3–5+ years administering Microsoft 365 and Entra ID. Hands-on with Conditional Access, PIM, Exchange Online, SharePoint/OneDrive, Teams, Intune, Defender. Demonstrated DLP experience designing, tuning, and operating Microsoft Purview DLP policies and Endpoint DLP. Proficiency with PowerShell (AzureAD/Microsoft.Graph/ExchangeOnline/Teams/Intune modules) and Microsoft Graph. Strong grasp of RBAC/least privilege, directory objects, auth protocols (OAuth/OIDC/SAML), and device/certificate trust. Solid network fundamentals (DNS, HTTP/S, TCP/IP). Excellent English communication. Right to work in Bulgaria. Experience with Azure Policy governance, Microsoft Sentinel, Purview, or endpoint hardening at scale. Experience with Microsoft Defender for Cloud Apps and DLP integrations. Prior work supporting audit frameworks (e.g., SOC 2) and access attestations.