The Endpoint Systems Administrator is responsible for the administration, security, compliance, and lifecycle management of enterprise endpoint devices across Ellis Medicine. This role manages Microsoft Intune, Mobile Device Management (MDM), Mobile Application Management (MAM), endpoint patching, device compliance, and endpoint security controls. The position partners with Infrastructure, Network Services, Information Security, Service Desk, and Clinical Operations teams to ensure endpoint devices remain secure, reliable, compliant, and operationally efficient.
The Endpoint Systems Administrator serves as a subject matter expert for endpoint management technologies and drives continuous improvement of endpoint security posture, automation, and standardization.
EDUCATION AND EXPERIENCE REQUIREMENT(S):Education: Associate's degree in Information Technology, Computer Science, Information Systems, or related field required. Bachelor's degree preferred.
Experience: Minimum 3 years of experience supporting enterprise endpoint management platforms, including administering Microsoft Intune in a production environment, enterprise patch management solutions, Windows endpoint administration, and network access control solutions for endpoints. Experience managing mobile devices in a healthcare or regulated environment preferred.
Certification: Microsoft Certified: Endpoint Administrator Associate; Microsoft Certified: Security Administrator Associate; ITIL Foundation; CompTIA Security+; CompTIA Network+ preferred.
Core Competencies:- Strong analytical and troubleshooting skills.
- Ability to manage multiple priorities in a fast-paced healthcare environment.
- Excellent written and verbal communication skills.
- Strong customer service orientation.
- Process improvement mindset.
- Attention to detail and commitment to security best practices.
- Ability to develop and maintain technical documentation.
PRIMARY RESPONSIBILITIES OF THE POSITION:Endpoint Management:- Administer Microsoft Intune for Windows, iOS, Android, and macOS devices.
- Manage endpoint provisioning, enrollment, configuration profiles, compliance policies, and device lifecycle processes.
- Develop and maintain device standards and endpoint configuration baselines.
- Support endpoint hardware refresh and deployment initiatives.
- Administer phone carrier services and accounts
Patch and Vulnerability Management:- Administer operating system and third-party application patching processes.
- Monitor endpoint compliance and remediation activities.
- Coordinate monthly patch deployment cycles and emergency security updates.
- Identify and remediate endpoint vulnerabilities in collaboration with Information Security.
- Produce compliance and patch management reports for leadership and audit reviews.
Mobile Device Management:- Manage organizational mobile devices through Intune and related MDM platforms.
- Maintain corporate-owned and personally owned device policies.
- Configure and support Apple Business Manager and Android Enterprise integrations.
- Develop and maintain mobile security standards and controls.
- Manage application deployment and mobile device compliance requirements.
Endpoint Security:- Implement and maintain endpoint security controls and security baselines.
- Configure Conditional Access and device compliance policies.
- Manage and configure endpoint access within a NAC such as Cisco ISE.
- Support endpoint encryption, Microsoft Defender, and security hardening initiatives.
- Assist with cybersecurity investigations involving endpoint systems.
- Participate in incident response and remediation efforts.
Application and Software Management:Monitoring and Reporting:Operational Support:Required Technical Skills:- Microsoft Intune, Microsoft Endpoint Manager, Mobile Device Management (MDM), Mobile Application Management (MAM), Microsoft Entra ID (Azure AD), Microsoft 365 Administration, Windows Operating Systems, Patch Management, Group Policy, PowerShell Scripting, Microsoft Defender, Endpoint Security Controls, Device Compliance Policies, Conditional Access, Cisco ISE.
Preferred Experience:- Healthcare IT experience, Apple Business Manager, Android Enterprise, endpoint compliance auditing, vulnerability management platforms, software deployment automation, cybersecurity and regulatory compliance initiatives.
PHYSICAL REQUIREMENTS:- Ability to travel between campus locations as needed. Ability to lift and move computing equipment up to organization standards. Should be able to push/pull, lift/move computing equipment, and perform moderately difficult manual manipulations such as using a keyboard, writing, and filing for extended periods of time. Must be able to perform tasks which require hand-eye coordination such as data entry and typing. Mobility requirements may include the ability to be stationary at a workstation for a prolonged period in addition to being mobile for a reasonable length of time and distance. Participation in on-call rotations and after-hours maintenance activities as required. Communication requirements include the ability to comprehend, communicate, and read the English language.
Salary Range: $ 36.07-$54.10 /hour Pay is based on experience, skills, and education. Exempt positions under the Fair Labor Standards Act (FLSA) will be paid within the base salary equivalent of the stated hourly rates. The pay range may also vary within the stated range based on location.