Systems Administrator – Endpoint, Identity
Posted 4hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Remote Systems Administrator managing Microsoft endpoints, Intune, Entra ID, and HIPAA security for a caregiving provider. Automating provisioning, access, compliance, and remote support.
Responsibilities:
- Administer Microsoft 365 tenant services, including Exchange Online, SharePoint/OneDrive, and Teams
- Administer Microsoft Intune across Windows and macOS, including enrollment, configuration and compliance policies, application deployment, patch rings, and updates
- Perform zero-touch provisioning through Windows Autopilot and Apple Business Manager
- Maintain standardized device builds and reduce configuration drift
- Coordinate endpoint hardware logistics, procurement, drop-shipping, RMAs, and secure device return or disposal
- Administer Entra ID users, groups, roles, licensing, SSO integrations, and application registrations
- Design, test, deploy, and tune Conditional Access and MFA policies
- Execute identity lifecycle management for onboarding, role changes, and offboarding access revocation
- Enforce least-privilege and role-based access and conduct periodic access reviews
- Configure endpoint controls supporting HIPAA Security Rule safeguards
- Enforce BitLocker and FileVault encryption and manage key escrow and recovery
- Maintain DLP and device compliance policies protecting PHI
- Execute remote lock and wipe and support incident response and breach investigations
- Maintain endpoint security baselines and remediate vulnerability findings
- Produce documentation and audit evidence for HIPAA, risk assessments, SOC 2 reviews, and customer security questionnaires
- Serve as escalation point for advanced remote Windows and macOS desktop support
- Manage support ticket queues against SLAs
- Develop SOPs, runbooks, internal documentation, and knowledge base articles
- Read and write PowerShell scripts to automate administrative work
- Track hardware, software, and license inventory across the asset lifecycle
- Interface with Network Engineering, Security, and Application teams
- Provide technical knowledge and recommendations to staff members
- Perform maintenance, patching, incident response, and other related duties
Requirements:
- 3–6 years' experience in IT systems administration, including hands-on administration of Microsoft 365 and Microsoft Intune in a production environment
- 3 years' experience serving as a direct technical interface to internal and external customers
- Demonstrated desktop support experience on both Windows and macOS
- Working understanding of HIPAA and handling of Protected Health Information (PHI) in an end-user computing environment
- Working knowledge of DNS, DHCP, TCP/IP, VPN, and remote diagnosis of home network and connectivity issues
- Ability to read and write PowerShell scripts for administrative automation
- Excellent written communication and self-directed work habits, with sound judgment about when to escalate
- Experience with a majority of: Entra ID or Active Directory administration, SSO, MFA, Conditional Access, HIPAA-compliant endpoint controls, BitLocker, FileVault, Windows Autopilot, Apple Business Manager, Jamf, Kandji or comparable macOS management, SaaS identity governance, SCIM-based provisioning, EDR, SIEM, vulnerability management, distributed remote workforce support, and HIPAA/HITRUST/SOC 2 audits
- Microsoft MD-102 or 3+ years hands-on endpoint administration experience
- Microsoft SC-300, Microsoft AZ-104, or Apple Certified Support Professional preferred
- Must be a U.S. citizen residing in the continental United States
- Must maintain a suitable home work environment with reliable high-speed internet
- Primarily a stationary role at a computer workstation with extended computer use
- Occasional lifting and handling of computer equipment up to 25 pounds
- Some after-hours availability required
Benefits:
- Fully remote position
- Some after-hours availability for maintenance, patching, and incident response
- Minimal travel required















