×
Register Here to Apply for Jobs or Post Jobs. X

Systems Administrator - Tier II

Job in Centennial, Arapahoe County, Colorado, USA
Listing for: YIELD SOLUTIONS GROUP LLC
Full Time position
Listed on 2026-07-19
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Administrator
Job Description & How to Apply Below

Systems Administrator – Tier II

Location:

Centennial, CO (In-Office) Company:
Yield Solutions Group

Reports to:

IT Manager

---

The Opportunity

Refi Jet processes thousands of auto loan refinancing applications every month across 30+ lending partners. That volume runs on Java Spring Boot services, AWS infrastructure, PostgreSQL and MariaDB databases, and a regulatory environment — FCRA, GLBA, SOC 2 — that requires every change to be documented, every endpoint to be compliant, and every access decision to be defensible.

The Systems Administrator, Tier II is the operational layer that holds all of that together. This is a senior individual contributor role, not a generalist help desk function. Tier I handles first-contact triage. Tier II owns what Tier I cannot resolve: stuck MFA enrollments, IAM role misconfigurations in AWS, permission conflicts in Git Lab, and anything else that requires genuine diagnosis before escalation.

At the same time, Tier II owns several operational domains outright — identity and access management, endpoint compliance, backup verification, monitoring response, and the documentation that survives a SOC 2 audit.

The person in this role needs to be technically grounded, documentation-disciplined, and comfortable working in a regulated environment where "I'll document that later" is not an option.

---

What You'll Do – Key Responsibilities

Identity & Access Management

· Provision and deprovision user accounts across Active Directory, AWS IAM, and the full Refi Jet SaaS stack. When a new employee onboards you build out the complete access profile, not just the basic account.

· Resolve Tier I escalations in this domain: stuck MFA enrollments, IAM role misconfigurations, permission conflicts in Git Lab, and access inconsistencies that require actual investigation to diagnose.

· Maintain access documentation that reflects current state at all times. In a SOC 2 environment, access records are audit evidence.

Endpoint & Device Management

· Image, configure, and manage workstations across the organization using Microsoft Intune and Autopilot. Own the full device lifecycle from Autopilot enrollment and provisioning profile assignment through Intune configuration policy application, compliance policy enforcement, and patch cycle execution — scheduling, documentation, and remediation included.

· Verify endpoint compliance against SOC 2 control requirements using Intune's compliance reporting. When a gap surfaces — and SOC 2 audits surface them — you own the remediation and the written record of what you did. Troubleshoot Autopilot enrollment failures and Intune policy conflicts before they require escalation.

· Coordinate with the Director of IT/Info Sec on endpoint policy standards and any findings that require a policy-level response.

Server & Infrastructure Operations

· Monitor on-prem and AWS resources on a routine basis: health checks, capacity monitoring, performance baselines.

· Execute maintenance windows, including OS patching, disk management, and scheduled restarts. Coordinate with Dev Ops before touching anything that sits under the Java Spring Boot services running in AWS.

· Document all infrastructure changes in a change log that can be reviewed without your presence to explain it.

Network & Connectivity

· Manage DNS and DHCP configurations. Troubleshoot VPN issues at the routing and configuration level, not just the client level. Review firewall ACLs when connectivity issues require it.

· When an issue requires Dev Ops or Info Sec escalation, hand it off with a clear, specific problem statement — what you've ruled out, what you believe the root cause is, what you've already tried.

Security Operations

· Participate in vulnerability remediation cycles under the direction of the Director of IT/Info Sec. This means executing the operational work: patching, configuration changes, verification, and documentation.

· Work with the Dev Ops team to respond to Datadog alerts that are security-adjacent with the same operational rigor as any other alert: acknowledge, work the runbook, escalate with context when the runbook doesn't resolve it.

· Enforce endpoint compliance policies in a way that holds up…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary