Systems Administrator – Endpoint & Identity
Posted 4hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Systems Administrator managing Microsoft 365, Intune, and Entra ID for a HIPAA-regulated caregiving company. Securing distributed Windows and macOS endpoints while supporting remote employees and audits.
Responsibilities:
- Administer Microsoft 365 tenant services, including Exchange Online, SharePoint/OneDrive, and Teams
- Administer Microsoft Intune across Windows and macOS, including enrollment, configuration and compliance policies, application deployment, patch rings, and updates
- Perform zero-touch provisioning through Windows Autopilot and Apple Business Manager
- Maintain standardized device builds and reduce configuration drift
- Coordinate endpoint hardware logistics, procurement, drop-shipping, RMAs, and secure device return or disposal
- Administer Entra ID users, groups, roles, licensing, SSO integrations, and application registrations
- Design, test, deploy, and tune Conditional Access and MFA policies
- Execute identity lifecycle management, including onboarding, role changes, and access revocation during offboarding
- Enforce least-privilege and role-based access; conduct access reviews and user access recertification
- Configure endpoint controls supporting HIPAA Security Rule safeguards
- Enforce BitLocker and FileVault encryption and manage key escrow and recovery
- Maintain DLP and device compliance policies protecting PHI on managed, compliant devices
- Execute remote lock and wipe for lost, stolen, or compromised devices
- Support incident response and breach investigations using device and access-log evidence
- Maintain endpoint security baselines and remediate vulnerability findings
- Maintain documentation and produce evidence for HIPAA audits, risk assessments, SOC 2 reviews, and customer security questionnaires
- Provide advanced remote desktop support for Windows and macOS issues
- Manage support tickets against SLAs and communicate with non-technical staff, primarily in writing
- Develop SOPs, runbooks, internal documentation, and end-user knowledge-base articles
- Write PowerShell scripts to automate administrative work
- Track hardware, software, and license inventory throughout the asset lifecycle
- Interface with Network Engineering, Security, and Application teams
- Provide technical knowledge and recommendations to staff
- Perform maintenance, patching, incident response, and other assigned duties, including some after-hours work
Requirements:
- 3–6 years' experience in IT systems administration, including hands-on administration of Microsoft 365 and Microsoft Intune in a production environment
- 3 years' experience serving as a direct technical interface to internal and external customers
- Demonstrated desktop support experience on both Windows and macOS
- Working understanding of HIPAA and handling Protected Health Information (PHI) in an end-user computing environment
- Working knowledge of DNS, DHCP, TCP/IP, VPN, and remote diagnosis of home network and connectivity issues
- Ability to read and write PowerShell scripts for administrative automation
- Excellent written communication and self-directed work habits, with sound judgment about when to escalate
- Experience with Entra ID or Active Directory administration, including SSO, MFA, and Conditional Access
- Experience in a HIPAA-compliant environment, including endpoint controls supporting the HIPAA Security Rule
- Experience with endpoint encryption and key escrow using BitLocker and FileVault
- Experience with zero-touch provisioning using Windows Autopilot and Apple Business Manager
- macOS management at scale with Jamf, Kandji, or a comparable platform
- Experience with SaaS identity governance or SCIM-based user provisioning
- Experience with EDR, SIEM, or vulnerability management tooling
- Experience supporting a fully distributed, remote workforce
- Experience supporting HIPAA, HITRUST, or SOC 2 audits
- Microsoft MD-102 or 3+ years of hands-on endpoint administration experience
- Must be a U.S. citizen residing in the continental United States
- Suitable home work environment with reliable high-speed internet
- Primarily stationary computer workstation role with extended computer use
- Occasional lifting and handling of computer equipment up to 25 pounds
Benefits:
- Fully remote position
- Minimal travel required
- Some after-hours availability for maintenance, patching, and incident response















