Systems Administrator – Endpoint, Identity
Posted 4hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Systems Administrator securing Microsoft endpoints and identity for a HIPAA-regulated caregiving provider. Managing Intune, Entra ID, automation, compliance, and remote support.
Responsibilities:
- Administer Microsoft 365 tenant services, including Exchange Online, SharePoint/OneDrive, and Teams
- Administer Microsoft Intune across Windows and macOS, including enrollment, configuration and compliance policies, application deployment, patch rings, and update management
- Perform zero-touch provisioning through Windows Autopilot and Apple Business Manager
- Maintain standardized device builds and reduce configuration drift
- Coordinate endpoint hardware logistics, procurement, drop-shipping, RMAs, and secure device returns or disposal
- Administer Entra ID users, groups, roles, licensing, SSO integrations, and application registrations
- Design, test, deploy, and tune Conditional Access and MFA policies
- Execute identity lifecycle management for onboarding, role changes, and offboarding access revocation
- Enforce least-privilege and role-based access and conduct access reviews and recertification
- Configure endpoint controls supporting HIPAA Security Rule safeguards
- Enforce BitLocker and FileVault encryption and manage key escrow and recovery
- Maintain data loss prevention and device compliance policies protecting PHI
- Execute remote lock and wipe for lost, stolen, or compromised devices
- Support incident response and breach investigations using device and access-log evidence
- Maintain endpoint security baselines and remediate vulnerability findings
- Produce documentation and audit evidence for HIPAA, risk assessments, SOC 2 reviews, and customer security questionnaires
- Serve as escalation point for advanced remote Windows and macOS desktop support
- Manage support ticket queue against service-level agreements
- Develop SOPs, runbooks, internal documentation, and end-user knowledge-base articles
- Read and write PowerShell scripts to automate administrative work
- Track hardware, software, and license inventory across the asset lifecycle
- Interface with Network Engineering, Security, and Application teams
- Provide technical knowledge and recommendations to staff
Requirements:
- Working understanding of HIPAA and handling of Protected Health Information (PHI) in an end-user computing environment
- 3–6 years' experience in IT systems administration, including hands-on administration of Microsoft 365 and Microsoft Intune in a production environment
- 3 years' experience serving as a direct technical interface to internal and external customers
- Demonstrated desktop support experience on both Windows and macOS
- Working knowledge of networking fundamentals, including DNS, DHCP, TCP/IP, VPN, and remote diagnosis of home network and connectivity issues
- Ability to read and write PowerShell scripts for administrative automation
- Excellent written communication and self-directed work habits, with sound judgment about when to escalate
- Experience administering Windows and macOS endpoints
- Entra ID or Active Directory administration, including SSO, MFA, and Conditional Access
- Experience working in a HIPAA-compliant environment
- Endpoint encryption and key escrow experience with BitLocker and FileVault
- Zero-touch provisioning with Windows Autopilot and Apple Business Manager
- macOS management at scale with Jamf, Kandji, or comparable platform
- SaaS identity governance or SCIM-based user provisioning
- Endpoint detection and response (EDR), SIEM, or vulnerability management tooling
- Experience supporting a fully distributed, remote workforce
- Experience supporting HIPAA, HITRUST, or SOC 2 audits
- Microsoft MD-102 or 3+ years hands-on endpoint administration experience
- Must be a U.S. citizen residing in the continental United States
- Suitable home work environment with reliable high-speed internet
- Stationary computer-workstation role with extended computer use
- Occasional lifting and handling of computer equipment up to 25 pounds
Benefits:
- Fully remote position
- Some after-hours availability/work for maintenance, patching, and incident response
- Minimal travel required















