Systems Administrator – Endpoint, Identity
Posted 4hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Systems Administrator managing Microsoft 365, Intune, and identity platforms for HIPAA-regulated caregiving company. Securing remote Windows and macOS endpoints and supporting distributed employees.
Responsibilities:
- Administer Microsoft 365 tenant services, including Exchange Online, SharePoint/OneDrive, and Teams
- Administer Microsoft Intune across Windows and macOS, including enrollment, configuration and compliance policies, application deployment, patch rings, and update management
- Perform zero-touch provisioning through Windows Autopilot and Apple Business Manager
- Maintain standardized device builds and reduce configuration drift
- Coordinate endpoint hardware logistics, procurement, drop-shipping, RMAs, and secure device returns or disposal
- Administer Entra ID users, groups, roles, licensing, SSO integrations, and application registrations
- Design, test, deploy, and tune Conditional Access and MFA policies
- Execute identity lifecycle management, including onboarding, role changes, and access revocation during offboarding
- Enforce least-privilege and role-based access; conduct access reviews and recertification
- Configure endpoint controls supporting HIPAA Security Rule safeguards
- Enforce BitLocker and FileVault encryption and manage key escrow and recovery
- Maintain DLP and device compliance policies protecting PHI
- Execute remote lock and wipe for lost, stolen, or compromised devices
- Support incident response and breach investigations using device and access-log evidence
- Maintain endpoint security baselines and remediate vulnerability findings
- Produce documentation and audit evidence for HIPAA audits, risk assessments, SOC 2 reviews, and customer security questionnaires
- Serve as escalation point for advanced remote Windows and macOS desktop support
- Manage support ticket queues against SLAs and communicate with non-technical staff, primarily in writing
- Develop SOPs, runbooks, internal documentation, and end-user knowledge-base articles
- Write PowerShell scripts to automate administrative work
- Track hardware, software, and license inventory throughout the asset lifecycle
- Interface with Network Engineering, Security, and Application teams
- Provide technical knowledge and recommendations to staff
- Perform maintenance, patching, and incident response work after hours as required
- Perform other related duties as assigned
Requirements:
- Working understanding of HIPAA and handling Protected Health Information (PHI) in an end-user computing environment
- 3–6 years’ experience in IT systems administration, including hands-on administration of Microsoft 365 and Microsoft Intune in a production environment
- 3 years’ experience serving as a direct technical interface to internal and external customers
- Demonstrated desktop support experience on both Windows and macOS
- Working knowledge of DNS, DHCP, TCP/IP, VPN, and remote diagnosis of home network and connectivity issues
- Ability to read and write PowerShell scripts for administrative automation
- Excellent written communication and self-directed work habits, with sound judgment about when to escalate
- Experience administering Windows and macOS endpoints
- Entra ID or Active Directory administration, including SSO, MFA, and Conditional Access
- Experience in a HIPAA-compliant environment
- Endpoint encryption and key escrow using BitLocker and FileVault
- Zero-touch provisioning with Windows Autopilot and Apple Business Manager
- macOS management at scale with Jamf, Kandji, or a comparable platform
- SaaS identity governance or SCIM-based user provisioning
- Experience with EDR, SIEM, or vulnerability management tooling
- Experience supporting a fully distributed, remote workforce
- Experience supporting HIPAA, HITRUST, or SOC 2 audits
- Microsoft MD-102 or 3+ years of hands-on endpoint administration experience
- Microsoft SC-300, Microsoft AZ-104, or Apple Certified Support Professional preferred
- Must be a U.S. citizen residing in the continental United States
- Must maintain a suitable home work environment with reliable high-speed internet
- Primarily stationary computer-based work with extended periods of computer use
- Occasional lifting and handling of computer equipment up to 25 pounds
- Some after-hours availability for maintenance, patching, and incident response
Benefits:
- Fully remote position
- Minimal travel required















