring robust security protocols are in place and adhered to.
    • Workload Identities: Develop and secure Workload identities, tailoring security measures to meet specific operational needs.
    • Modern Authentication Technologies: Maintain modern authentication technologies, such as Windows Hello for Business, Certificate-Based Authentication, and Passwordless phone sign-in.
    • SSO and automated provisioning for Corporate Apps: Integrate and maintain corporate applications in Entra Single Sign-On (SSO) systems, setting-up SCIM, ensuring seamless access across platforms according to policies
  • As an "Endpoint" specialist:
    • Endpoint Security Baselines: Define, implement, and maintain security baselines for all company endpoints, including Windows laptops, Macbooks, company iPhones, and Android phones, following industry best practices.
    • Modern Endpoint Login Capabilities: Deploy and maintain modern endpoint login capabilities, such as Windows Hello for Business and Certificate-Based Authentication, both locally and through remote login methods like RDP.
    • EDR Solution Management: Work with the internal SOC to fine-tune our Microsoft Defender EDR solution, leveraging all available hardening capabilities on each platform.
    • Browser Policy Management: Define and implement browser policies that balance usability and security.
    • Local Admin Policies: Implement policies ensuring that high privilege access is managed with just-in-time and just-enough access principles, using Microsoft LAPS and endpoint privilege management tools.
    • Device Management: Define, deploy, and maintain modern device management, configuration, and compliance policies using Microsoft Intune.
    • Patching Management: Define and maintain patching management capabilities for MacOS and Windows, focusing on automation wherever possible.
    • Corporate Apps Deployment: Deploy and maintain up-to-date corporate applications to our Mac and Windows endpoints.
    • Asset Inventory Maintenance: Maintain our asset inventory, recording all corporate IT assets from purchase to decommissioning.
    • Automatic Provisioning: Deploy and maintain automatic provisioning systems to provide an excellent Out of Box experience for employees, leveraging Zero touch and platform-specific capabilities such as Autopilot.
    • Maintaining expertise: Continuously stay up to date on new Intune capabilities and work on implementing Microsoft recommended practices to improve our Secure Score in the Endpoint area.
    • Remote Assistance: Deploy and maintain remote assistance capabilities across our fleet to support Helpdesk staff in assisting employees regardless of their location.
  • As a "Applications & Data management" specialist:
    • Data Lifecycle and Retention Policies: Define, implement, and maintain data labelling and retention policies based on business requirements.
    • Data Protection Templates: Develop and maintain data protection templates aligned with the company's Information Classification policies, tailored to fit main business use cases around data sharing and processing.
    • Data Leakage Prevention (DLP) Policies: Define, implement, and maintain data leakage prevention policies through Microsoft Purview and Defender for Cloud Apps to protect against oversharing and insider risks, whether accidental or adversarial.
    • Email Policies: Maintain email flow rules and security policies to protect against phishing and spam, including maintaining SPF, DKIM, and DMARC rules.
    • Office365 Configuration: Configure Office365 to follow security best practices, embrace new productivity and collaboration features or assist employees in adequately labelling and protecting company data. Oversee the Office suite, Exchange Online and Outlook, Teams IM, collaboration and voice, Power Apps, Automate and Planner, AI, and security management within the Microsoft 365 ecosystem.
    • Automatic Labelling and DLP Remediation Policies: Deploy automatic labelling and DLP resolution policies to reduce the overhead on both employees and corporate IT staff.
  • As an "Infrastructure" specialist:
    • VDI Infrastructure Management: Manage VDI infrastructure for hundreds of employees, ensuring high availability and optimal performance.
    • Security Hardening Policies: Define, deploy, and maintain security hardening policies for Windows and Linux servers, following industry's best practices.
    • Windows Server Administration: Deploy and maintain on-premise and azure-based Windows Server and, occasionally, Linux/Unix systems (CentOS).
    • Zero-Trust Network Access: Deploy zero-trust network access to corporate apps using technologies like Azure Application Proxy.
    • Corporate Services: Maintain corporate services including Radius, cloud, and on-premise Active Directory.
    • PKI: Maintain our Public Key Infrastructure (PKI), supporting user and device certificates for uses such as Certificate-Based Authentication and Network Access Control.
    • Secure Administration Workflows: Deploy and maintain secure administration workflows, leveraging privileged access workstation (PAW), secure protocols (SSH, RDP), and privileged access management (PAM) solutions.
    • Network Access Control (NAC): Maintain and support a Network Access Control setup leveraging Certificate Based Authentication to authenticate devices on the corporate network

Requirements

  • Educational Background: Master degree in Computer Science, Information Technology, or a related field.
  • Experience: Proven experience in Microsoft-heavy ecosystem, including Entra, Defender, Purview, Azure, Intune, Office365 product lines.
  • Certification: Relevant Microsoft certifications such as SC-100, SC-300, SC-400, MD-102, MS-102, MS-900, AZ-140, AZ-104, AZ-900 are highly regarded.
  • MacOS Management: Experience handling MacOS devices in an Enterprise environment is a plus.
  • Technical Skills: Proficiency in scripting and query languages like KQL, Python, Bash, and PowerShell is a plus.
  • Cultural and Language Proficiency: Strong understanding of European work culture with excellent proficiency in English, both written and spoken.
  • Project Management: Self-driven and autonomous, with a proven track record of successfully handling deployment of end user impacting change across thousands of employees spread over multiple locations.
  • Interpersonal Skills: Exceptional communication and interpersonal skills, capable of engaging directly with stakeholders at various levels within the organization.

Our Way Of Working

Our world is hybrid.

A career is not a sprint. It’s a marathon. One of the perks of joining us is that we value you as a person first. Our hybrid world allows you to focus on your goals and responsibilities and lets you self-organise to improve your deliveries and get the work done in your own way.

Application Process

We believe talent knows no boundaries. Our hiring process focuses solely on your skills, experience, and potential to contribute to our team. We welcome applicants from all backgrounds and evaluate each candidate based on merit, regardless of personal characteristics as the age, gender, origin, religion, sexual orientation, neurodiversity or disability.

 
 

Details

  • Work Location Type:
    Hybrid
  • Office:
    Bengaluru
  • Type of Employment:
    Full Time Permanent
  • Reference Number:
    TEC2408

Location

Loading...
Close map
Location
Bengaluru
WeWork - KINDRED INDIVIDUALS PRIVATE LIMITED, 43 Residency Rd, Bengaluru, India, KA 560025
Loading...
Loading...

Benefits

Well-being allowance
Learning and development opportunities
Inclusion networks
Charity days
Long service awards

Meet the recruiter

Aditi Joshi

aditi.joshi@kindredgroup.com

Share this page

Share with linkedin
Share with facebook
Share with twitter
Share with email
Loading