Our client is a rapidly growing consulting firm with over 10 years of experience working with clientele ranging from Fortune 500 to early-stage pre-IPO companies. They offer an array of services that solve problems surrounding compensation, financial reporting, and human resource functions to ultimately advance their client’s long-term strategy.
The Position
Our client’s CTO is seeking a Senior System Administrator to join its Technology and Innovation group. This is a senior hands-on IT operations role focused on owning and administering the platforms, endpoints, identity systems, and security controls that support the business every day.
You’ll support the business applications employees rely on, the laptops and devices they work from, and the identity and access controls that help protect sensitive client data. The organization is also transitioning away from a virtual desktop environment toward managed, trusted laptops, making endpoint management an increasingly important part of the security perimeter.
This role will own that transition operationally while helping maintain continuously audit-ready environments for SOC 1 and SOC 2 requirements. The position reports to the Head of IT and is well suited for someone who takes ownership, communicates clearly with non-technical colleagues, and proactively addresses issues before they become problems.
Primary responsibilities include:
- Administer the firm’s core business platforms, including Monday.com, Jira, HubSpot, and other SaaS applications, with responsibility for user provisioning, permissions, workspace structure, integrations, and license management.
- Manage Claude access and spending controls, including seat provisioning, group membership, usage limits, and cost monitoring against budget.
- Own Microsoft Intune administration for the Windows fleet and Jamf administration for Macs and iPads, including enrollment, compliance policies, configuration profiles, application deployment, and patching.
- Build and operate the trusted laptop program, including device baselines, encryption, conditional access enrollment, and lifecycle management from provisioning through decommissioning.
- Support the transition from VDI to physical laptops, including imaging, migrations, user onboarding, and managing the exceptions that arise during the transition.
- Administer Microsoft 365 and Entra identity, including SSO, group management, conditional access, license assignment, and end-to-end onboarding and offboarding.
- Administer OneDrive and SharePoint governance, including storage policies, retention, and external-sharing controls appropriate for an organization handling client data.
- Automate repetitive administrative processes using PowerShell or Python to improve onboarding and offboarding, reporting, license reconciliation, and compliance evidence collection.
- Monitor security alerting across Microsoft 365 Defender, Intune, and endpoint tooling, using sound judgment to triage and investigate events and elevate based on severity.
- Execute ISMS automation work in Vanta and own technical evidence collection for SOC 1 and SOC 2, including access reviews, device compliance, patch records, and offboarding logs.
- Proactively identify control gaps and access drift before they become audit findings.
- Work collaboratively across the organization with a strong focus on exceptional internal service, execution, professional development, and continuous improvement.
- Solve complex and ambiguous technology problems with creativity, rigor, and a bias toward action and measurable impact.
Qualifications and Candidate Background
The ideal candidate will have:
- 6+ years of experience in system administration, IT operations, or endpoint management within a business environment.
- Hands‑on administration experience with Microsoft Intune and Microsoft 365/Entra, including conditional access and identity governance.
- Experience with Jamf for macOS and iPad management.
- Demonstrated experience administering SaaS business platforms such as Monday.com, Jira, HubSpot, or comparable tools, including permissions models, integrations, and license governance.
- Working knowledge of OneDrive and SharePoint administration, including sharing and retention policy enforcement.
- Scripting proficiency in PowerShell or Python sufficient to automate routine administrative work, reporting, and evidence collection.
- Experience supporting SOC 1 or SOC 2 evidence collection and control operation. Familiarity with compliance automation platforms such as Vanta is a strong plus.
- Practical security monitoring experience, with the ability to triage alerts thoughtfully rather than escalating indiscriminately or failing to elevate when appropriate.
- Experience supporting a VDI-to-physical-endpoint migration or comparable environment transition is a plus.
- Strong written and verbal communication skills, with the ability to explain technical constraints and solutions clearly
Location
This position is in the Greater Phoenix area.
Your information will not be shared with any outside parties without your prior consent