Manager, Datacenter Operations
- Hiring from
- United States
- Work type
- Remote
- Posted
- Sep 25, 2026
Overview
A global biopharmaceutical company on a mission to Solve On, Incyte follows science to find solutions for patients with unmet medical needs. Through the discovery, development, and commercialization of proprietary therapeutics, Incyte has established a portfolio of first-in-class medicines for patients and a strong pipeline of products in Hematology, Oncology and Inflammation and Autoimmunity
Headquartered in Wilmington, Delaware, Incyte has operations in North America, Europe, and Asia.
Role Summary
The Manager, Microsoft Cloud Services is accountable for the strategy, architecture, governance, security, lifecycle, financial stewardship, and engineering direction of the organization’s Microsoft cloud environment, including Microsoft Azure, Microsoft Intune, Microsoft Entra ID, Exchange Online, and core Microsoft 365 tenant services. This technical management role leads a small team, establishes platform standards, makes architecture decisions, and ensures the environment is secure, scalable, resilient, compliant, cost-effective, and aligned with business priorities.
The role owns platform strategy and the control plane rather than routine infrastructure operations. Standard activities such as individual server deployments, daily monitoring, backup execution, routine patching, and first-line operational support are performed by Infrastructure Operations or managed service providers. The Manager defines the architecture, guardrails, service expectations, and governance under which those teams operate and provides senior technical escalation for platform-wide issues and risk decisions.
SharePoint Online, Microsoft Teams, Power Apps, Power Automate, and the broader Power Platform suite are outside the scope of this role and are owned by separate service teams.
Key Responsibilities
Azure Platform Strategy & Architecture
- Own the Azure strategy and roadmap and translate business, security, compliance, and infrastructure requirements into a prioritized platform plan.
- Define and govern the Azure enterprise architecture, including management groups, subscriptions, landing zones, resource organization, naming and tagging, Azure Policy, RBAC, shared services, connectivity, DNS, private endpoints, logging architecture, and hybrid integration.
- Serve as the senior technical authority for cloud service selection, architecture patterns, resilience, workload placement, integration, and modernization decisions.
- Review and approve significant Azure designs and exceptions to ensure alignment with enterprise architecture, cybersecurity, regulatory, supportability, and cost requirements.
- Establish reusable reference architectures and engineering standards that enable secure, consistent, and efficient cloud adoption.
Microsoft Intune & Endpoint Management
- Oversees the Intune strategy, architecture, and governance, of the Intune platform and conditional access policies.
- Define standards for securing the Intune platform working with IT Security and Microsoft to understand the platform roadmap.
- Provide technical direction to endpoint operations teams and End User servers. Excluding routine device support, software fulfillment, and day-to-day
- endpoint administration from this role.
Microsoft Entra ID & Identity Governance
- Own the Entra ID architecture and governance model for workforce identities, guest identities, privileged identities, enterprise applications, application registrations, service principals, and managed identities.
- Define and govern identity security controls, including Conditional Access, multifactor authentication, passwordless authentication, Privileged Identity Management, Identity Protection, access reviews, and entitlement management.
- Direct identity lifecycle engineering for joiner, mover, and leaver processes, automated provisioning and deprovisioning, role-based access, group governance, and integration with authoritative systems.
- Establish application authentication and authorization standards for SAML, OpenID Connect, OAuth, certificates, secrets, API permissions, consent, and workload identities.
- Ensure privileged access is controlled, reviewed, monitored, and auditable using least privilege and segregation-of-duties principles.
Microsoft 365 Core Services
- Provide platform ownership for Microsoft 365 tenant administration, including tenant configuration, administrative roles, domain management, service-health governance, licensing, and cross-service dependencies within the defined scope.
- Own the Exchange Online strategy and architecture, including mail flow, accepted domains, connectors, transport controls, authentication, hybrid dependencies, retention alignment, and third-party email security integration.
- Lead major tenant and messaging initiatives, including migrations, acquisitions, domain changes, service consolidations, security enhancements, and platform lifecycle activities.
- Monitor Microsoft roadmaps, advisories, and service changes and coordinate impact assessments, testing, communications, and adoption planning for in-scope services.
- Maintain clear service boundaries with the owners of SharePoint Online, Microsoft Teams, Power Apps, Power Automate, and the Power Platform suite.
Security, Compliance, Risk & Resilience
- Maintain the Microsoft cloud security baseline in partnership with Cybersecurity through policy, secure configuration standards, identity controls, encryption, key management, centralized logging, and posture assessment.
- Own remediation plans for platform-level findings from audits, risk assessments, configuration reviews, penetration tests, and internal control evaluations.
- Define resilience and continuity requirements, including regional strategy, recovery objectives, configuration recovery, dependency mapping, emergency access, and service continuity procedures.
- Ensure architecture decisions and controls are documented and auditable through current standards, diagrams, decision records, control evidence, exception approvals, and lifecycle documentation.
Governance, Automation & Financial Management
- Establish platform guardrails using Azure Policy, RBAC, privileged workflows, resource locks, tagging, budgets, quotas, approved service catalogs, and automated compliance checks.
- Drive infrastructure-as-code and policy-as-code adoption using approved tools such as Bicep, Terraform, PowerShell, Microsoft Graph, Azure DevOps, or GitHub-based pipelines.
- Own cloud financial governance, including cost allocation, forecasting, showback or chargeback support, reservations, savings plans, licensing optimization, consumption analysis, and waste reduction.
- Maintain a platform lifecycle and technical-debt plan covering unsupported configurations, legacy authentication, expiring credentials, deprecated services, policy exceptions, and modernization priorities.
- Define performance and health indicators for service quality, identity risk, device compliance, configuration compliance, security posture, cost, capacity, and technical debt without performing daily monitoring activities.
Operational Oversight & Service Accountability
- Establish the operating model and RACI across cloud engineering, endpoint operations, infrastructure operations, service desk, Cybersecurity, application teams, and managed service providers.
- Set technical standards and service expectations for teams performing server provisioning, monitoring, backups, patching, routine incident response, and other day-to-day operational activities.
- Provide senior escalation and problem-management leadership for complex, recurring, or platform-wide incidents, focusing on root cause, architectural remediation, risk reduction, and prevention of recurrence.
- Lead governance and service reviews covering roadmap progress, security posture, cost, service performance, risk, lifecycle, vendor delivery, and corrective actions.
Team, Vendor & Stakeholder Leadership
- Lead, coach, and develop a small technical team by setting priorities, assigning accountability, building skills plans, managing performance, and maintaining high engineering standards.
- Remain technically engaged through architecture reviews, design decisions, escalations, proof-of-concept oversight, and mentoring while delegating execution appropriately.
- Manage strategic vendors and partners, including statements of work, deliverables, technical quality, service performance, financial commitments, risk, and knowledge transfer.
- Communicate platform risks, decisions, investments, and tradeoffs to executive and technical audiences and coordinate priorities across business and technology stakeholders.
Scope Exclusions
This role is not responsible for SharePoint Online, Microsoft Teams, Power Apps, Power Automate, or the broader Power Platform suite. It is also not the primary owner for routine server builds, virtual machine deployment fulfillment, daily alert monitoring, backup job administration, standard patch deployment, service-desk support, or first-line operational incident response. The role remains accountable for the architecture, governance, security standards, service requirements, escalation paths, and control framework that guide in-scope platform operations.
Qualifications & Experience
Required
- Proven technical leadership experience managing cloud, identity, endpoint, infrastructure, or Microsoft platform teams in an enterprise environment.
- Deep expertise across Microsoft Azure, Microsoft Intune, Microsoft Entra ID, Exchange Online, and Microsoft 365 tenant administration, including architecture, governance, security, integration, and lifecycle management.
- Strong Azure architecture experience with landing zones, subscriptions, management groups, Azure Policy, RBAC, networking, private connectivity, shared services, and hybrid integration.
- Advanced Intune experience with Windows, iOS/iPadOS, Android, Autopilot, MDM, MAM, compliance, configuration, application deployment, and endpoint security policy architecture.
- Advanced identity and access management experience with Conditional Access, MFA, passwordless authentication, PIM, Identity Protection, enterprise applications, access reviews, entitlement management, and hybrid identity.
- Strong Exchange Online and tenant administration experience including mail flow, domains, connectors, administrative roles, authentication, security dependencies, and licensing.
- Demonstrated security, compliance, and audit experience with secure baselines, least privilege, risk remediation, control evidence, and work in a regulated or complex enterprise environment.
- Experience with automation and modern engineering practices, including infrastructure as code, source control, CI/CD, scripting, APIs, and configuration management.
- Strong financial, vendor, and stakeholder management skills with the ability to present technical options, risks, and recommendations to engineering and executive audiences.
- Bachelor’s degree or equivalent experience in information technology, computer science, engineering, or a related discipline.
Preferred
- Relevant Microsoft certifications, such as Azure Solutions Architect Expert, Endpoint Administrator Associate, Identity and Access Administrator Associate, Microsoft 365 Administrator Expert, or Cybersecurity Architect Expert.
- Experience in a pharmaceutical, life sciences, healthcare, or similarly regulated environment with formal change control, data integrity, privacy, and audit-readiness expectations.
- Experience with Microsoft Defender, Microsoft Sentinel, and Microsoft Purview capabilities as they relate to in-scope cloud, endpoint, identity, messaging, security, and compliance services.
- Knowledge of recognized governance and security frameworks, such as ITIL, COBIT, NIST, CIS, Zero Trust, Microsoft Cloud Adoption Framework, and Microsoft Well-Architected Framework.
Key Competencies
- Technical leadership: Ability to challenge designs, resolve ambiguity, and establish credible engineering direction.
- Platform ownership: Accountability for strategy, security, lifecycle, service quality, risk, and continuous improvement.
- People leadership: Coaching, prioritization, delegation, performance management, and capability development.
- Strategic judgment: Balancing security, usability, cost, resilience, compliance, delivery speed, and technical debt.
- Governance and rigor: Discipline in architecture decisions, standards, documentation, change management, and audit readiness.
- Influence and communication: Effective engagement across executives, engineers, security, compliance, application teams, operations teams, and vendors.
Measures of Success
- Secure and compliant services: Azure, Intune, Entra ID, Exchange Online, and core Microsoft 365 controls remain within approved baselines, with timely risk remediation.
- Reliable platform services: Resilience, recovery, and service-quality objectives are achieved, and recurring issues are reduced through structural remediation.
- Improved identity and endpoint posture: Privileged access, legacy authentication, stale identities, excessive permissions, and noncompliant devices are measurably reduced.
- Effective governance: Cloud and endpoint changes consistently follow approved architecture, identity, security, lifecycle, and financial controls.
- Cost and license optimization: Azure consumption and Microsoft licensing are forecasted, allocated, governed, and continuously optimized.
- Engineering maturity: Automation, reusable patterns, policy as code, documentation, and self-service capabilities improve consistency and delivery speed.
- Strong team and partner performance: Staff and vendors deliver high-quality outcomes with clear ownership, current skills, and measurable accountability.
- Stakeholder confidence: Leaders and technical partners receive clear reporting, timely decisions, transparent risk management, and predictable roadmaps.
Disclaimer: The above statements are intended to describe the general nature and level of work performed by employees assigned to this job. They are not intended to be an exhaustive list of all duties, responsibilities, and qualifications. Management reserves the right to change or modify such duties as required.
Incyte Corporation is committed to creating a diverse environment and is proud to be an equal opportunity employer.
We Respect Your Privacy
Learn more at: http://www.incyte.com/privacy-policy
The Incyte hiring organization processes your personal data to manage your job application in order to enter into an employment relationship with you if you are the successful candidate.During the process, you may be asked to respond to questions that will screen out your application if you do not meet certain objective criteria required by the job. You can learn more about this process here.
You may have the right to access, delete, restrict, edit, move, or object to the use of your personal data. You may also have a right to report concerns to the authority responsible for data privacy in the country where the position is based or where you live or work.
You can learn more about Incyte’s data protection practices here. By accessing this link you can learn about the types of personal data we collect, how we use it, whether collection and processing is optional, sources of the personal data we process, how it is shared, where it is stored or transferred to, how long we keep it, and contact information for Incyte, Incyte’s data protection officer, and your supervisory authority (if applicable).
Please contact privacy@incyte.com if you have any questions or concerns or would like to exercise your rights.