IT Systems Administrator (62996)

Union Community Care

Lancaster (Lancaster County)

On-site

USD 90,000 - 120,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Union Community Care in Lancaster, PA is seeking a seasoned IT professional to manage and secure a hybrid Microsoft‑centric infrastructure. You will own AD, Group Policy, Azure AD/Entra ID, Intune, MDM, and security controls, collaborating with security, networking, and operations teams to maintain reliability and compliance.

Ideal candidates bring 5+ years of hands-on experience, strong PowerShell skills, and a pragmatic problem‑solving mindset to support a healthcare environment with HIPAA

Qualifications

  • 5+ years hands-on experience administering Active Directory and Group Policy in production
  • Strong PowerShell scripting skills to automate AD/Entra ID/M365/Intune tasks
  • Experience managing Microsoft 365 tenants and Azure AD/Entra ID, including hybrid identity
  • Practical experience with Intune/Endpoint Manager and MDM
  • Knowledge of IAM, conditional access, MFA, and privileged identity management
  • Familiarity with DLP concepts and M365 compliance tools
  • Understanding of DNS, VPN, certificates, and firewall basics
  • Clear written and verbal communication; able to document technical work

Responsibilities

  • Administer and maintain on-prem Active Directory domains and GPOs
  • Design and deploy Group Policy configurations for security baselines
  • Write and optimize PowerShell scripts for AD/Azure AD/M365/Intune
  • Manage Microsoft 365 tenants: Exchange Online, SharePoint, Teams, OneDrive
  • Administer Azure AD/Entra ID users, groups, app registrations, and CA
  • Own Intune and MDM operations: device enrollment, configs, compliance
  • Support SSO, MFA, and passwordless initiatives
  • Implement and monitor DLP policies across Microsoft 365
  • Assist with network aspects impacting identity and device management
  • Contribute to cybersecurity posture and incident response
  • Document configurations, runbooks; participate in change management
  • Collaborate with cross-functional teams on identity and cloud projects

Skills

PowerShell scripting
Active Directory administration
Group Policy management
Azure AD / Entra ID
Intune / Endpoint Manager
MDM
Security controls
Troubleshooting
Documentation
Communication skills

Tools

Microsoft Defender for Endpoint
Microsoft Sentinel
AD CS / PKI
Entra ID app proxy

Job description

Job Details

Job Location: Administration - Lancaster, PA 17602


Our Mission, Vision, & Model of Care

At Union Community Care, our purpose is at the forefront of all that we do: we stand for whole health to help you live your fullest life.


We envision vibrant and healthy communities supported by inclusive healthcare that embraces each member’s unique culture, needs, and values, and emboldens them to make healthful choices that fuel their well-being and the well-being of others.


We believe in whole health. This means we address and heal disease but equally important, we work at the causes of the causes, the social ills that must be addressed to achieve true equity.


We listen, learn, and embrace the complex lives and unique strengths of our patients, and we work hard to break down all barriers to care. This means we look through a grassroots lens. We connect with our communities because we are our communities. Each of us is a neighbor, a friend, a family member, and together, we are a trusted community health center.


Qualifications

JOB SUMMARY

We are seeking a seasoned technician with deep hands‑on expertise in Microsoft identity, endpoint, and cloud administration to manage and secure our hybrid environment. This role focuses on Active Directory, Group Policy, Microsoft 365, Azure tenant operations, Intune/MDM, identity governance, and related security controls. The ideal candidate is a pragmatic problem‑solver who can design, implement, maintain, and troubleshoot complex Microsoft‑centric infrastructure while collaborating with security, networking, and operations teams. Healthcare/Epic experience a plus, but not required.


SPECIFIC JOB DUTIES


  • Administer and maintain on‑premises Active Directory (AD) domains, including user/computer object management, OU design, Group Policy Objects (GPOs), and replication health.

  • Design, test, deploy, and troubleshoot Group Policy configurations for security baselines, software deployment, and configuration management.

  • Write, maintain, and optimize PowerShell scripts and modules for automation of AD, Azure AD / Entra ID, Microsoft 365, and Intune tasks.

  • Manage Microsoft 365 tenants: Exchange Online, SharePoint Online, Teams, OneDrive, licensing, and service health.

  • Administer Azure AD / Microsoft Entra ID (users, groups, app registrations, conditional access, PIM, identity protection, hybrid identity with Entra Connect).

  • Own Intune (Microsoft Endpoint Manager) and MDM operations: device enrollment, configuration profiles, compliance policies, application deployment, and Autopilot.

  • Support identity lifecycle management, single sign‑on (SSO), multifactor authentication (MFA), and passwordless initiatives.

  • Implement and monitor Data Loss Prevention (DLP) policies across Microsoft 365 and related platforms.

  • Assist with network‑related aspects of identity and endpoint management (DNS, DHCP, VPN, certificate services, firewall rules affecting authentication and device connectivity).

  • Contribute to cybersecurity posture through hardening of AD/Azure AD, privileged access management, logging/monitoring (including Microsoft Defender and Sentinel where applicable), and response to identity‑related incidents.

  • Document configurations, procedures, and runbooks; participate in change management and after‑hours support as needed.

  • Collaborate with support, networking, and application teams on projects involving identity, endpoints, and cloud services.

  • Performs other work‑related duties as assigned


POSITION REQUIREMENTS


  • 5+ years of progressive hands‑on experience administering Active Directory and Group Policy in production environments.

  • Strong PowerShell scripting skills with proven ability to automate AD, Entra ID, Microsoft 365, and Intune tasks.

  • Demonstrated experience managing Microsoft 365 tenants and Azure AD / Entra ID (including hybrid identity scenarios).

  • Practical experience with Microsoft Intune / Endpoint Manager and mobile device management (MDM).

  • Working knowledge of identity and access management principles, conditional access, MFA, and privileged identity management.

  • Familiarity with Data Loss Prevention (DLP) concepts and Microsoft 365 compliance tools.

  • Understanding of core networking concepts relevant to identity and device management (DNS, certificates, VPN, firewalls).

  • Solid foundation in cybersecurity best practices for identity, endpoints, and hybrid environments.

  • Ability to troubleshoot complex issues across on‑premises, hybrid, and cloud Microsoft stacks.

  • Clear written and verbal communication skills; ability to document technical work and explain issues to both technical and non‑technical audiences.

  • Ability to work independently and collaboratively in a fast‑paced environment.

  • Occasional after‑hours work required for system maintenance and emergency response.


PREFERRED QUALIFICATIONS


  • Microsoft certifications such as AZ-104, MS-102, SC-300, MD-102, or equivalent practical experience.

  • Experience with Microsoft Defender for Endpoint / Identity, Microsoft Sentinel, or similar security tooling.

  • Exposure to certificate services (AD CS / PKI), Entra ID app proxy, or advanced conditional access scenarios.

  • Familiarity with other identity or MDM platforms (e.g., Okta, Jamf) as complementary knowledge.

  • Experience in regulated or highly secured environments (compliance frameworks such as NIST, CIS, and HIPAA requirements).

  • Scripting beyond PowerShell (e.g., Graph API, Azure CLI, or basic Python) is a plus.


ESSENTIAL FUNCTIONS

In order to fulfill the requirements of this position, duties 1-13 are considered essential functions of the job.


ORGANIZATIONAL INVOLVEMENT

This position is required to participate in mandatory all staff meetings, team meetings and trainings.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Systems Administrator
IT Systems Administrator

Union-Community-Care • Lancaster

On-site
USD 90,000 - 120,000
Sr Systems Administrator
Sr Systems Administrator

Progressive IT • Irving (TX)

Hybrid
USD 90,000 - 140,000
System Admin / Onsite / Mesa
System Admin / Onsite / Mesa

Motion Recruitment Partners LLC • Mesa (AZ)

Hybrid
USD 120,000 - 160,000
Security Administrator
Security Administrator

Centers for Independence • Milwaukee (WI)

On-site
USD 90,000 - 130,000
Systems Administrator
Systems Administrator

SPOC Automation • Trussville (AL)

On-site
USD 65,000 - 90,000
Systems Administrator
Systems Administrator

MetroSys, Inc. • Lisle (IL)

On-site
USD 70,000 - 95,000
System Administrator
System Administrator

Insight Global • Terre Haute (IN)

Hybrid
USD 85,000 - 120,000
Power Apps administration
Teams administration
SharePoint Online administration
+3
System Admin / Onsite / Mesa
System Admin / Onsite / Mesa

Motion Recruitment • Mesa (AZ)

On-site
USD 110,000 - 150,000
System Administrator - Hybrid
System Administrator - Hybrid

AllCom Global Services / STRANTECH • Lake Saint Louis (MO)

Hybrid
USD 65,000 - 90,000
IT Systems Engineer
IT Systems Engineer

LegalSight • United States

Hybrid
USD 90,000 - 130,000
Hybrid work arrangement
Priority for local candidates (Ocean C
Office-based collaboration two days a週