Systems Administrator – Endpoint, Identity

Posted 4hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Systems Administrator securing Microsoft endpoints and identities for a HIPAA-regulated caregiving company. Managing Intune, Entra ID, compliance, automation, and remote support.

Responsibilities:

  • Administer Microsoft 365 tenant services, including Exchange Online, SharePoint/OneDrive, and Teams
  • Administer Microsoft Intune across Windows and macOS, including enrollment, configuration and compliance policies, application deployment, patch rings, and updates
  • Perform zero-touch provisioning through Windows Autopilot and Apple Business Manager
  • Maintain standardized device builds and reduce configuration drift
  • Coordinate endpoint hardware logistics, procurement, drop-shipping, RMAs, and secure device returns or disposal
  • Administer Entra ID users, groups, roles, licensing, SSO integrations, and application registrations
  • Design, test, deploy, and tune Conditional Access and multi-factor authentication policies
  • Execute identity lifecycle management for onboarding, role changes, and offboarding access revocation
  • Enforce least-privilege and role-based access and conduct periodic access reviews
  • Maintain endpoint controls supporting HIPAA Security Rule safeguards
  • Enforce BitLocker and FileVault encryption and manage key escrow and recovery
  • Maintain data loss prevention and device compliance policies protecting PHI
  • Execute remote lock and wipe and support incident response and breach investigations
  • Apply endpoint security baselines and remediate vulnerability findings
  • Maintain documentation and produce evidence for HIPAA audits, risk assessments, SOC 2 reviews, and customer security questionnaires
  • Provide advanced remote desktop support for Windows and macOS issues
  • Manage support tickets against service level agreements and communicate with non-technical staff
  • Develop SOPs, runbooks, internal documentation, and knowledge base articles
  • Read and write PowerShell scripts to automate administrative work
  • Track hardware, software, and license inventory across the asset lifecycle
  • Interface with Network Engineering, Security, and Application teams
  • Provide technical knowledge and recommendations to staff members
  • Perform maintenance, patching, and incident response after hours as needed

Requirements:

  • 3–6 years' experience in IT systems administration, including hands-on administration of Microsoft 365 and Microsoft Intune in a production environment
  • 3 years' experience serving as a direct technical interface to internal and external customers
  • Demonstrated desktop support experience on both Windows and macOS
  • Working understanding of HIPAA and handling of Protected Health Information (PHI) in an end-user computing environment
  • Working knowledge of DNS, DHCP, TCP/IP, VPN, and remote diagnosis of home network and connectivity issues
  • Ability to read and write PowerShell scripts for administrative automation
  • Excellent written communication and self-directed work habits, with sound judgment about when to escalate
  • Experience with a majority of specialized endpoint, identity, security, provisioning, SaaS governance, audit, and distributed-workforce areas listed in the posting
  • Microsoft MD-102, or 3+ years hands-on endpoint administration experience
  • Microsoft SC-300, Microsoft AZ-104, or Apple Certified Support Professional preferred
  • Must be a U.S. citizen residing in the continental United States
  • Must maintain a suitable home work environment with reliable high-speed internet
  • Primarily stationary computer-workstation role with extended computer use
  • Occasional lifting and handling of computer equipment up to 25 pounds

Benefits:

  • Fully remote position
  • Some after-hours availability for maintenance, patching, and incident response
  • Minimal travel required