Systems Administrator – Endpoint, Identity

Posted 4hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Systems Administrator managing Microsoft 365, Intune, and identity platforms for HIPAA-regulated caregiving company. Securing remote Windows and macOS endpoints and supporting distributed employees.

Responsibilities:

  • Administer Microsoft 365 tenant services, including Exchange Online, SharePoint/OneDrive, and Teams
  • Administer Microsoft Intune across Windows and macOS, including enrollment, configuration and compliance policies, application deployment, patch rings, and update management
  • Perform zero-touch provisioning through Windows Autopilot and Apple Business Manager
  • Maintain standardized device builds and reduce configuration drift
  • Coordinate endpoint hardware logistics, procurement, drop-shipping, RMAs, and secure device returns or disposal
  • Administer Entra ID users, groups, roles, licensing, SSO integrations, and application registrations
  • Design, test, deploy, and tune Conditional Access and MFA policies
  • Execute identity lifecycle management, including onboarding, role changes, and access revocation during offboarding
  • Enforce least-privilege and role-based access; conduct access reviews and recertification
  • Configure endpoint controls supporting HIPAA Security Rule safeguards
  • Enforce BitLocker and FileVault encryption and manage key escrow and recovery
  • Maintain DLP and device compliance policies protecting PHI
  • Execute remote lock and wipe for lost, stolen, or compromised devices
  • Support incident response and breach investigations using device and access-log evidence
  • Maintain endpoint security baselines and remediate vulnerability findings
  • Produce documentation and audit evidence for HIPAA audits, risk assessments, SOC 2 reviews, and customer security questionnaires
  • Serve as escalation point for advanced remote Windows and macOS desktop support
  • Manage support ticket queues against SLAs and communicate with non-technical staff, primarily in writing
  • Develop SOPs, runbooks, internal documentation, and end-user knowledge-base articles
  • Write PowerShell scripts to automate administrative work
  • Track hardware, software, and license inventory throughout the asset lifecycle
  • Interface with Network Engineering, Security, and Application teams
  • Provide technical knowledge and recommendations to staff
  • Perform maintenance, patching, and incident response work after hours as required
  • Perform other related duties as assigned

Requirements:

  • Working understanding of HIPAA and handling Protected Health Information (PHI) in an end-user computing environment
  • 3–6 years’ experience in IT systems administration, including hands-on administration of Microsoft 365 and Microsoft Intune in a production environment
  • 3 years’ experience serving as a direct technical interface to internal and external customers
  • Demonstrated desktop support experience on both Windows and macOS
  • Working knowledge of DNS, DHCP, TCP/IP, VPN, and remote diagnosis of home network and connectivity issues
  • Ability to read and write PowerShell scripts for administrative automation
  • Excellent written communication and self-directed work habits, with sound judgment about when to escalate
  • Experience administering Windows and macOS endpoints
  • Entra ID or Active Directory administration, including SSO, MFA, and Conditional Access
  • Experience in a HIPAA-compliant environment
  • Endpoint encryption and key escrow using BitLocker and FileVault
  • Zero-touch provisioning with Windows Autopilot and Apple Business Manager
  • macOS management at scale with Jamf, Kandji, or a comparable platform
  • SaaS identity governance or SCIM-based user provisioning
  • Experience with EDR, SIEM, or vulnerability management tooling
  • Experience supporting a fully distributed, remote workforce
  • Experience supporting HIPAA, HITRUST, or SOC 2 audits
  • Microsoft MD-102 or 3+ years of hands-on endpoint administration experience
  • Microsoft SC-300, Microsoft AZ-104, or Apple Certified Support Professional preferred
  • Must be a U.S. citizen residing in the continental United States
  • Must maintain a suitable home work environment with reliable high-speed internet
  • Primarily stationary computer-based work with extended periods of computer use
  • Occasional lifting and handling of computer equipment up to 25 pounds
  • Some after-hours availability for maintenance, patching, and incident response

Benefits:

  • Fully remote position
  • Minimal travel required