Full Job Description
REP is hiring a Systems Administrator to own the technology the company runs on: our Microsoft 365 tenant, identity and access, 200+ Windows and macOS endpoints, the network across all sites, and the dozens of software platforms the business relies on daily. You'll be the primary technical resource for the organization and accountable for keeping systems up, secure, and recoverable.
The role is split between service and engineering. Service means responding to a broken laptop, a new hire first day, a down time clock on the warehouse floor, or a store associate who can't ring a sale. Engineering means deploying config and policy via tested scripts, automating identity lifecycle from our HRIS, tuning application-control and network policy, and eliminating recurring manual requests for good.
We're growing, and this is an opportunity to support our employees across our four sites in our retail stores and additional distribution centers (California, Colorado, and Pennsylvania). Support can't scale by adding headcount; we need someone who builds leverage instead.
You'll report to the Manager of IT Operations and work alongside our Systems, Web Development, and AI/Data teams, our outsourced SOC, and regional IT/network partners. This is an on-site role at our Colorado HQ, with occasional travel to distribution centers and retail locations.
Essential Functions:
Microsoft 365, Identity and Access Administration
Administer REP's Microsoft 365 tenant - Exchange Online, SharePoint Online, OneDrive and Teams - including tenant configuration, service health, mail flow and message hygiene, retention and data governance. Administer Entra ID as a controlled lifecycle: user and group lifecycle, role-based access, licensing, Conditional Access, MFA and password less methods, and SSO/SAML/SCIM integrations for enterprise applications. Maintain least privileged standards and run periodic access reviews.
Endpoint Management and Device Lifecycle
Own the complete device lifecycle for 200+ Windows and macOS endpoints plus the iPadOS and kiosk fleet: Windows Autopilot and Apple Business Manager/ADE enrollment, Intune configuration profiles and compliance policies, application packaging and deployment, driver and OS patch rings, BitLocker and File Vault encryption with key escrow, procurement, imaging, refresh, secure decommissioning, hardware standards and asset tracking, and equipment provisioning and shipping to remote employees. Deliver fleet-wide changes through tested, version-controlled scripts using staged rollout and documented rollback.
Endpoint Security, RMM, and Security Operations
Own the remote monitoring and management and application-control platforms (Ninja One and Threat Locker) end to end - deployment and agent health, policy creation and tuning, allowlisting and elevation request handling, remote support sessions, automated patching and script execution. Serve as primary point of contact for REP's outsourced SOC: triage, investigate and remediate escalated alerts such as impossible travel, anomalous sign-in and unusual IP activity; coordinate containment and document findings; support endpoint protection coverage and hygiene alongside the SOC-managed Sentinel One instance. Issue third-party and API credentials only against a governed register with defined owner, scope and expiration.
Network, SASE, and Site Infrastructure
Own REP's Cato Networks SASE environment - site and endpoint client deployment, firewall and security policy, SD-WAN across locations, QoS and traffic shaping, VPN and remote access, and network performance monitoring and troubleshooting. Manage on-premises infrastructure across REP facilities: wireless access points and coverage, network switching and structured cabling, printers and print management including distribution-center label printers and print/pack station technology, time clocks and scanners, and conference-room and AV technology.
DNS, Email Security, and Data Protection
Own DNS for the corporate domain and the website, including records and domain configuration. Manage email authentication (SPF, DKIM and DMARC), quarantine review and release, and investigation of user-reported phishing and suspicious messages. Administer backup and recovery for Microsoft 365 data - Exchange Online, SharePoint, OneDrive and Teams - through REP's third-party backup platform and maintain protection for on-premises creative storage; monitor coverage and job health, perform periodic restore testing, and document recovery procedures.
Automation and SaaS Platform Administration
Design and build automations that eliminate manual IT work, with particular focus on identity lifecycle automation driven from the Rippling HRIS - automated onboarding, role and department changes, and same-day offboarding across all connected platforms - using PowerShell, the Microsoft Graph API and native platform integrations. Serve as technical administrator for REP's SaaS portfolio: provisioning and deprovisioning, permission structures, group and role assignment and access auditing, and maintenance of the tenant register (named administrators, break-glass access, license counts and renewal dates). Partner with business system owners such as NetSuite and Shopify who manage day-to-day platform configuration, while retaining ownership of access and identity governance.
End-User Support, Documentation and Enablement
Serve as the primary technical resource for the organization across tier 1 through tier 3 - from account and hardware requests to complex platform, network and security troubleshooting - for corporate, distribution center and, as stores open, retail staff. Manage the ticket queue, set response expectations and drive issues to resolution. Act as a technical point of contact with platform vendors, resellers and service providers, driving support cases, vendor on-site work, and warranty and RMA logistics. Maintain documentation of infrastructure, configurations, integrations and runbooks; contribute to IT policy, standards and business-continuity and disaster-recovery planning; and deliver security awareness, phishing simulation and user enablement.
What You Will Bring:
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required.
Microsoft 365 and Entra ID: hands-on tenant administration including Exchange Online, SharePoint, OneDrive and Teams; Conditional Access, MFA and passwordless, licensing, and SSO/SAML/SCIM application integrations.
Endpoint management at scale: Microsoft Intune for both Windows and macOS, including Autopilot, Apple Business Manager/ADE, compliance policies, application deployment and patch management.
RMM and endpoint security tooling: NinjaOne or comparable RMM; application allowlisting and zero-trust endpoint control (ThreatLocker or comparable); endpoint protection / EDR.
Scripting and automation: PowerShell strongly preferred; Microsoft Graph API and HRIS-driven identity automation (Rippling or similar) highly valued; comfort working in version control
Networking and SASE: routing, switching, wireless, VLANs, firewall policy, VPN, SD-WAN and QoS; experience with a SASE platform (Cato Networks preferred) is a strong plus.
DNS and email security: DNS administration for production domains, SPF, DKIM and DMARC, quarantine management and phishing investigation workflows.
Backup and recovery: third-party backup for Microsoft 365 workloads, restore testing and documented recovery procedures.
SaaS administration: multi-tenant business application administration, license management, access auditing, and governance of API keys and service accounts.
Service management: ticketing / ITSM platforms, knowledge base and runbook authoring, and reporting on service volume, deflection and compliance.
Workplace and operational hardware: iPad and kiosk fleets, time clocks, barcode scanners, label and print/pack station printers, conference-room AV and point-of-sale hardware.
Ability to work autonomously as the primary technical resource, prioritizing across competing requests and owning issues from intake through resolution.
Understanding core security operations concepts, including endpoint protection, identity-based threat detection, phishing and account-compromise response, and least-privilege access.
Ability to read, analyze and interpret technical procedures, professional journals and governmental regulations; to write reports, business correspondence and procedure manuals; and to present information and respond to questions from managers, employees and vendors.
Ability to solve practical problems and deal with a variety of concrete variables in situations where only limited standardization exists, and to interpret instructions furnished in written, oral, diagram or schedule form.
Travel:
Occasional travel, up to approximately 10%. Periodic travel to REP distribution centers and retail locations for equipment deployment, network and site setup, and on-site support.
Occasional after-hours and weekend work for maintenance windows, site cutovers, deployments and incident response
Education and/or Experience:
Bachelor's degree in information technology, computer science or a related field preferred; an equivalent combination of education and directly related experience is accepted in place of a degree.
5-8 years of progressive systems administration or IT infrastructure experience, including at least 3 years administering a mixed Windows and macOS fleet and a Microsoft 365 / Entra ID tenant.
Demonstrated experience deploying configuration or scripts fleet-wide across more than one operating system, including staged rollout, testing and rollback.
Demonstrated experience administering an identity lifecycle end to end - provisioning, entitlement and deprovisioning you can verify across a directory and multiple SaaS platform.
Demonstrated ownership of production network or security infrastructure - firewall or SASE policy, DNS for a production domain, or an equivalent high-blast-radius system.
Experience supporting multi-site, distribution center, retail or shop-floor populations preferred.
Certifications preferred but not required: Microsoft MS-900, MD-102 or SC-300; Jamf, CompTIA A+, Network+ or Security+; comparable endpoint, identity or networking certifications will also be considered.
What's in it for You:
Our commitment to quality and transparency applies not only to our products, but to our people. We are focused on creating a fun, exciting, collaborative space that's centered around health and well-being. We empower everyone on our team to take control of their careers and balance their work and life in a modern, fast-paced environment.
We offer an exceptional compensation package which includes:
Compensation base range: $80,000 - $95,000 annually with bonus potential
Day One Benefits!
Medical, Dental, Vision (Competitive Benefits Packages Available)
Health Savings Account (HSA) with employer contributions
Flexible Spending Account (FSA) options
LTD/STD, Life and AD&D (100% premiums covered by REP)
401k and Roth options with employer match up to 4%
Employee Assistance Program (EAP)
Recharge Yourself!