Systems Administrator – Endpoint, Identity
Posted 4hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Systems Administrator securing Microsoft endpoints and identities for a HIPAA-regulated caregiving company. Managing Intune, Entra ID, compliance, automation, and remote support.
Responsibilities:
- Administer Microsoft 365 tenant services, including Exchange Online, SharePoint/OneDrive, and Teams
- Administer Microsoft Intune across Windows and macOS, including enrollment, configuration and compliance policies, application deployment, patch rings, and updates
- Perform zero-touch provisioning through Windows Autopilot and Apple Business Manager
- Maintain standardized device builds and reduce configuration drift
- Coordinate endpoint hardware logistics, procurement, drop-shipping, RMAs, and secure device returns or disposal
- Administer Entra ID users, groups, roles, licensing, SSO integrations, and application registrations
- Design, test, deploy, and tune Conditional Access and multi-factor authentication policies
- Execute identity lifecycle management for onboarding, role changes, and offboarding access revocation
- Enforce least-privilege and role-based access and conduct periodic access reviews
- Maintain endpoint controls supporting HIPAA Security Rule safeguards
- Enforce BitLocker and FileVault encryption and manage key escrow and recovery
- Maintain data loss prevention and device compliance policies protecting PHI
- Execute remote lock and wipe and support incident response and breach investigations
- Apply endpoint security baselines and remediate vulnerability findings
- Maintain documentation and produce evidence for HIPAA audits, risk assessments, SOC 2 reviews, and customer security questionnaires
- Provide advanced remote desktop support for Windows and macOS issues
- Manage support tickets against service level agreements and communicate with non-technical staff
- Develop SOPs, runbooks, internal documentation, and knowledge base articles
- Read and write PowerShell scripts to automate administrative work
- Track hardware, software, and license inventory across the asset lifecycle
- Interface with Network Engineering, Security, and Application teams
- Provide technical knowledge and recommendations to staff members
- Perform maintenance, patching, and incident response after hours as needed
Requirements:
- 3–6 years' experience in IT systems administration, including hands-on administration of Microsoft 365 and Microsoft Intune in a production environment
- 3 years' experience serving as a direct technical interface to internal and external customers
- Demonstrated desktop support experience on both Windows and macOS
- Working understanding of HIPAA and handling of Protected Health Information (PHI) in an end-user computing environment
- Working knowledge of DNS, DHCP, TCP/IP, VPN, and remote diagnosis of home network and connectivity issues
- Ability to read and write PowerShell scripts for administrative automation
- Excellent written communication and self-directed work habits, with sound judgment about when to escalate
- Experience with a majority of specialized endpoint, identity, security, provisioning, SaaS governance, audit, and distributed-workforce areas listed in the posting
- Microsoft MD-102, or 3+ years hands-on endpoint administration experience
- Microsoft SC-300, Microsoft AZ-104, or Apple Certified Support Professional preferred
- Must be a U.S. citizen residing in the continental United States
- Must maintain a suitable home work environment with reliable high-speed internet
- Primarily stationary computer-workstation role with extended computer use
- Occasional lifting and handling of computer equipment up to 25 pounds
Benefits:
- Fully remote position
- Some after-hours availability for maintenance, patching, and incident response
- Minimal travel required















