IT Systems Administrator (62996)

UNION COMMUNITY CARELancaster, PA
Onsite

About The Position

We are seeking a seasoned technician with deep hands-on expertise in Microsoft identity, endpoint, and cloud administration to manage and secure our hybrid environment. This role focuses on Active Directory, Group Policy, Microsoft 365, Azure tenant operations, Intune/MDM, identity governance, and related security controls. The ideal candidate is a pragmatic problem-solver who can design, implement, maintain, and troubleshoot complex Microsoft-centric infrastructure while collaborating with security, networking, and operations teams. Healthcare/Epic experience a plus, but not required.

Requirements

  • 5+ years of progressive hands-on experience administering Active Directory and Group Policy in production environments.
  • Strong PowerShell scripting skills with proven ability to automate AD, Entra ID, Microsoft 365, and Intune tasks.
  • Demonstrated experience managing Microsoft 365 tenants and Azure AD / Entra ID (including hybrid identity scenarios).
  • Practical experience with Microsoft Intune / Endpoint Manager and mobile device management (MDM).
  • Working knowledge of identity and access management principles, conditional access, MFA, and privileged identity management.
  • Familiarity with Data Loss Prevention (DLP) concepts and Microsoft 365 compliance tools.
  • Understanding of core networking concepts relevant to identity and device management (DNS, certificates, VPN, firewalls).
  • Solid foundation in cybersecurity best practices for identity, endpoints, and hybrid environments.
  • Ability to troubleshoot complex issues across on-premises, hybrid, and cloud Microsoft stacks.
  • Clear written and verbal communication skills; ability to document technical work and explain issues to both technical and non-technical audiences.
  • Ability to work independently and collaboratively in a fast-paced environment.
  • Occasional after-hours work required for system maintenance and emergency response.

Nice To Haves

  • Microsoft certifications such as AZ-104, MS-102, SC-300, MD-102, or equivalent practical experience.
  • Experience with Microsoft Defender for Endpoint / Identity, Microsoft Sentinel, or similar security tooling.
  • Exposure to certificate services (AD CS / PKI), Entra ID app proxy, or advanced conditional access scenarios.
  • Familiarity with other identity or MDM platforms (e.g., Okta, Jamf) as complementary knowledge.
  • Experience in regulated or highly secured environments (compliance frameworks such as NIST, CIS, and HIPAA requirements).
  • Scripting beyond PowerShell (e.g., Graph API, Azure CLI, or basic Python) is a plus.
  • Healthcare/Epic experience

Responsibilities

  • Administer and maintain on-premises Active Directory (AD) domains, including user/computer object management, OU design, Group Policy Objects (GPOs), and replication health.
  • Design, test, deploy, and troubleshoot Group Policy configurations for security baselines, software deployment, and configuration management.
  • Write, maintain, and optimize PowerShell scripts and modules for automation of AD, Azure AD / Entra ID, Microsoft 365, and Intune tasks.
  • Manage Microsoft 365 tenants: Exchange Online, SharePoint Online, Teams, OneDrive, licensing, and service health.
  • Administer Azure AD / Microsoft Entra ID (users, groups, app registrations, conditional access, PIM, identity protection, hybrid identity with Entra Connect).
  • Own Intune (Microsoft Endpoint Manager) and MDM operations: device enrollment, configuration profiles, compliance policies, application deployment, and Autopilot.
  • Support identity lifecycle management, single sign-on (SSO), multifactor authentication (MFA), and passwordless initiatives.
  • Implement and monitor Data Loss Prevention (DLP) policies across Microsoft 365 and related platforms.
  • Assist with network-related aspects of identity and endpoint management (DNS, DHCP, VPN, certificate services, firewall rules affecting authentication and device connectivity).
  • Contribute to cybersecurity posture through hardening of AD/Azure AD, privileged access management, logging/monitoring (including Microsoft Defender and Sentinel where applicable), and response to identity-related incidents.
  • Document configurations, procedures, and runbooks; participate in change management and after-hours support as needed.
  • Collaborate with support, networking, and application teams on projects involving identity, endpoints, and cloud services.
  • Performs other work-related duties as assigned
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service