IT Systems Administrator (62996)

Posted Yesterday
Be an Early Applicant
17602, Lancaster, PA, USA
In-Office
Senior level
Healthtech • Social Impact
The Role
Manage and secure a hybrid Microsoft environment: administer on-prem AD and GPOs; operate Azure AD/Entra ID, Microsoft 365, Intune/Endpoint Manager; automate with PowerShell; implement identity controls (MFA, conditional access, PIM), DLP, and Defender/Sentinel monitoring; collaborate with networking/security teams and provide after-hours support as needed.
Summary Generated by Built In

Our Mission, Vision, & Model of Care


At Union Community Care, our purpose is at the forefront of all that we do: we stand for whole health to help you live your fullest life.


We envision vibrant and healthy communities supported by inclusive healthcare that embraces each member’s unique culture, needs, and values, and emboldens them to make healthful choices that fuel their well-being and the well-being of others.


We believe in whole health. This means we address and heal disease but equally important, we work at the causes of the causes, the social ills that must be addressed to achieve true equity.


We listen, learn, and embrace the complex lives and unique strengths of our patients, and we work hard to break down all barriers to care. This means we look through a grassroots lens. We connect with our communities because we are our communities. Each of us is a neighbor, a friend, a family member, and together, we are a trusted community health center.

Qualifications

JOB SUMMARY

We are seeking a seasoned technician with deep hands-on expertise in Microsoft identity, endpoint, and cloud administration to manage and secure our hybrid environment. This role focuses on Active Directory, Group Policy, Microsoft 365, Azure tenant operations, Intune/MDM, identity governance, and related security controls. The ideal candidate is a pragmatic problem-solver who can design, implement, maintain, and troubleshoot complex Microsoft-centric infrastructure while collaborating with security, networking, and operations teams. Healthcare/Epic experience a plus, but not required. 


SPECIFIC JOB DUTIES

  1. Administer and maintain on-premises Active Directory (AD) domains, including user/computer object management, OU design, Group Policy Objects (GPOs), and replication health. 
  1. Design, test, deploy, and troubleshoot Group Policy configurations for security baselines, software deployment, and configuration management. 
  1. Write, maintain, and optimize PowerShell scripts and modules for automation of AD, Azure AD / Entra ID, Microsoft 365, and Intune tasks. 
  1. Manage Microsoft 365 tenants: Exchange Online, SharePoint Online, Teams, OneDrive, licensing, and service health. 
  1. Administer Azure AD / Microsoft Entra ID (users, groups, app registrations, conditional access, PIM, identity protection, hybrid identity with Entra Connect). 
  1. Own Intune (Microsoft Endpoint Manager) and MDM operations: device enrollment, configuration profiles, compliance policies, application deployment, and Autopilot. 
  1. Support identity lifecycle management, single sign-on (SSO), multifactor authentication (MFA), and passwordless initiatives. 
  1. Implement and monitor Data Loss Prevention (DLP) policies across Microsoft 365 and related platforms. 
  1. Assist with network-related aspects of identity and endpoint management (DNS, DHCP, VPN, certificate services, firewall rules affecting authentication and device connectivity). 
  1. Contribute to cybersecurity posture through hardening of AD/Azure AD, privileged access management, logging/monitoring (including Microsoft Defender and Sentinel where applicable), and response to identity-related incidents. 
  1. Document configurations, procedures, and runbooks; participate in change management and after-hours support as needed. 
  1. Collaborate with support, networking, and application teams on projects involving identity, endpoints, and cloud services. 
  2. Performs other work-related duties as assigned

 

POSITION REQUIREMENTS

  • 5+ years of progressive hands-on experience administering Active Directory and Group Policy in production environments. 
  • Strong PowerShell scripting skills with proven ability to automate AD, Entra ID, Microsoft 365, and Intune tasks. 
  • Demonstrated experience managing Microsoft 365 tenants and Azure AD / Entra ID (including hybrid identity scenarios). 
  • Practical experience with Microsoft Intune / Endpoint Manager and mobile device management (MDM). 
  • Working knowledge of identity and access management principles, conditional access, MFA, and privileged identity management. 
  • Familiarity with Data Loss Prevention (DLP) concepts and Microsoft 365 compliance tools. 
  • Understanding of core networking concepts relevant to identity and device management (DNS, certificates, VPN, firewalls). 
  • Solid foundation in cybersecurity best practices for identity, endpoints, and hybrid environments. 
  • Ability to troubleshoot complex issues across on-premises, hybrid, and cloud Microsoft stacks. 
  • Clear written and verbal communication skills; ability to document technical work and explain issues to both technical and non-technical audiences. 
  • Ability to work independently and collaboratively in a fast-paced environment. 
  • Occasional after-hours work required for system maintenance and emergency response. 

 

PREFERRED QUALIFICATIONS

  • Microsoft certifications such as AZ-104, MS-102, SC-300, MD-102, or equivalent practical experience. 
  • Experience with Microsoft Defender for Endpoint / Identity, Microsoft Sentinel, or similar security tooling. 
  • Exposure to certificate services (AD CS / PKI), Entra ID app proxy, or advanced conditional access scenarios. 
  • Familiarity with other identity or MDM platforms (e.g., Okta, Jamf) as complementary knowledge. 
  • Experience in regulated or highly secured environments (compliance frameworks such as NIST, CIS, and HIPAA requirements). 
  • Scripting beyond PowerShell (e.g., Graph API, Azure CLI, or basic Python) is a plus. 

 

ESSENTIAL FUNCTIONS

In order to fulfill the requirements of this position, duties 1-13 are considered essential functions of the job.

 

ORGANIZATIONAL INVOLVEMENT

This position is required to participate in mandatory all staff meetings, team meetings and trainings.

Skills Required

  • 5+ years administering Active Directory and Group Policy in production environments
  • Strong PowerShell scripting skills to automate AD, Entra ID, Microsoft 365, and Intune tasks
  • Experience managing Microsoft 365 tenants (Exchange Online, SharePoint Online, Teams, OneDrive) and Azure AD / Entra ID
  • Practical experience with Microsoft Intune / Endpoint Manager and mobile device management (MDM)
  • Working knowledge of identity and access management principles, conditional access, MFA, and privileged identity management
  • Familiarity with Data Loss Prevention (DLP) concepts and Microsoft 365 compliance tools
  • Understanding of DNS, DHCP, VPN, certificate services, and firewall rules relevant to identity and device management
  • Foundational cybersecurity best practices for identity, endpoints, and hybrid environments
  • Ability to troubleshoot complex issues across on-premises, hybrid, and cloud Microsoft stacks
  • Clear written and verbal communication skills and ability to document technical work
  • Ability to work independently and collaboratively in a fast-paced environment
  • Occasional after-hours work required for system maintenance and emergency response
  • Microsoft certifications such as AZ-104, MS-102, SC-300, MD-102 or equivalent practical experience
  • Experience with Microsoft Defender for Endpoint / Identity and Microsoft Sentinel
  • Exposure to AD CS / PKI, Entra ID app proxy, or advanced conditional access scenarios
  • Familiarity with other identity or MDM platforms (Okta, Jamf)
  • Experience in regulated or highly secured environments (NIST, CIS, HIPAA)
  • Scripting beyond PowerShell (Graph API, Azure CLI, or basic Python)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
380 Employees
Year Founded: 1969

What We Do

Union Community Care is a federally qualified health center and nationally recognized Patient-Centered Medical Home dedicated to providing integrated, affordable, and inclusive care. They provide a comprehensive range of services, including medical, urgent, dental, behavioral health, and social support. Their mission is to spark equity through patient-led healthcare that welcomes and strengthens their communities by integrating body and mind.

Similar Jobs

BlackLine Logo BlackLine

Artificial Intelligence Engineer

Cloud • Fintech • Information Technology • Machine Learning • Software • App development • Generative AI
Remote or Hybrid
USA
1810 Employees
128K-160K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Technical Director, Commercial Auto

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
8 Locations
40000 Employees
106K-197K Annually

Enverus Logo Enverus

Owner Relations Agent - 25270

Big Data • Information Technology • Software • Analytics • Energy
In-Office or Remote
3 Locations
1800 Employees
43K-58K Annually

Enverus Logo Enverus

Consultant

Big Data • Information Technology • Software • Analytics • Energy
In-Office or Remote
5 Locations
1800 Employees
120K-135K Annually

Similar Companies Hiring

Playground (tryplayground.com) Thumbnail
Kids + Family • Payments • Social Impact • Software
New York City, New York
80 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account