Own and secure the Microsoft 365 environment (Email/Exchange Online, Teams, SharePoint, OneDrive), including tenant hardening, data protection, and secure collaboration controls.
Manage email security, sharing policies, and access governance across collaboration platforms.
Mobile Device Management
Administer and secure the mobile fleet via Microsoft Intune, including enrolment, compliance policies, conditional access, and app protection.
Identity & Access Governance
Support identity lifecycle, provisioning, and access certification through SailPoint and its integration with workplace platforms.
Endpoint Management & Automated Deployment
Design, build, and operate automated endpoint deployment using SCCM (MECM) and ManageEngine.
Own application packaging, patching, and lifecycle management for non-Windows / third-party applications (e.g., 7-Zip, Notepad++), ensuring timely updates and vulnerability remediation.
Define, implement, and maintain Windows 10 / Windows 11 hardening baselines aligned to CIS Benchmarks and Microsoft Security Baselines.
Monitor endpoint compliance and remediate configuration drift.
Requirements
Bachelor's degree in Computer Science, Information Technology, Information Security, or related disciplines
4 years of experience in endpoint / digital workplace engineering with a strong security focus
Hands-on experience securing and administering Microsoft 365 (Exchange Online, Teams, SharePoint, OneDrive)
Solid experience with SCCM and ManageEngine for endpoint deployment, patching, and application management
Practical experience administering Microsoft Intune (MDM/MAM, compliance, conditional access)
Demonstrated experience applying Windows 10/11 hardening baselines (CIS / Microsoft Security Baselines)
Working knowledge of SailPoint for identity governance and access management
Experience packaging and maintaining third-party / non-Windows applications
Scripting and automation skills (PowerShell, Office Scripts) is a big advantage
Certifications such as Microsoft SC-300, MD-102, SC-200, AZ-500 or CompTIA Security+ is preferred
Experience in change management and supporting production environments
Ability to work under pressure and prioritise work effectively
Benefits
Bupa offers 5 days’ work per week and comprehensive remuneration packages including base salary, study assistance plan, company pension plan, life and medical benefit, dental benefit, annual leave, examination leave, etc.
Bupa is an equal opportunity employer and welcomes applications from qualified candidates. Information provided will be treated in strict confidence and only be used for consideration of application with Bupa.
Personal data collected will be used for recruitment purposes only. Bupa will be in touch for any opportunities that matches your profile. All personal data of unsuccessful application will be destroyed 24 months from the date of receiving the application. Full version of Data Privacy Notice available upon request.
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in Hong Kong.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in Hong Kong, connecting you to thousands of jobs fast!
Find the best jobs in Hong Kong, apply in 1 click and get a job today!