IT Systems Administrator (62996)

Union Community Care

Lancaster (Lancaster County)

On-site

USD 90,000 - 120,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Union Community Care in Lancaster, PA is seeking a seasoned IT professional to manage and secure a hybrid Microsoft‑centric infrastructure. You will own AD, Group Policy, Azure AD/Entra ID, Intune, MDM, and security controls, collaborating with security, networking, and operations teams to maintain reliability and compliance.

Ideal candidates bring 5+ years of hands-on experience, strong PowerShell skills, and a pragmatic problem‑solving mindset to support a healthcare environment with HIPAA

Qualifications

  • 5+ years hands-on experience administering Active Directory and Group Policy in production
  • Strong PowerShell scripting skills to automate AD/Entra ID/M365/Intune tasks
  • Experience managing Microsoft 365 tenants and Azure AD/Entra ID, including hybrid identity
  • Practical experience with Intune/Endpoint Manager and MDM
  • Knowledge of IAM, conditional access, MFA, and privileged identity management
  • Familiarity with DLP concepts and M365 compliance tools
  • Understanding of DNS, VPN, certificates, and firewall basics
  • Clear written and verbal communication; able to document technical work

Responsibilities

  • Administer and maintain on-prem Active Directory domains and GPOs
  • Design and deploy Group Policy configurations for security baselines
  • Write and optimize PowerShell scripts for AD/Azure AD/M365/Intune
  • Manage Microsoft 365 tenants: Exchange Online, SharePoint, Teams, OneDrive
  • Administer Azure AD/Entra ID users, groups, app registrations, and CA
  • Own Intune and MDM operations: device enrollment, configs, compliance
  • Support SSO, MFA, and passwordless initiatives
  • Implement and monitor DLP policies across Microsoft 365
  • Assist with network aspects impacting identity and device management
  • Contribute to cybersecurity posture and incident response
  • Document configurations, runbooks; participate in change management
  • Collaborate with cross-functional teams on identity and cloud projects

Skills

PowerShell scripting
Active Directory administration
Group Policy management
Azure AD / Entra ID
Intune / Endpoint Manager
MDM
Security controls
Troubleshooting
Documentation
Communication skills

Tools

Microsoft Defender for Endpoint
Microsoft Sentinel
AD CS / PKI
Entra ID app proxy

Job description

Job Details

Job Location: Administration - Lancaster, PA 17602


Our Mission, Vision, & Model of Care

At Union Community Care, our purpose is at the forefront of all that we do: we stand for whole health to help you live your fullest life.


We envision vibrant and healthy communities supported by inclusive healthcare that embraces each member’s unique culture, needs, and values, and emboldens them to make healthful choices that fuel their well-being and the well-being of others.


We believe in whole health. This means we address and heal disease but equally important, we work at the causes of the causes, the social ills that must be addressed to achieve true equity.


We listen, learn, and embrace the complex lives and unique strengths of our patients, and we work hard to break down all barriers to care. This means we look through a grassroots lens. We connect with our communities because we are our communities. Each of us is a neighbor, a friend, a family member, and together, we are a trusted community health center.


Qualifications

JOB SUMMARY

We are seeking a seasoned technician with deep hands‑on expertise in Microsoft identity, endpoint, and cloud administration to manage and secure our hybrid environment. This role focuses on Active Directory, Group Policy, Microsoft 365, Azure tenant operations, Intune/MDM, identity governance, and related security controls. The ideal candidate is a pragmatic problem‑solver who can design, implement, maintain, and troubleshoot complex Microsoft‑centric infrastructure while collaborating with security, networking, and operations teams. Healthcare/Epic experience a plus, but not required.


SPECIFIC JOB DUTIES


  • Administer and maintain on‑premises Active Directory (AD) domains, including user/computer object management, OU design, Group Policy Objects (GPOs), and replication health.

  • Design, test, deploy, and troubleshoot Group Policy configurations for security baselines, software deployment, and configuration management.

  • Write, maintain, and optimize PowerShell scripts and modules for automation of AD, Azure AD / Entra ID, Microsoft 365, and Intune tasks.

  • Manage Microsoft 365 tenants: Exchange Online, SharePoint Online, Teams, OneDrive, licensing, and service health.

  • Administer Azure AD / Microsoft Entra ID (users, groups, app registrations, conditional access, PIM, identity protection, hybrid identity with Entra Connect).

  • Own Intune (Microsoft Endpoint Manager) and MDM operations: device enrollment, configuration profiles, compliance policies, application deployment, and Autopilot.

  • Support identity lifecycle management, single sign‑on (SSO), multifactor authentication (MFA), and passwordless initiatives.

  • Implement and monitor Data Loss Prevention (DLP) policies across Microsoft 365 and related platforms.

  • Assist with network‑related aspects of identity and endpoint management (DNS, DHCP, VPN, certificate services, firewall rules affecting authentication and device connectivity).

  • Contribute to cybersecurity posture through hardening of AD/Azure AD, privileged access management, logging/monitoring (including Microsoft Defender and Sentinel where applicable), and response to identity‑related incidents.

  • Document configurations, procedures, and runbooks; participate in change management and after‑hours support as needed.

  • Collaborate with support, networking, and application teams on projects involving identity, endpoints, and cloud services.

  • Performs other work‑related duties as assigned


POSITION REQUIREMENTS


  • 5+ years of progressive hands‑on experience administering Active Directory and Group Policy in production environments.

  • Strong PowerShell scripting skills with proven ability to automate AD, Entra ID, Microsoft 365, and Intune tasks.

  • Demonstrated experience managing Microsoft 365 tenants and Azure AD / Entra ID (including hybrid identity scenarios).

  • Practical experience with Microsoft Intune / Endpoint Manager and mobile device management (MDM).

  • Working knowledge of identity and access management principles, conditional access, MFA, and privileged identity management.

  • Familiarity with Data Loss Prevention (DLP) concepts and Microsoft 365 compliance tools.

  • Understanding of core networking concepts relevant to identity and device management (DNS, certificates, VPN, firewalls).

  • Solid foundation in cybersecurity best practices for identity, endpoints, and hybrid environments.

  • Ability to troubleshoot complex issues across on‑premises, hybrid, and cloud Microsoft stacks.

  • Clear written and verbal communication skills; ability to document technical work and explain issues to both technical and non‑technical audiences.

  • Ability to work independently and collaboratively in a fast‑paced environment.

  • Occasional after‑hours work required for system maintenance and emergency response.


PREFERRED QUALIFICATIONS


  • Microsoft certifications such as AZ-104, MS-102, SC-300, MD-102, or equivalent practical experience.

  • Experience with Microsoft Defender for Endpoint / Identity, Microsoft Sentinel, or similar security tooling.

  • Exposure to certificate services (AD CS / PKI), Entra ID app proxy, or advanced conditional access scenarios.

  • Familiarity with other identity or MDM platforms (e.g., Okta, Jamf) as complementary knowledge.

  • Experience in regulated or highly secured environments (compliance frameworks such as NIST, CIS, and HIPAA requirements).

  • Scripting beyond PowerShell (e.g., Graph API, Azure CLI, or basic Python) is a plus.


ESSENTIAL FUNCTIONS

In order to fulfill the requirements of this position, duties 1-13 are considered essential functions of the job.


ORGANIZATIONAL INVOLVEMENT

This position is required to participate in mandatory all staff meetings, team meetings and trainings.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Systems Administrator
IT Systems Administrator

Union-Community-Care • Lancaster

On-site
USD 90,000 - 120,000
System Admin / Onsite / Mesa
System Admin / Onsite / Mesa

Motion Recruitment Partners LLC • Mesa (AZ)

On-site
USD 120,000 - 160,000
Systems Administrator
Systems Administrator

SPOC Automation • Trussville (AL)

On-site
USD 65,000 - 90,000
Senior Identity and Access Management Analyst
Senior Identity and Access Management Analyst

Baptist Memorial Health Care • Memphis (TN)

On-site
USD 110,000 - 160,000
M365 - Technical Lead, Infrastructure & Applications
M365 - Technical Lead, Infrastructure & Applications

Healthcare Systems of America • Miami (FL)

On-site
USD 85,000 - 120,000
Sr. Infrastructure Security Engineer
Sr. Infrastructure Security Engineer

NOW Health Group INC • Bloomingdale (IL)

On-site
USD 110,000 - 160,000
IT Cloud & Identity Administrator II (Remote)
IT Cloud & Identity Administrator II (Remote)

cafairplan • Los Angeles (CA)

Remote
USD 110,000 - 150,000
Microsoft 365 Enterprise Administrator
Microsoft 365 Enterprise Administrator

Vaco Recruiter Services • Dublin (OH)

Hybrid
USD 95,000 - 135,000
IT SUPPORT ENGINEER
IT SUPPORT ENGINEER

Environmental Restoration LLC • St. Louis (MO)

On-site
USD 65,000 - 95,000
ASSOCIATE IT SPECIALIST - IT SPECIALIST - Microsoft EntraID & Active Directory Administrator
ASSOCIATE IT SPECIALIST - IT SPECIALIST - Microsoft EntraID & Active Directory Administrator

Southwest Research Institute • San Antonio (TX)

On-site
USD 70,000 - 110,000