Systems Administrator - Endpoint & Identity

Liberty Mutual Insurance
United States
2 days ago
Apply on amchealth.clearcompany.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Experience required
3 years minimum
Compensation
$45,000.0 - $85,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Artificial Intelligence Data Analysis Apple Mac Systems Audit Trail User Authentication BitLocker Drive Encryption Software as a Service Program Optimization Cyber Security Computer Literacy
+23 more
Information Leak Prevention Dynamic Host Configuration Protocol Domain Name System (DNS) Multi-Factor Authentication Identity and Access Management Issue Tracking Systems Virtual Private Networks (VPN) Python (Programming Language) Networking Basics Network Connections Windows PowerShell Runbook Microsoft SharePoint Security Information and Event Management Software Deployment TCP/IP User Provisioning Software Software Vulnerability Management Home Networking Microsoft InTune Computer Equipment Deployment Automation Casper Suite

Job description

Be an Early Applicant Remote Hiring Remotely in United States Mid level Remote Hiring Remotely in United States Mid level Administers Microsoft 365, Intune, Entra ID, and Windows/macOS endpoints in a HIPAA-regulated remote environment. Manages identity lifecycle, MFA, Conditional Access, encryption, compliance, DLP, provisioning, endpoint security, vulnerability remediation, audits, asset logistics, and advanced desktop support. Automates administrative tasks with PowerShell, maintains documentation and runbooks, supports incident response, and coordinates with infrastructure and security teams. Occasional after-hours maintenance and minimal travel are required. The summary above was generated by AI

Primary Job Function:

Systems Administrator responsible for the administration, security, and support of the enterprise endpoint fleet and identity platform in a HIPAA-regulated environment. Responsibilities include Microsoft 365 and Microsoft Intune administration; Entra ID identity and access management; Windows and macOS device management and desktop support; endpoint security and compliance controls protecting Protected Health Information (PHI); administrative automation; and creation and maintenance of documentation including SOPs and runbooks. This is a fully remote position, and all provisioning, administration, and support are performed remotely.

Essential Job Functions:

  • Administers Microsoft 365 tenant services, including Exchange Online, SharePoint/OneDrive, and Teams.
  • Owns Microsoft Intune administration across Windows and macOS, including device enrollment, configuration and compliance policies, application deployment, patch rings, and update management.
  • Performs zero-touch provisioning through Windows Autopilot and Apple Business Manager so that endpoints ship directly to remote employees and are production-ready at first login.
  • Maintains standardized, reproducible device builds and reduces configuration drift across the fleet.
  • Coordinates endpoint hardware logistics with vendors and depot partners, including procurement, drop-shipping, RMAs, and the secure return or disposal of devices from departing employees.
  • Administers Entra ID, including users, groups, roles, licensing, SSO integrations, and application registrations.
  • Designs, tests, deploys, and tunes Conditional Access and multi-factor authentication policies.
  • Executes identity lifecycle management, including automated onboarding, role changes, and same-day access revocation at offboarding.
  • Enforces least-privilege and role-based access across Microsoft 365 and integrated SaaS applications, and conducts periodic access reviews and user access recertification.
  • Configures and maintains endpoint controls supporting HIPAA Security Rule safeguards, including access control, automatic logoff, audit logging, and encryption.
  • Enforces full-disk encryption on all endpoints (BitLocker and FileVault) and manages key escrow and recovery.
  • Maintains data loss prevention and device compliance policies that keep Protected Health Information (PHI) on managed, compliant devices.
  • Executes remote lock and wipe for lost, stolen, or compromised devices, and supports incident response and breach investigation with device and access log evidence.
  • Applies and maintains endpoint security baselines, and tracks and remediates vulnerability findings across the fleet.
  • Maintains documentation and produces evidence for HIPAA audits, risk assessments, SOC 2 reviews, and customer security questionnaires.
  • Ensures the rigorous application of Information Security/Information Assurance policies, principles, and practices in the delivery of systems, applications, and services.
  • Serves as the escalation point for advanced desktop support across Windows and macOS, including operating system, application, authentication, VPN, network connectivity, printing, and hardware issues, all diagnosed remotely.
  • Manages the support ticket queue against defined service level agreements and communicates clearly with non-technical staff, primarily in writing.
  • Develops and maintains standard operating procedures, runbooks, internal documentation, and end-user knowledge base articles.
  • Reads and writes PowerShell scripts to automate repetitive administrative work. Python is nice to have but not required.
  • Tracks hardware, software, and license inventory across the full asset lifecycle.
  • Interfaces with internal and external Network Engineers, Security, and Application teams to optimize systems use and configuration.
  • Provides technical knowledge and recommendations to staff members as required.
  • Some after-hours work will be required for maintenance, patching, and incident response.
  • Performs other related duties as assigned.
  • Ensures the rigorous application of Information Security/Information Assurance policies, principles, and practices in the delivery of systems, applications, and services.
  • Serves as the escalation point for advanced desktop support across Windows and macOS, including operating system, application, authentication, VPN, network connectivity, printing, and hardware issues, all diagnosed remotely.
  • Manages the support ticket queue against defined service level agreements and communicates clearly with non-technical staff, primarily in writing.
  • Develops and maintains standard operating procedures, runbooks, internal documentation, and end-user knowledge base articles.
  • Reads and writes PowerShell scripts to automate repetitive administrative work. Python is nice to have but not required.
  • Tracks hardware, software, and license inventory across the full asset lifecycle.
  • Interfaces with internal and external Network Engineers, Security, and Application teams to optimize systems use and configuration.
  • Provides technical knowledge and recommendations to staff members as required.
  • Some after-hours work will be required for maintenance, patching, and incident response.
  • Performs other related duties as assigned., Own and expand customer relationships across the Western United States for a cloud-based healthcare genomics platform. Drive adoption, usage, and account growth within hospitals, laboratories, and healthcare organizations; identify expansion opportunities; navigate complex stakeholder groups; provide account support; and partner with sales teams on customer meetings and commercial development. The field-based role requires approximately 30-40% territory travel.

Requirements

  • Working understanding of HIPAA and the handling of Protected Health Information (PHI) in an end-user computing environment., * 3-6 years’ experience in IT systems administration, including hands-on administration of Microsoft 365 and Microsoft Intune in a production environment.
  • 3 years’ experience serving as a direct technical interface to internal and external customers.
  • Demonstrated desktop support experience on both Windows and macOS.
  • Working knowledge of networking fundamentals, including DNS, DHCP, TCP/IP, VPN, and the remote diagnosis of home network and connectivity issues.
  • Ability to read and write PowerShell scripts for administrative automation.
  • Excellent written communication and self-directed work habits, with sound judgment about when to escalate.

SPECIALIZED EXPERIENCE:

  • Demonstrated experience in a majority of the following:
  • Day-to-day administration of both Windows and macOS endpoints, rather than depth in one platform with limited exposure to the other.
  • Entra ID or Active Directory administration, including SSO, MFA, and Conditional Access.
  • Work in a HIPAA compliant environment, including endpoint controls supporting the HIPAA Security Rule.
  • Endpoint encryption and key escrow (BitLocker and FileVault).
  • Zero-touch provisioning with Windows Autopilot and Apple Business Manager.
  • macOS management at scale with Jamf, Kandji, or a comparable platform.
  • SaaS identity governance or SCIM-based user provisioning.
  • Endpoint detection and response (EDR), SIEM, or vulnerability management tooling.
  • Supporting a fully distributed, remote workforce.
  • Supporting HIPAA, HITRUST, or SOC 2 audits.

Licensure and/or Certification Requirements:

  • Microsoft MD-102 (Endpoint Administrator Associate), or 3+ years hands-on endpoint administration experience.
  • Microsoft SC-300, Microsoft AZ-104, or Apple Certified Support Professional preferred.

Must be a U.S. citizen residing in the continental United States and maintain a suitable home work environment with reliable high-speed internet.

Primarily a stationary role performed at a computer workstation, with extended periods of computer use.

Occasional lifting and handling of computer equipment up to 25 pounds.

Some after-hours availability required for maintenance, patching, and incident response.

Minimal travel required.

Benefits & conditions

An Hour Ago Remote or Hybrid 45K-85K Annually Junior 45K-85K Annually Junior Artificial Intelligence * Fintech * Insurance * Marketing Tech * Software * Analytics Handle inbound calls and warm leads, consult customers on insurance needs, recommend appropriate property and casualty coverage, and convert prospects into policyholders. The role includes paid training and licensing, customer communication, sales closing, and brand representation. Representatives must work a fixed schedule including one weekend day and meet remote-work requirements with a dedicated workspace and wired high-speed internet. Top Skills: PcWired High-Speed Internet SOPHiA GENETICS, An Hour Ago Remote or Hybrid 119K-170K Annually Senior level 119K-170K Annually Senior level Artificial Intelligence * Cloud * Fintech * Information Technology * Insurance * Financial Services * Big Data Analytics Lead end-to-end operational and financial management of the Executive Aviation Program, managing vendor contracts, optimizing aircraft usage and costs, coordinating complex executive travel, providing 24/7 escalated support, forecasting and reporting usage and expenses, and advising leadership on program performance and improvements. Top Skills: ExcelMS Office

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on amchealth.clearcompany.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:32 min

Ensuring secure and reliable connectivity for remote employees

Kyle Daigle · Coffee With Developers

2:50 min

Introduction and the value of runbooks

Hila Fish · World Congress 2023

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · World Congress 2026 Europe

1:32 min

Structuring automated incident workflows between runbooks and raw models

Aram Hakobyan Aram Hakobyan +1 · World Congress 2026 Europe

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · World Congress 2022

Videos

See all

Related articles

See all