3rd Line Support Engineer
3 days ago
Wilmslow
IT Service Desk – 3rd Line Engineer Reports To: 3rd Line Team Leader (Head of IT Infrastructure) Location: Wilmslow / Hybrid / Remote Hours of Work: Mon–Fri, staggered start/finish times between 8am and 6pm. Occasional work outside these hours may be required to support change windows or incidents; TOIL applies. The Role The IT Service Desk is the single point of contact for all IT services, requests, and incidents. It's a busy, dynamic, fast-paced team supporting Citation Group's multiple business units across the UK, Canada, and Australia. As a member of the 3rd Line Team, you will be responsible for building, managing, and maintaining company infrastructure across a multi-tenant, multi-country Microsoft 365 and Azure environment. The role of the IT Support team is to ensure colleagues have the technology they need to achieve business objectives — whether in the office or working remotely. Alongside day-to-day ticket resolution, you'll work on infrastructure projects and change initiatives — from platform migrations to identity and security improvements — balancing planned project work with reactive support. We're looking for customer-focused engineers to join our IT department, supporting colleagues both in the office and remotely across the UK (and coordinating with Canada/Australia counterparts). This role suits someone with 3+ years of experience in a similar role. Duties Include but not limited to: • 3rd line support of technology-related incidents within agreed SLAs, • Contributing to infrastructure projects and change initiatives alongside day-to-day ticket work, • Resolution of escalated colleague service requests or incidents as assigned within SLA, logged and tracked via service desk, • Building, configuring, and maintaining Azure infrastructure — virtual machines, networking, storage, and app services, • Supporting Azure governance activities — naming/tagging standards, Azure Policy, RBAC, and PIM, • Performing systems administration activities such as performance tuning and data management across Azure and on-prem infrastructure, • Managing identity and access — user/group administration, Conditional Access policies, and enterprise application configuration in Entra ID, • Monitoring and reviewing quality of service delivered, • Remediating vulnerability findings (patching, configuration fixes, closing out scan results) across networks, systems, and applications, • Planning, implementing, and optimising cloud and on-prem data storage technologies, • Installing, managing, controlling, deploying, and maintaining infrastructure systems software to meet operational needs and service levels, • Installing and testing, or decommissioning and removing, systems or system components, • Supporting device provisioning and lifecycle management, including Windows and Cloud PC (Windows 365) estates, • Raising and documenting changes in line with the change management process (standard/normal/emergency changes), • Producing and maintaining system, solution, and knowledge base documentation, • Liaising with 3rd party suppliers, • Travel to other offices as and when required Skills • 3+ years' experience in Microsoft Azure infrastructure and/or Entra ID identity & access administration (other specialist areas below are an advantage, not a substitute), • Strong communication and customer service skills, putting colleagues at the heart of everything you do, • Proven organisational skills with good attention to detail, • Comfortable balancing planned project work with reactive incident/ticket demands, • Clear, thorough approach to documenting changes and solutions for others to follow, • Ability and desire to learn about the systems we support, • Ability to prioritise your own workload and manage expectations Qualifications / Certifications (Preferred) • ITIL Foundation, • AZ-104 — Microsoft Azure Administrator, • SC-300 — Microsoft Identity and Access Administrator, • Other relevant Microsoft or specialist certifications (e.g. AZ-500, MS-102) Technologies & Specialisms Knowledge and experience in several of the following is preferred. Cloud — Microsoft Azure • Virtual machines, storage accounts, and app services, • Networking — hub-and-spoke topology, private endpoints, DNS, • Governance — naming/tagging standards, Azure Policy, Management Groups, • Identity & access — RBAC, Privileged Identity Management (PIM), managed identities, • Key Vault and secrets management, • Backup and patching (Azure Update Manager) Microsoft Based Technologies • Windows Platforms – Windows 10, 11, Server 2016+, • Active Directory, Entra ID, PowerShell, • Entra ID — Conditional Access, Enterprise Applications, SSO, identity and access management (IAM), • M365 – Exchange, Teams, SharePoint/OneDrive, • Intune Endpoint Manager, • Windows 365 / Azure Virtual Desktop (AVD) Network & Security • Cisco Meraki Firewalls, Switches and APs, • LAN, WLAN, DNS, VPN, • Cloudflare Telephony • Experience with cloud telephony platforms (e.g. RingCentral, Vonage, Amazon Connect) is beneficial but not a primary focus of the role, • MS Teams, • Mobile devices – iPhone, iPad