IT Platform Manager

Clear Creek Systems, Inc.
Baltimore, MD, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$125,000.0 - $160,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Android Software Development Apple IOS Microsoft Online Services Business Software Cloud Computing Cyber Security Domainkeys Identified Mail Domain-Based Message Authentication Reporting and Conformance (DMARC) Identity and Access Management Mobile Application Software Microsoft Office
+13 more
Windows PowerShell Role-Based Access Control Azure Active Directory Zero Trust Network Access Microsoft SharePoint Software Deployment Systems Integration Tablet Computers Software Troubleshooting Microsoft InTune Sender Policy Framework (SPF) Deployment Automation CIS Benchmarks

Job description

We are seeking a hands-on IT Manager to own and operate our Microsoft 365 ecosystem across four tenants supporting approximately 100-200 users. This individual will be responsible for day-to-day administration, endpoint and mobile device lifecycle management, and continuous improvement of security and device management platforms including Entra ID, Intune, and Microsoft Defender.

This role combines operational execution with strategic development. The IT Manager will partner closely with the CIO to evolve the organization’s IT roadmap, strengthen security posture over time, and standardize processes across business units. The role spans full ownership of identity, endpoint, and mobile device integration within a unified security model., Microsoft 365 & Identity Management

  • Administer and maintain Microsoft 365 services across four tenants
  • Manage Entra ID (Azure AD), including:

  • User lifecycle (onboarding, offboarding, role changes)
  • Conditional Access policies (device compliance, app protection, location/risk-based controls)
  • MFA enforcement and authentication methods
  • Group design and role-based access control (RBAC)

  • Integrate identity with endpoint and mobile device compliance to enforce secure access (Zero Trust model)
  • Oversee Exchange Online, Teams, SharePoint, and OneDrive administration
  • Ensure tenant configuration consistency where appropriate while supporting business-specific needs

Endpoint Management (Intune & Device Lifecycle)

  • Own Microsoft Intune configuration and operations across Windows, iOS, and Android devices:

  • Device enrollment (Windows Autopilot, Apple Business Manager, Android Enterprise)
  • Configuration profiles, compliance policies, and security baselines
  • Application deployment, updates, and patching strategies

  • Continuously enhance endpoint security posture (e.g., hardening policies, reducing attack surface, enforcing compliance for access)
  • Manage full device lifecycle:

  • Procurement and vendor coordination (laptops, phones, tablets)
  • Provisioning and zero-touch deployment
  • Maintenance, diagnostics, repair coordination, andrepurposing
  • Secure decommissioning and disposal

Mobile Device & Phone Management

  • Manage corporate mobile ecosystem (iOS and Android phones and tablets) using Intune and integrated identity controls
  • Configure and maintain:

  • Mobile Device Management (MDM) and Mobile Application Management (MAM)
  • App protection policies for BYOD and corporate-owned devices
  • Compliance policies tied to Conditional Access

  • Integrate mobile device posture with Entra ID for secure access to M365 resources
  • Coordinate carrier relationships, device procurement, upgrades, and lifecycle planning
  • Support secure and reliable mobile access to email, Teams, and business applications

Security Operations (Microsoft Defender & Integrated Security Stack)

  • Administer Microsoft Defender suite (Endpoint, Office 365, Identity, and Cloud Apps as applicable)
  • Monitor alerts and respond to security incidents across endpoints, identities, and email
  • Correlate signals between Defender and Entra ID (e.g., risky sign-ins, compromised devices)
  • Tune policies over time to balance usability and protection
  • Improve visibility, reporting, and response workflows across tenants
  • Support implementation and enforcement of email security standards (SPF, DKIM, DMARC)

End-User Support & Operations

  • Serve as escalation point for technical issues across laptops, mobile devices, and M365 services
  • Provide hands-on support for:

  • Windows endpoints
  • iOS/Android phones and tablets
  • Identity and access issues

  • Maintain and improve IT documentation, standards, and operational procedures
  • Ensurea consistent, secure, and high-quality user experience across all business units
  • Arrange supportrelationshipsfor branch infrastructure-routers, printers and phones

Strategy & Continuous Improvement

  • Partner with CIO to execute IT strategy and roadmap across identity, device, and security domains
  • Identify opportunities to improve:

  • Security posture (e.g., stronger Conditional Access, device compliance enforcement)
  • Automation and efficiency (Intune, provisioning, scripting)
  • User onboarding/offboarding processes across tenants
  • Standardization of policies across endpoints and mobile devices
  • Evolve the environment toward modern best practices:

  • Zero Trust architecture
  • Device-based access enforcement
  • Unified endpoint and identity security model

Requirements

  • 5+ years of experience in Microsoft 365 administration
  • Strong hands-on experience with:

  • Entra ID (Azure AD)
  • Microsoft Intune (Windows, iOS, Android device management)
  • Microsoft Defender security stack

  • Experience managing endpoint and mobile device ecosystems in a cloud-managed environment
  • Strong understanding of identity-driven security and Conditional Access
  • Ability to operate independently in a broad, all-in-one IT role

Preferred Qualifications

  • Experience managing multi-tenant Microsoft 365 environments
  • Knowledge of Zero Trust security principles and implementation
  • Experience with Apple Business Manager and Android Enterprise
  • PowerShell scripting or automation experience
  • Experience integrating device compliance with identity-based access controls

Key Traits for Success

  • Hands-on, proactive, and detail-oriented
  • Strong ownership mindset across identity, devices, and security platforms
  • Able to balance operational support with long-term platform evolution
  • Strong troubleshooting and systems-thinking skills
  • Clear communicator who can connect technical systems to business impact

Benefits & conditions

Pulled from the full job description

  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Dental insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

2:25 min

Testing the AI generated Apple iOS Flashcards application

MIlan Todorović MIlan Todorović · World Congress 2026 Europe

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

Videos

See all

Related articles

See all