About the Company
We are a Healthcare IT Data & Analytics company that is on the cutting edge, with an amazing offering. We have a very fun, creative, collaborative, and fast-paced work environment. This is a fantastic team that has a great work/life balance.
About the Role
Helpdesk Administrator
*This is a 100% Remote and full-time opportunity*
Position Summary
We’re looking for a Helpdesk Administrator to own the end-user computing environment. This is not a ticket-triage-and-escalate role — you’ll be the primary owner of every laptop and workstation in the company, from enrollment through decommission, including the security posture of those endpoints.
You’ll administer our Microsoft 365 and Entra ID tenant, run device management through Intune and NinjaOne RMM, and take full ownership of workstation patching and vulnerability remediation. We operate in a HITRUST and SOC 2 regulated environment, so endpoint compliance isn’t a nice-to-have; it’s an audited control you’ll be accountable for.
Key Responsibilities
Microsoft 365 & Entra ID Administration
- Manage user lifecycle: account creation, renames, transfers, and offboarding
- Administer license assignment, optimization, and reclamation across M365 SKUs
- Create and maintain security groups, distribution lists, and dynamic group membership rules
- Support Entra ID administration including group-based access, MFA registration issues, and sign-in troubleshooting
- Manage Company Portal availability, app assignment, and the self-service enrollment experience
Endpoint & Device Management
- Own device enrollment across macOS (ABM/ADE → Intune) and Windows
- Build, test, and troubleshoot Intune configuration and compliance policies
- Administer NinjaOne RMM: agent deployment, policy configuration, remote script execution, and automation
- Perform laptop maintenance, imaging, refresh cycles, and hardware lifecycle tracking
- Coordinate device offboarding, wipe verification, and asset return with vendor partners
- Maintain accurate endpoint inventory and enrollment compliance reporting
Patch & Vulnerability Management (primary ownership)
- Own the full workstation patching program — OS updates, third-party software, and firmware — across macOS and Windows
- Define and maintain patch rings, deployment schedules, and deferral policies in Intune and NinjaOne
- Actively hunt vulnerabilities across the workstation fleet rather than waiting for them to be reported
- Triage, prioritize, and remediate endpoint findings surfaced by the security team, working to defined SLAs by severity
- Track and report remediation status, patch compliance percentages, and exception justifications for audit evidence
- Investigate and resolve failed patch deployments and non-compliant devices
Ticket Ownership
- Serve as primary owner for internal end-user support tickets (excluding server and cloud infrastructure, which sit with Platform Engineering)
- Own all security, QAR, and security-team-generated tickets relating to laptops and workstations
- Maintain ticket hygiene: accurate categorization, documented resolution steps, and timely closure
- Identify recurring issues and drive permanent fixes rather than repeat remediation
Compliance & Documentation
- Maintain endpoint controls in support of HITRUST and SOC 2 requirements
- Produce audit evidence on request — patch compliance, encryption status, enrollment coverage, and access reviews
- Follow established change management SOPs and CAB procedures for endpoint-impacting changes
- Write and maintain runbooks, standard operating procedures, and end-user documentation
Required Qualifications
- 3+ years in a helpdesk, desktop support, or endpoint administration role
- Hands-on administration of Microsoft 365 and Entra ID (user, license, and group management)
- Working experience with Microsoft Intune for device configuration and compliance
- Experience with an RMM platform (NinjaOne, Kaseya, Datto, or similar)
- Demonstrated ownership of a patch management program
- Support experience across both macOS and Windows in a managed environment
- Scripting ability for automation and remediation (PowerShell, Bash, or Python)
- Strong written communication and documentation habits
Preferred Qualifications
- Experience in a HITRUST, SOC 2, or HIPAA-regulated environment
- Familiarity with vulnerability management tooling and CVE triage
- Experience with Apple Business Manager and Automated Device Enrollment
- Jira or equivalent ticketing system experience
- Microsoft certifications (MD-102, MS-102) or equivalent
- Exposure to Conditional Access policy design and troubleshooting
What Success Looks Like
- First 30 days — Fully ramped on the M365, Intune, and NinjaOne environments. Handling day-to-day tickets independently.
- First 90 days — Owning the workstation patch cycle end to end. Endpoint compliance reporting is accurate and current.
- First 6 months — Fleet patch compliance is measurably improved, vulnerability remediation is running to SLA, and repeat ticket categories have been reduced through automation or permanent fixes.





