The Microsoft System Administrator is responsible for administering and supporting Microsoft 365, Azure, Endpoint, identity and security platforms to protect organizational systems, data, and users. This role monitors security posture, supports compliance requirements, responds to security alerts, maintains secure configurations, and partners with IT teams to ensure reliable and secure technology services across Centers for Independence. This role also supports on-premises servers.
Essential Job Functions:(Reasonable accommodation may be made to enable individuals with disabilities to perform these essential functions.)
- Administer Microsoft Entra ID, conditional access, MFA, sign-in risk policies, identity protection, service accounts, app registrations, managed identities, access reviews, align platform with least privilege access model, enforce (PIM) Privileged Identify Management, and identity access management configuration.
- Administer Microsoft Defender for Office 365, anti-phishing protections, Safe Links, Safe Attachments, Microsoft Purview DLP, retention policies, and external sharing governance for email, Teams, SharePoint, and related collaboration platforms.
- Manage Intune security baselines, endpoint onboarding, encryption, firewall settings, device compliance, alert response, endpoint reporting, vulnerability exposure, and patch prioritization.
- Monitor Microsoft Secure Score and Defender for Cloud recommendations; manage Azure secure score, Azure role assignments, Azure Policy compliance, network security groups, firewall rules, Key Vault access policies, and related cloud security remediation.
- Monitor security alerts, investigate potential threats, coordinate response activities, document findings, escalate risks, and support timely remediation with internal teams and external partners.
- Maintain documentation of security configurations, access reviews, remediation activities, compliance controls, and audit evidence; prepare reports for leadership on security status, trends, risks, and progress.
- Provide systems administration support for security-related platforms, assist with configuration changes, troubleshoot access and device compliance issues, support infrastructure projects, and collaborate with IT teams to maintain secure and reliable technology services.
- Participate in the IT on-call rotation to provide after-hours support, respond to urgent system or security issues, escalate incidents as appropriate, and support continuity of technology services.
- Server Management on Windows Operating Systems, working with active directory and group policies
- Perform other job-related duties as assigned to support departmental goals, organizational priorities, and the overall mission of Centers for Independence.
Required Education, Experience, Certifications, Licensure and Credentials: (Where appropriate, education and/or experience may be substituted)
Minimum Required Education: Associate degree in information technology, cybersecurity, computer science, or a related field; equivalent education, training, or experience may be considered.
Minimum Required Experience: a combination of education, certificates, or hands on experience totaling 7 years in administering Microsoft 365 and Azure security technologies, including Entra ID, conditional access, MFA, privileged access management, Microsoft Defender, Intune endpoint compliance, Purview DLP and retention, SharePoint/Teams external sharing governance, vulnerability management, Azure role assignments, Azure Policy, and Key Vault access controls.
Required License – Certification – Registration:Microsoft security, identity, or cloud certifications strongly preferred.
Travel Type (local): Less than 10%
Required Valid Driver’s License: Valid driver’s license
Required Auto Insurance: Vehicle liability insurance in accordance with Agency policy
Knowledge, Skills, & Abilities:- Working knowledge of Microsoft Entra ID, conditional access, MFA, identity protection, privileged access management, and least privilege security practices.
- Ability to perform access reviews, identify stale or excessive permissions, and support secure identity and access governance.
- Knowledge of service accounts, app registrations, managed identities, authentication methods, and secure permission management.
- Experience with Microsoft Defender security tools, including Defender for Office 365, endpoint alert response, anti-phishing protections, Safe Links, and Safe Attachments.
- Knowledge of Microsoft Purview capabilities, including data loss prevention, retention policies, compliance support, and eDiscovery-related controls.
- Ability to configure, monitor, and report on Intune security baselines, endpoint compliance, encryption, firewall settings, and device remediation activities.
- Knowledge of SharePoint and Teams external sharing controls and the ability to audit access against organizational policies.
- Ability to review Microsoft Secure Score and Defender for Cloud recommendations, prioritize security improvements, and track progress over time.
- Knowledge of Azure security controls, including role assignments, Azure Policy compliance, network security groups, firewall rules, Key Vault access policies, and vulnerability remediation.
- Strong analytical, documentation, communication, and follow-through skills with the ability to escalate risks, report status, and coordinate remediation with technical teams.
Physical Requirements, Visual Acuity, and Work Conditions:
Physical Requirements: Ability to sit for extended periods while working at a computer workstation; regularly view and work from a computer screen; use hands and fingers for keyboarding, mouse use, and related computer tasks; and occasionally lift, carry, push, or pull equipment or materials weighing up to 50 pounds.
Visual Acuity: The worker is required to have close visual acuity to perform an activity such as preparing and analyzing data and figures; transcribing; viewing a computer terminal.
Working Conditions: None: The worker is not substantially exposed to adverse environmental conditions.
Skills Required
- Associate degree in information technology, cybersecurity, computer science, or related field (or equivalent education/training/experience)
- Seven years administering Microsoft 365 and Azure security technologies
- Experience administering Microsoft Entra ID, conditional access, MFA, sign-in risk, identity protection, PIM, service accounts, app registrations, and managed identities
- Experience with Microsoft Defender for Office 365 and Defender endpoint tools including anti-phishing, Safe Links, Safe Attachments, and alert response
- Experience managing Intune security baselines, endpoint onboarding, device compliance, encryption, firewall settings, and patch prioritization
- Knowledge and implementation experience with Microsoft Purview DLP, retention policies, eDiscovery, and external sharing governance for SharePoint and Teams
- Experience with Azure security controls including Azure Policy, role assignments, Defender for Cloud, Key Vault access policies, network security groups, and firewall rules
- Server management on Windows OS, Active Directory administration, and Group Policy management
- Valid driver's license and vehicle liability insurance per agency policy
- Microsoft security, identity, or cloud certifications
What We Do
Founded in 1938 in Milwaukee, Centers for Independence (CFI) is a leading nonprofit dedicated to assisting people of all ages and abilities in achieving their fullest level of independence. CFI offers over 30 life-changing programs, including behavioral health and crisis resources, support and advocacy for people with disabilities, and services for children's health and well-being, fostering healthy, hopeful, and inclusive communities.






