Senior Systems AdministratorDepartment: IT
Employment Type: Full Time
Location: British Columbia, Canada
Compensation: The base annual salary range for this full-time role is between $104,300 and $130,400. This range reflects the minimum and maximum target range for new hire base salary across all Canadian locations. Actual compensation may vary outside of this range and is dependent on various factors including but not limited to a candidate's qualifications including relevant education and training, competencies, experience, geographic location, and business needs. Base pay is only one part of the total compensation package. Full time roles are eligible for equity and benefits. Base pay is subject to change and may be modified in the future.
DescriptionAs a
Senior Systems Administrator at Photonic you will maintain, secure, and improve Photonics' hybrid infrastructure across Azure, Windows, identity, networking, and PKI services.
This role administers Microsoft Azure, Windows Server, Linux, Mac and endpoint environments, on-premises Active Directory, Microsoft Entra ID, Microsoft Intune, core network services, VPN connectivity, firewall and segmentation controls, and PKI/SSL certificate management.
As the successful candidate you will help ensure reliable connectivity, secure access, resilient configuration, and efficient service delivery while contributing to documentation, automation, troubleshooting, and knowledge sharing across the IT team.
In this role, you will support critical systems, strengthen our security posture, and help deliver a reliable technology experience for employees across the organization.
You are a hands-on systems administrator who can balance reliable operations, strong security practices, and responsive customer support in a fast-moving technical environment.
WHAT WE NEED YOU TO DO- Azure Cloud, Azure AD, and identity administration: Administer Microsoft Azure Cloud infrastructure and identity services, including virtual machines, networking, storage, Azure AD/Microsoft Entra ID, VPN, RBAC, MFA, conditional access, monitoring, and security controls.
- Windows and on-premises Active Directory administration: Administer Windows Server and Windows endpoint environments, including on-premises Active Directory, Group Policy, DNS, DHCP, domain services, account administration, access permissions, and related troubleshooting.
- Networking and connectivity: Support core network services, including switching, routing, VLANs, DNS, DHCP, VPN access, firewall rules, network segmentation, connectivity troubleshooting, and coordination with vendors or facilities teams for cabling and infrastructure changes.
- Device management: Manage Microsoft Intune device enrolment, MDM and MAM policies, compliance settings, application deployment, and troubleshooting.
- PKI and SSL certificate management: Manage PKI and SSL/TLS certificate lifecycle activities, including certificate requests, issuance, renewal, revocation, inventory tracking, expiry monitoring, and certificate-related troubleshooting.
- Virtualization and systems operations: Manage Azure and on-premises virtual machines, including provisioning, patching, backups, migrations, monitoring, and disaster recovery activities.
- Linux administration: Support Linux systems across on-premises and cloud environments, including configuration, maintenance, and operational troubleshooting.
- Colocation and data centre operations: Support rack management, hardware provisioning, asset coordination, cabling, capacity planning, and resilience activities in colocation environments.
- Hybrid infrastructure: Help design, maintain, and support hybrid cloud environments that connect cloud, on-premises, and colocation systems.
- Security and compliance: Support endpoint protection, vulnerability remediation, security incident response, access controls, and compliance-related activities.
- End-user and service desk support: Provide day-to-day support for desktops, laptops, mobile devices, software installations, access issues, and general troubleshooting to ensure a positive user experience.
- Documentation and team enablement: Maintain clear technical documentation, prepare reports as needed, mentor junior administrators, and contribute to IT planning and continuous improvement.
WHAT YOU BRING TO OUR TEAM- 5-10+ years experience administering Microsoft Azure Cloud infrastructure, Azure AD/Microsoft Entra ID, on-premises Active Directory, Microsoft Intune, Windows Server, and Windows endpoints in an enterprise environment.
- Working knowledge of virtualization, cloud infrastructure, Linux systems, backups, monitoring, disaster recovery, and core networking concepts, including routing, switching, VLANs, firewall rules, VPN connectivity, DNS, DHCP, and troubleshooting.
- Practical experience with Windows administration and directory services, including Windows Server, Group Policy, DNS, DHCP, domain controller health, user and group management, permissions, and hybrid identity troubleshooting.
- A security-first mindset, with experience supporting endpoint protection, access controls, MFA, vulnerability remediation, and incident response processes.
- Practical experience with PKI and SSL/TLS certificate management, including certificate authorities, certificate signing requests, renewals, revocation, trust chains, certificate stores, and expiry monitoring.
- Ability to troubleshoot complex issues across cloud, network, server, and endpoint environments while communicating clearly with technical and non-technical users.
- Experience creating and maintaining clear technical documentation, standard operating procedures, and operational reports.
- A collaborative approach, with the ability to mentor junior team members, share knowledge, and contribute to continuous improvement across IT operations.
An exceptional candidate:- will also bring experience with colocation operations, Azure automation, infrastructure automation, PKI governance, SSL certificate lifecycle tooling, Windows Server hardening, Active Directory health and recovery, Azure AD/Microsoft Entra ID governance, network segmentation, firewall and VPN administration, secure network architecture, security compliance frameworks, identity governance, and hybrid cloud architecture.