Systems Administrator - Endpoint & Identity

Posted 2 Days Ago
Hiring Remotely in United States
Remote
Mid level
Artificial Intelligence • Healthtech • Telehealth
The Role
Administers Microsoft 365, Intune, Entra ID, and Windows/macOS endpoints in a HIPAA-regulated remote environment. Manages identity lifecycle, MFA, Conditional Access, encryption, compliance, DLP, provisioning, endpoint security, vulnerability remediation, audits, asset logistics, and advanced desktop support. Automates administrative tasks with PowerShell, maintains documentation and runbooks, supports incident response, and coordinates with infrastructure and security teams. Occasional after-hours maintenance and minimal travel are required.
Summary Generated by Built In

Primary Job Function:

Systems Administrator responsible for the administration, security, and support of the enterprise endpoint fleet and identity platform in a HIPAA-regulated environment. Responsibilities include Microsoft 365 and Microsoft Intune administration; Entra ID identity and access management; Windows and macOS device management and desktop support; endpoint security and compliance controls protecting Protected Health Information (PHI); administrative automation; and creation and maintenance of documentation including SOPs and runbooks. This is a fully remote position, and all provisioning, administration, and support are performed remotely.

Essential Job Functions:

  • Administers Microsoft 365 tenant services, including Exchange Online, SharePoint/OneDrive, and Teams.
  • Owns Microsoft Intune administration across Windows and macOS, including device enrollment, configuration and compliance policies, application deployment, patch rings, and update management.
  • Performs zero-touch provisioning through Windows Autopilot and Apple Business Manager so that endpoints ship directly to remote employees and are production-ready at first login.
  • Maintains standardized, reproducible device builds and reduces configuration drift across the fleet.
  • Coordinates endpoint hardware logistics with vendors and depot partners, including procurement, drop-shipping, RMAs, and the secure return or disposal of devices from departing employees.
  • Administers Entra ID, including users, groups, roles, licensing, SSO integrations, and application registrations.
  • Designs, tests, deploys, and tunes Conditional Access and multi-factor authentication policies.
  • Executes identity lifecycle management, including automated onboarding, role changes, and same-day access revocation at offboarding.
  • Enforces least-privilege and role-based access across Microsoft 365 and integrated SaaS applications, and conducts periodic access reviews and user access recertification.
  • Configures and maintains endpoint controls supporting HIPAA Security Rule safeguards, including access control, automatic logoff, audit logging, and encryption.
  • Enforces full-disk encryption on all endpoints (BitLocker and FileVault) and manages key escrow and recovery.
  • Maintains data loss prevention and device compliance policies that keep Protected Health Information (PHI) on managed, compliant devices.
  • Executes remote lock and wipe for lost, stolen, or compromised devices, and supports incident response and breach investigation with device and access log evidence.
  • Applies and maintains endpoint security baselines, and tracks and remediates vulnerability findings across the fleet.
  • Maintains documentation and produces evidence for HIPAA audits, risk assessments, SOC 2 reviews, and customer security questionnaires.
  • Ensures the rigorous application of Information Security/Information Assurance policies, principles, and practices in the delivery of systems, applications, and services.
  • Serves as the escalation point for advanced desktop support across Windows and macOS, including operating system, application, authentication, VPN, network connectivity, printing, and hardware issues, all diagnosed remotely.
  • Manages the support ticket queue against defined service level agreements and communicates clearly with non-technical staff, primarily in writing.
  • Develops and maintains standard operating procedures, runbooks, internal documentation, and end-user knowledge base articles.
  • Reads and writes PowerShell scripts to automate repetitive administrative work. Python is nice to have but not required.
  • Tracks hardware, software, and license inventory across the full asset lifecycle.
  • Interfaces with internal and external Network Engineers, Security, and Application teams to optimize systems use and configuration.
  • Provides technical knowledge and recommendations to staff members as required.
  • Some after-hours work will be required for maintenance, patching, and incident response.
  • Performs other related duties as assigned.
  • Ensures the rigorous application of Information Security/Information Assurance policies, principles, and practices in the delivery of systems, applications, and services.
  • Serves as the escalation point for advanced desktop support across Windows and macOS, including operating system, application, authentication, VPN, network connectivity, printing, and hardware issues, all diagnosed remotely.
  • Manages the support ticket queue against defined service level agreements and communicates clearly with non-technical staff, primarily in writing.
  • Develops and maintains standard operating procedures, runbooks, internal documentation, and end-user knowledge base articles.
  • Reads and writes PowerShell scripts to automate repetitive administrative work. Python is nice to have but not required.
  • Tracks hardware, software, and license inventory across the full asset lifecycle.
  • Interfaces with internal and external Network Engineers, Security, and Application teams to optimize systems use and configuration.
  • Provides technical knowledge and recommendations to staff members as required.
  • Some after-hours work will be required for maintenance, patching, and incident response.
  • Performs other related duties as assigned.

Experience/Education

  • Working understanding of HIPAA and the handling of Protected Health Information (PHI) in an end-user computing environment.

General Experience:

  • 3-6 years' experience in IT systems administration, including hands-on administration of Microsoft 365 and Microsoft Intune in a production environment.
  • 3 years' experience serving as a direct technical interface to internal and external customers.
  • Demonstrated desktop support experience on both Windows and macOS.
  • Working knowledge of networking fundamentals, including DNS, DHCP, TCP/IP, VPN, and the remote diagnosis of home network and connectivity issues.
  • Ability to read and write PowerShell scripts for administrative automation.
  • Excellent written communication and self-directed work habits, with sound judgment about when to escalate.

SPECIALIZED EXPERIENCE:

  • Demonstrated experience in a majority of the following:

  • Day-to-day administration of both Windows and macOS endpoints, rather than depth in one platform with limited exposure to the other.
  • Entra ID or Active Directory administration, including SSO, MFA, and Conditional Access.
  • Work in a HIPAA compliant environment, including endpoint controls supporting the HIPAA Security Rule.
  • Endpoint encryption and key escrow (BitLocker and FileVault).
  • Zero-touch provisioning with Windows Autopilot and Apple Business Manager.
  • macOS management at scale with Jamf, Kandji, or a comparable platform.
  • SaaS identity governance or SCIM-based user provisioning.
  • Endpoint detection and response (EDR), SIEM, or vulnerability management tooling.
  • Supporting a fully distributed, remote workforce.
  • Supporting HIPAA, HITRUST, or SOC 2 audits.

Licensure and/or Certification Requirements:

  • Microsoft MD-102 (Endpoint Administrator Associate), or 3+ years hands-on endpoint administration experience.
  • Microsoft SC-300, Microsoft AZ-104, or Apple Certified Support Professional preferred.

Must be a U.S. citizen residing in the continental United States and maintain a suitable home work environment with reliable high-speed internet.

Primarily a stationary role performed at a computer workstation, with extended periods of computer use.

Occasional lifting and handling of computer equipment up to 25 pounds.

Some after-hours availability required for maintenance, patching, and incident response.

Minimal travel required.

Skills Required

  • 3-6 years of IT systems administration experience, including hands-on Microsoft 365 and Microsoft Intune administration in production
  • 3 years of experience serving as a direct technical interface to internal and external customers
  • Demonstrated desktop support experience with both Windows and macOS
  • Working knowledge of DNS, DHCP, TCP/IP, VPN, and remote diagnosis of connectivity issues
  • Ability to read and write PowerShell scripts for administrative automation
  • Working understanding of HIPAA and Protected Health Information handling in an end-user computing environment
  • Experience administering Windows and macOS endpoints, Entra ID or Active Directory, SSO, MFA, and Conditional Access
  • Experience with endpoint controls supporting the HIPAA Security Rule
  • Experience with endpoint encryption and key escrow using BitLocker and FileVault
  • Experience with zero-touch provisioning using Windows Autopilot and Apple Business Manager
  • Experience managing macOS at scale with Jamf, Kandji, or a comparable platform
  • Experience with SaaS identity governance or SCIM-based user provisioning
  • Experience with EDR, SIEM, or vulnerability management tooling
  • Experience supporting a fully distributed remote workforce
  • Experience supporting HIPAA, HITRUST, or SOC 2 audits
  • Microsoft MD-102 certification, or 3+ years of hands-on endpoint administration experience
  • Microsoft SC-300, Microsoft AZ-104, or Apple Certified Support Professional certification
  • Python experience
  • U.S. citizenship and residence in the continental United States
  • Suitable home work environment with reliable high-speed internet
  • Ability to handle occasional lifting of computer equipment up to 25 pounds
  • Availability for some after-hours maintenance, patching, and incident response
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
311 Employees
Year Founded: 2002

What We Do

AMC Health is a virtual care and remote patient monitoring company serving health plans, health systems, hospitals, and government programs. Its end-to-end solution combines in-home medical devices, real-time physiometric data, predictive AI and analytics, and nurse-led clinical care to support earlier intervention, reduce care gaps, and improve outcomes for people managing chronic conditions at home. The company has operated since 2002 and staffs U.S.-based clinical teams.

Similar Jobs

Afterpay Logo Afterpay

Program Manager

Fintech • Payments • Software • Financial Services
Remote or Hybrid
2 Locations
900 Employees
136K-245K Annually

TIDAL Logo TIDAL

Creative Director

Consumer Web • Information Technology • Mobile • Music • News + Entertainment • Software
Remote or Hybrid
New York, NY, USA
450 Employees
252K-377K Annually

Square Logo Square

Account Executive

eCommerce • Fintech • Hardware • Payments • Software • Financial Services
Remote or Hybrid
Everett, WA, USA
12000 Employees
129K-233K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Inside Sales Representative

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
9 Locations
40000 Employees
45K-85K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account