DescriptionWe are looking for a
Windows Systems Administrator to join our growing IT department. Do you naturally create new ways to deliver exceptional results? We want to meet you!
Windows Systems Administrator SummaryWe are seeking an experienced, agile, and collaborative
Windows Systems Administrator with the maturity, confidence, and sound design, troubleshooting, and decision-making skills required to operate as a Tier 3 technical resource within a GxP-regulated environment. Reporting to the
Sr. Infrastructure Manager, this role will own the day-to-day execution of INCOG's patch and vulnerability management program and will serve as the technical lead for onboarding new software and hardware systems.
This position requires a passion for IT, systems administration, and supporting the ever-changing technology needs of the company, along with the ability to work independently and collaboratively at all levels of the organization. The IT Systems Administrator will partner closely with our Managed Services Provider (MSP), program managers acting as technical system owners, and stakeholders across Quality, Engineering, and Operations to ensure infrastructure and enterprise systems remain reliable, secure, and inspection-ready.
Essential Job Functions:Infrastructure,Endpoint & Tier 3 Operations- Administer Microsoft Azure / Entra ID infrastructure, including user accounts, groups, conditional access policies, Intune, mobile device management, and endpoint security.
- Serve as the onsite Tier 3 escalation point for complex infrastructure, endpoint, and system issues that cannot be resolved by the MSP-operated Tier 1/2 helpdesk; provide oversight, technical direction, and quality feedback to MSP resources.
- Partner with the Security Analyst, who owns access reviews and audit trail reviews, by providing technical support, data extracts, and remediation actions as needed.
- Work closely with Engineering, Quality Control, Quality Assurance, and other stakeholders to deliver infrastructure solutions that drive operational excellence and process improvements.
- Ensure alignment with internal directives, regulatory expectations, and industry guidelines for supported applications and systems.
- Participate in occasional after-hours and weekend work to support scheduled maintenance windows, patching cycles, and system onboarding activities.
Patch & Vulnerability Management- Own day-to-day execution of the enterprise patch management program for Windows endpoints and servers, leveraging WSUS as the primary tooling.
- Plan, schedule, and execute patching cycles in coordination with the MSP, including pre-deployment testing, phased rollouts, maintenance window coordination, and post-deployment validation.
- Assist the MSP and Infrastructure team with patching and firmware updates for network gear and firewalls; coordinate change windows and validate post-patch connectivity.
- Plan and execute patching for laboratory and engineering instrument workstations and servers, accounting for vendor-validated configurations, locked OS images, and qualification status.
- Track patch compliance, exceptions, and remediation timelines; escalate risks and report status to the Sr. Infrastructure Manager.
- Maintain patch-related runbooks, work instructions, and change documentation in accordance with GxP and Good Documentation Practices.
System Onboarding & Lifecycle Administration- Serve as the IT technical lead for onboarding new software platforms and hardware systems including Lab and Engineering instruments and equipment joining the domain while partnering with the program manager as the designated technical system owner.
- Coordinate with vendors, system owners, Quality, and Validation to plan integration activities, network/domain join requirements, account provisioning, endpoint security baselines, and documentation handoffs.
- Author and maintain system work orders, runbooks, configuration records, and supporting documentation to ensure assets are reliable, accessible, secure, and inspection-ready.
- Administer, support, and maintain workstations, servers, and instrument software across Quality Control labs, Engineering, and other business areas throughout their lifecycle.
- Support continuous improvement of onboarding standards, intake processes, and lifecycle controls in alignment with ITIL and GxP expectations.
Special Job Requirements- 5+ years of progressive IT administration experience.
- 3+ years of experience managing the Microsoft Azure / Entra ID platform, including Intune, MDM, endpoint management, Teams, SharePoint, and related Azure-powered solutions.
- Demonstrated experience operating an enterprise patch management program, including WSUS administration, patch cycle planning, and coordination with managed service providers.
- 5+ years of proven experience maintaining and troubleshooting Windows-based workstations and servers.
- Experience supporting the onboarding and lifecycle administration of enterprise software platforms and instrument/laboratory hardware in a regulated environment.
- Proven experience as a Tier 2/Tier 3 escalation resource with a strong customer service mindset; experience providing technical oversight to or partnership with an MSP is a plus.
- Working knowledge of SOP authoring, systems support, Data Integrity guidance, GxP compliance, Software Development Life Cycle, ITIL, and Good Documentation Practices in a regulated environment.
- B.S. in Engineering, Computer Science, Information Technology, or related field; or equivalent experience.
Additional Preferences- Advanced certification in Microsoft Azure platforms (e.g., AZ-104, AZ-500).
- Microsoft Endpoint Administrator certification (MD-102) or equivalent endpoint/patching credential.
- ITIL Foundation certification.
- CompTIA Security+ or equivalent security credential.
- Familiarity with GAMP 5 and Computer System Validation (CSV) concepts.