More jobs:
Systems Administrator - Endpoint & Identity
Remote / Online - Candidates ideally in
Springfield, Sangamon County, Illinois, 62701, USA
Listed on 2026-09-07
Springfield, Sangamon County, Illinois, 62701, USA
Listing for:
Advanced Monitored Caregiving Inc.
Full Time, Remote/Work from Home
position Listed on 2026-09-07
Job specializations:
-
IT/Tech
Cybersecurity, Systems Administrator, IT Support
Job Description & How to Apply Below
Job Description
Primary Job Function:
Systems Administrator responsible for the administration, security, and support of the enterprise endpoint fleet and identity platform in a HIPAA-regulated environment. Responsibilities include Microsoft 365 and Microsoft Intune administration;
Entra and access management;
Windows and macOS device management and desktop support; endpoint security and compliance controls protecting Protected Health Information (PHI); administrative automation; and creation and maintenance of documentation including SOPs and runbooks. This is a fully remote position, and all provisioning, administration, and support are performed remotely.
Essential Job Functions:
- Administers Microsoft 365 tenant services, including Exchange Online, SharePoint/One Drive, and Teams.
- Owns Microsoft Intune administration across Windows and macOS, including device enrollment, configuration and compliance policies, application deployment, patch rings, and update management.
- Performs zero-touch provisioning through Windows Autopilot and Apple Business Manager so that endpoints ship directly to remote employees and are production-ready at first login.
- Maintains standardized, reproducible device builds and reduces configuration drift across the fleet.
- Coordinates endpoint hardware logistics with vendors and depot partners, including procurement, drop-shipping, RMAs, and the secure return or disposal of devices from departing employees.
- Administers Entra , including users, groups, roles, licensing, SSO integrations, and application registrations.
- Designs, tests, deploys, and tunes Conditional Access and multi-factor authentication policies.
- Executes identity lifecycle management, including automated onboarding, role changes, and same-day access revocation at offboarding.
- Enforces least-privilege and role-based access across Microsoft 365 and integrated SaaS applications, and conducts periodic access reviews and user access recertification.
- Configures and maintains endpoint controls supporting HIPAA Security Rule safeguards, including access control, automatic logoff, audit logging, and encryption.
- Enforces full-disk encryption on all endpoints (Bit Locker and File Vault) and manages key escrow and recovery.
- Maintains data loss prevention and device compliance policies that keep Protected Health Information (PHI) on managed, compliant devices.
- Executes remote lock and wipe for lost, stolen, or compromised devices, and supports incident response and breach investigation with device and access log evidence.
- Applies and maintains endpoint security baselines, and tracks and remediates vulnerability findings across the fleet.
- Maintains documentation and produces evidence for HIPAA audits, risk assessments, SOC 2 reviews, and customer security questionnaires.
- Ensures the rigorous application of Information Security/Information Assurance policies, principles, and practices in the delivery of systems, applications, and services.
- Serves as the escalation point for advanced desktop support across Windows and macOS, including operating system, application, authentication, VPN, network connectivity, printing, and hardware issues, all diagnosed remotely.
- Manages the support ticket queue against defined service level agreements and communicates clearly with non-technical staff, primarily in writing.
- Develops and maintains standard operating procedures, runbooks, internal documentation, and end-user knowledge base articles.
- Reads and writes Power Shell scripts to automate repetitive administrative work. Python is nice to have but not required.
- Tracks hardware, software, and license inventory across the full asset lifecycle.
- Interfaces with internal and external Network Engineers, Security, and Application teams to optimize systems use and configuration.
- Provides technical knowledge and recommendations to staff members as required.
- Some after-hours work will be required for maintenance, patching, and incident response.
- Performs other related duties as assigned.
- Ensures the rigorous application of Information Security/Information Assurance policies, principles, and practices in the delivery of systems, applications, and…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×