Systems Administrator - Endpoint & Identity

AMC Health

$80K — $95K *
Healthcare
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-6 years of IT systems administration experience, focusing on Microsoft 365 and Microsoft Intune.
  • 3 years of experience as a technical interface with internal and external customers.
  • Demonstrated desktop support experience for both Windows and macOS platforms.
  • Working knowledge of networking fundamentals like DNS, DHCP, and TCP/IP.
  • Ability to read and write PowerShell scripts for automation.

Responsibilities

  • Administer Microsoft 365 services such as Exchange Online and Teams.
  • Manage Microsoft Intune for device enrollment and compliance.
  • Execute zero-touch provisioning for remote employees using Windows Autopilot and Apple Business Manager.
  • Maintain endpoint security and compliance controls for HIPAA.
  • Document processes, develop standard operating procedures, and maintain knowledge articles.

Benefits

  • Fully remote position offering flexibility in work environment.
  • Opportunity to work with cutting-edge technologies in a regulated industry.
  • Involvement in critical areas of identity management and cybersecurity.
  • Support for continuing education and professional certifications.
Full Job Description
Primary Job Function:

Systems Administrator responsible for the administration, security, and support of the enterprise endpoint fleet and identity platform in a HIPAA-regulated environment. Responsibilities include Microsoft 365 and Microsoft Intune administration; Entra ID identity and access management; Windows and macOS device management and desktop support; endpoint security and compliance controls protecting Protected Health Information (PHI); administrative automation; and creation and maintenance of documentation including SOPs and runbooks. This is a fully remote position, and all provisioning, administration, and support are performed remotely.

Essential Job Functions:
  • Administers Microsoft 365 tenant services, including Exchange Online, SharePoint/OneDrive, and Teams.
  • Owns Microsoft Intune administration across Windows and macOS, including device enrollment, configuration and compliance policies, application deployment, patch rings, and update management.
  • Performs zero-touch provisioning through Windows Autopilot and Apple Business Manager so that endpoints ship directly to remote employees and are production-ready at first login.
  • Maintains standardized, reproducible device builds and reduces configuration drift across the fleet.
  • Coordinates endpoint hardware logistics with vendors and depot partners, including procurement, drop-shipping, RMAs, and the secure return or disposal of devices from departing employees.
  • Administers Entra ID, including users, groups, roles, licensing, SSO integrations, and application registrations.
  • Designs, tests, deploys, and tunes Conditional Access and multi-factor authentication policies.
  • Executes identity lifecycle management, including automated onboarding, role changes, and same-day access revocation at offboarding.
  • Enforces least-privilege and role-based access across Microsoft 365 and integrated SaaS applications, and conducts periodic access reviews and user access recertification.
  • Configures and maintains endpoint controls supporting HIPAA Security Rule safeguards, including access control, automatic logoff, audit logging, and encryption.
  • Enforces full-disk encryption on all endpoints (BitLocker and FileVault) and manages key escrow and recovery.
  • Maintains data loss prevention and device compliance policies that keep Protected Health Information (PHI) on managed, compliant devices.
  • Executes remote lock and wipe for lost, stolen, or compromised devices, and supports incident response and breach investigation with device and access log evidence.
  • Applies and maintains endpoint security baselines, and tracks and remediates vulnerability findings across the fleet.
  • Maintains documentation and produces evidence for HIPAA audits, risk assessments, SOC 2 reviews, and customer security questionnaires.
  • Ensures the rigorous application of Information Security/Information Assurance policies, principles, and practices in the delivery of systems, applications, and services.
  • Serves as the escalation point for advanced desktop support across Windows and macOS, including operating system, application, authentication, VPN, network connectivity, printing, and hardware issues, all diagnosed remotely.
  • Manages the support ticket queue against defined service level agreements and communicates clearly with non-technical staff, primarily in writing.
  • Develops and maintains standard operating procedures, runbooks, internal documentation, and end-user knowledge base articles.
  • Reads and writes PowerShell scripts to automate repetitive administrative work. Python is nice to have but not required.
  • Tracks hardware, software, and license inventory across the full asset lifecycle.
  • Interfaces with internal and external Network Engineers, Security, and Application teams to optimize systems use and configuration.
  • Provides technical knowledge and recommendations to staff members as required.
  • Some after-hours work will be required for maintenance, patching, and incident response.
  • Performs other related duties as assigned.
  • Ensures the rigorous application of Information Security/Information Assurance policies, principles, and practices in the delivery of systems, applications, and services.
  • Serves as the escalation point for advanced desktop support across Windows and macOS, including operating system, application, authentication, VPN, network connectivity, printing, and hardware issues, all diagnosed remotely.
  • Manages the support ticket queue against defined service level agreements and communicates clearly with non-technical staff, primarily in writing.
  • Develops and maintains standard operating procedures, runbooks, internal documentation, and end-user knowledge base articles.
  • Reads and writes PowerShell scripts to automate repetitive administrative work. Python is nice to have but not required.
  • Tracks hardware, software, and license inventory across the full asset lifecycle.
  • Interfaces with internal and external Network Engineers, Security, and Application teams to optimize systems use and configuration.
  • Provides technical knowledge and recommendations to staff members as required.
  • Some after-hours work will be required for maintenance, patching, and incident response.
  • Performs other related duties as assigned.

Experience/Education
  • Working understanding of HIPAA and the handling of Protected Health Information (PHI) in an end-user computing environment.

General Experience:
  • 3-6 years' experience in IT systems administration, including hands-on administration of Microsoft 365 and Microsoft Intune in a production environment.
  • 3 years' experience serving as a direct technical interface to internal and external customers.
  • Demonstrated desktop support experience on both Windows and macOS.
  • Working knowledge of networking fundamentals, including DNS, DHCP, TCP/IP, VPN, and the remote diagnosis of home network and connectivity issues.
  • Ability to read and write PowerShell scripts for administrative automation.
  • Excellent written communication and self-directed work habits, with sound judgment about when to escalate.

SPECIALIZED EXPERIENCE:
  • Demonstrated experience in a majority of the following:
  • Day-to-day administration of both Windows and macOS endpoints, rather than depth in one platform with limited exposure to the other.
  • Entra ID or Active Directory administration, including SSO, MFA, and Conditional Access.
  • Work in a HIPAA compliant environment, including endpoint controls supporting the HIPAA Security Rule.
  • Endpoint encryption and key escrow (BitLocker and FileVault).
  • Zero-touch provisioning with Windows Autopilot and Apple Business Manager.
  • macOS management at scale with Jamf, Kandji, or a comparable platform.
  • SaaS identity governance or SCIM-based user provisioning.
  • Endpoint detection and response (EDR), SIEM, or vulnerability management tooling.
  • Supporting a fully distributed, remote workforce.
  • Supporting HIPAA, HITRUST, or SOC 2 audits.

Licensure and/or Certification Requirements:

  • Microsoft MD-102 (Endpoint Administrator Associate), or 3+ years hands-on endpoint administration experience.
  • Microsoft SC-300, Microsoft AZ-104, or Apple Certified Support Professional preferred.


Must be a U.S. citizen residing in the continental United States and maintain a suitable home work environment with reliable high-speed internet.

Primarily a stationary role performed at a computer workstation, with extended periods of computer use.

Occasional lifting and handling of computer equipment up to 25 pounds.

Some after-hours availability required for maintenance, patching, and incident response.

Minimal travel required.

Similar Jobs

More Jobs at AMC Health

More Healthcare Jobs

Find similar Systems Administrator - Endpoint & Identity jobs: