Senior IT Manager
Constructor’s mission is to enable all educational organisations to provide high-quality digital education to 10x people with 10x efficiency.
With strong expertise in machine intelligence and data science, Constructor’s all-in-one platform for education and research addresses today’s pressing educational challenges: access inequality, tech clutter, and low engagement of students.
We are looking for a Senior IT Manager with proven hands-on expertise in Microsoft 365 and Entra ID, who is equally comfortable leading a small team as operating the infrastructure directly. The role owns our cloud productivity and identity stack and carries formal line management responsibility for 2–3 individual contributors, with the team expected to grow to up to 5 as the function matures.
This is not a pure management position: you will remain a working technical lead, serving as the primary subject matter expert for M365 and Entra ID while setting direction, growing your team's capability, and handling escalations that require senior judgement. You will work with considerable autonomy, collaborating closely with security, engineering, and business stakeholders across the organisation.
Key Responsibilities
- Own the Entra ID (Azure AD) tenant: lifecycle management, Conditional Access policies, MFA enforcement, Privileged Identity Management (PIM), and external identity (B2B/B2C where applicable)
- Maintain and evolve RBAC models across M365 workloads
- Administer hybrid identity infrastructure: AD Connect / Entra Connect sync, password hash sync or pass-through authentication, and seamless SSO
- Manage Exchange Online including mail flow rules, connectors, shared mailboxes, distribution groups, and migration tasks
- Configure and maintain mail security controls: DKIM, DMARC, SPF, Defender for Office 365 (anti-phishing, safe links, safe attachments), and quarantine policies
- Monitor and respond to mail security incidents and anomalies
- Manage the Intune environment: device enrolment (Windows, macOS, iOS/Android), compliance policies, configuration profiles, and application deployment
- Maintain Autopilot workflows and co-management configuration where applicable
- Enforce device-based Conditional Access in coordination with identity policies
- Administer on-premises Active Directory: ensure clean synchronisation between on-prem AD and Entra ID; manage schema, attribute filtering, and sync scope
- Participate in and support AD migration initiatives, move to cloud-only environment
- Lead lean IT team, develop runbooks and operational procedures to reduce manual toil and improve consistency
- Set the SLAs and ensure the service levels are consistently improving
- Collaborate with network/infrastructure colleagues on firewall rules, proxy configurations, and Microsoft 365 endpoint optimisation