Skip to content
← Back to job listings

Modern Digital Workplace - Microsoft Azure

creativeitc · All Offices, United Kingdom

IT - Network / Systems / DB AdminImported listingfull-timeabout 6 hours ago

About The Role

The L3 Modern Digital Workplace Engineer is a senior, hands-on role in Azure infrastructure and workplace engineering. The position will serve as a technical authority and constructive challenger, assessing Creative ITC's current approaches, identifying where they no longer reflect modern practice, and turning better ideas into secure, supportable, and repeatable services.
The role owns architecture and delivery across the Azure infrastructure stack, with a strong focus on modern identity through Microsoft Entra, automation, governance, resilience, operational readiness and continuous improvement. It will work closely with Security and other technical functions so that identity, endpoint, cloud and security controls are designed together rather than in isolation.
Azure Virtual Desktop experience is highly desirable. The successful individual will also provide L3 escalation support, mentor engineers, contribute to customer and internal design discussions, and help establish the engineering standards, patterns and roadmaps needed for Creative ITC's next phase of modernisation.
EDUCATION AND EXPERIENCE

  • Extensive hands-on experience designing, implementing, operating and improving production Microsoft Azure environments in an enterprise or managed services setting.
  • End-to-end Azure infrastructure depth across landing zones, management groups, subscriptions, compute, storage, networking, private connectivity, DNS, load balancing, backup, disaster recovery, monitoring and cost management.
  • Architecture ownership from discovery and options analysis through HLD, LLD, implementation, technical assurance, operational handover and lifecycle improvement.
  • Deep Microsoft Entra knowledge, including Conditional Access, MFA, RBAC, Privileged Identity Management, identity governance, access reviews, entitlement management, lifecycle controls, managed identities and hybrid identity.
  • Practical governance experience using Azure Policy, tagging, security baselines, Azure Monitor, Log Analytics, budgets and platform standards.
  • Automation and Infrastructure as Code capability using PowerShell, Bicep, ARM templates, Terraform, Azure Automation and/or CI/CD pipelines.
  • Ability to apply current Microsoft architecture guidance, Cloud Adoption Framework and Well-Architected principles in an operationally proportionate way.
  • A track record of constructively challenging established technical decisions and influencing stakeholders through evidence, clear options and pragmatic recommendations.
  • Experience collaborating across cloud, network, endpoint, service operations and cyber security teams, embedding security by design.
  • Strong troubleshooting and L3 escalation experience across complex Azure and hybrid infrastructure environments.
  • Excellent documentation and communication skills, including explaining technical risk, cost and trade-offs to varied audiences.

Highly desirable

  • Azure Virtual Desktop design, migration, optimisation and support, including host pools, session hosts, image management, FSLogix, application delivery, autoscaling, monitoring, identity and profile storage.
  • Windows 365, Microsoft Intune, Windows Autopilot and wider Microsoft 365 modern management experience.
  • Integration with Defender XDR, Defender for Endpoint, Defender for Cloud and Microsoft Sentinel.
  • Relevant Microsoft certifications such as Azure Administrator Associate, Azure Solutions Architect Expert or Identity and Access Administrator Associate.
  • ITIL knowledge and MSP or multi-customer delivery experience.

KEY JOB ELEMENTS

  1. Azure Architecture and Technical Direction
  • Assess current Azure and Modern Digital Workplace architecture, standards and operational practices, then define pragmatic target state improvements.
  • Challenge legacy assumptions and technical debt constructively through evidence, prototypes, architecture principles and measurable outcomes.
  • Own reference architectures, roadmaps, design patterns, guardrails and engineering standards aligned to current Microsoft capabilities.
  • Lead discovery and design reviews, documenting options, dependencies, risks, costs and recommendations.
  1. Azure Infrastructure Engineering
  • Design, build and improve secure Azure platforms across landing zones, resource organisation, compute, storage, networking, private endpoints, connectivity and name resolution.
  • Engineer resilience through availability, backup, recovery, capacity, monitoring, alerting and tested operational procedures.
  • Apply governance through Azure Policy, RBAC, tagging, budgets, cost controls, diagnostics and configuration standards.
  • Use automation and Infrastructure as Code to reduce manual effort, configuration drift and inconsistent delivery.
  1. Modern Identity and Microsoft Entra
  • Work with Security to modernise how Creative ITC uses Entra across workforce, privileged, guest, service and workload identities.
  • Design and improve Conditional Access, MFA, PIM, access reviews, entitlement management, identity lifecycle and least-privilege controls.
  • Evaluate where cloud-native identity, managed identities and modern authentication can replace legacy patterns safely.
  • Ensure identity, endpoint, Azure platform and security monitoring controls operate coherently.
  1. Azure Virtual Desktop and Modern Workplace
  • Where required, design, deliver and optimise AVD, including host pools, images, FSLogix, application delivery, autoscaling, monitoring and user experience.
  • Contribute to decisions across AVD, Windows 365 and other workplace models based on need, security, supportability, performance and value.
  • Align Intune, Windows, application management and identity with the wider Azure platform.
  1. Security and Cross-Functional Collaboration
  • Partner with Security from the outset of design and change, embedding Zero Trust, secure-by-design and least-privilege principles.
  • Support risk assessment, remediation, vulnerability response and implementation of appropriate cloud security controls.
  • Collaborate with Service Desk, NOC, project, architecture, network, application and commercial stakeholders so changes are operable and owned.
  1. L3 Operations and Service Improvement
  • Act as a senior escalation point for Azure, identity, AVD and hybrid infrastructure incidents and problems.
  • Lead deep investigations, root cause analysis and permanent corrective action rather than short-term workarounds.
  • Improve performance, resilience, security, cost efficiency and support quality through data-led continuous improvement.
  • Participate in change, incident and problem management and, where applicable, an agreed out-of-hours rota.
  1. Standards, Documentation and Knowledge Transfer
  • Create and maintain HLDs, LLDs, decision records, build guides, runbooks, support models and acceptance criteria.
  • Turn successful engineering outcomes into repeatable services, templates, standards and deployment pipelines.
  • Mentor colleagues and raise capability through knowledge sharing, open technical debate and certification.
  • Track Microsoft roadmap changes and assess their relevance, benefits, risks and adoption path for Creative ITC and its customers.

PERSON SPECIFICATION

  • Strong leadership presence with the ability to influence technical direction through expertise and credibility.
  • Confident in constructively challenging existing practices and driving continuous improvement.
  • Excellent communication skills with the ability to engage technical and non-technical stakeholders.
  • Strong stakeholder management and relationship-building capabilities.
  • Demonstrable mentoring and coaching experience, helping to develop technical capability within teams.
  • Highly collaborative with the ability to work effectively across Engineering, Security, Service Operations and Project functions.
  • Strong analytical and problem-solving skills with a methodical approach to troubleshooting.
  • Able to make informed decisions balancing risk, security, supportability, cost and business value.
  • Takes ownership and accountability for technical outcomes and service quality.
  • Self-motivated, adaptable and committed to continuous learning and professional development.
  • Customer-focused with a passion for delivering secure, resilient and high-quality services.
  • Resilient and composed under pressure, particularly during critical incidents and major service events.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing