Systems Administrator – Endpoint, Identity

Posted 4hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Systems Administrator securing Microsoft endpoints and identity for a HIPAA-regulated caregiving company. Supporting remote employees, compliance, automation, and advanced desktop operations.

Responsibilities:

  • Administer Microsoft 365 tenant services, including Exchange Online, SharePoint/OneDrive, and Teams
  • Administer Microsoft Intune across Windows and macOS, including enrollment, configuration, compliance, application deployment, patch rings, and updates
  • Perform zero-touch provisioning through Windows Autopilot and Apple Business Manager
  • Maintain standardized device builds and reduce configuration drift
  • Coordinate endpoint hardware procurement, drop-shipping, RMAs, and secure returns/disposal
  • Administer Entra ID users, groups, roles, licensing, SSO integrations, and application registrations
  • Design, test, deploy, and tune Conditional Access and MFA policies
  • Execute identity lifecycle management for onboarding, role changes, and offboarding access revocation
  • Enforce least-privilege and role-based access and conduct access reviews
  • Configure endpoint controls supporting HIPAA Security Rule safeguards
  • Enforce BitLocker and FileVault encryption and manage key escrow/recovery
  • Maintain DLP and device compliance policies protecting PHI
  • Execute remote lock and wipe and support incident response and breach investigations
  • Maintain endpoint security baselines and remediate vulnerability findings
  • Produce documentation and audit evidence for HIPAA, risk assessments, SOC 2 reviews, and customer security questionnaires
  • Provide advanced remote desktop support for Windows and macOS issues
  • Manage support tickets against SLAs and communicate with non-technical staff
  • Develop SOPs, runbooks, internal documentation, and knowledge base articles
  • Automate administrative work with PowerShell
  • Track hardware, software, and license inventory across the asset lifecycle
  • Interface with Network Engineering, Security, and Application teams
  • Provide technical knowledge and recommendations to staff
  • Perform after-hours maintenance, patching, and incident response as needed

Requirements:

  • Working understanding of HIPAA and handling Protected Health Information (PHI) in an end-user computing environment
  • 3–6 years’ experience in IT systems administration, including hands-on Microsoft 365 and Microsoft Intune administration in production
  • 3 years’ experience serving as a direct technical interface to internal and external customers
  • Demonstrated desktop support experience on both Windows and macOS
  • Working knowledge of DNS, DHCP, TCP/IP, VPN, and remote diagnosis of home network/connectivity issues
  • Ability to read and write PowerShell scripts for administrative automation
  • Excellent written communication and self-directed work habits, with sound judgment about escalation
  • Experience with a majority of: Entra ID or Active Directory, SSO, MFA, Conditional Access, HIPAA-compliant endpoint controls, BitLocker, FileVault, Windows Autopilot, Apple Business Manager, Jamf, Kandji, SCIM, EDR, SIEM, vulnerability management, distributed workforces, HIPAA/HITRUST/SOC 2 audits
  • Microsoft MD-102 or 3+ years’ hands-on endpoint administration experience
  • Microsoft SC-300, Microsoft AZ-104, or Apple Certified Support Professional preferred
  • Must be a U.S. citizen residing in the continental United States
  • Suitable home work environment with reliable high-speed internet
  • Ability to perform a stationary computer-based role with extended computer use
  • Occasional lifting and handling of computer equipment up to 25 pounds
  • Some after-hours availability for maintenance, patching, and incident response

Benefits:

  • Fully remote position
  • Reliable high-speed internet required for home work environment
  • Minimal travel required