Job Overview
We are seeking a hands-on Network Operations & IT Systems Administrator to keep our corporate infrastructure and our affiliated physician practices running securely and continuously. This is a generalist role in a small, cost-conscious organization: you will own day-to-day operations across a Microsoft-centric environment (Entra ID, Microsoft 365, Azure, Intune, Teams Phone), maintain the network and security posture that protects PHI, and serve as the primary technical support resource for corporate employees and practice staff.
The right candidate is comfortable being both the architect and the person who does the work — someone who can design a firewall policy in the morning, unstick a practice manager's Teams call in the afternoon, and document both.
Core Responsibilities: Identity, Endpoint & Microsoft 365 Operations
- Administer Entra ID: user lifecycle, conditional access, MFA enforcement, privileged access review, and hybrid/on-prem sync where applicable.
- Administer Exchange Online, SharePoint Online, OneDrive, and Teams, including mailbox hygiene, retention policies, external sharing controls, and eDiscovery/legal hold requests.
- Manage Intune for endpoint enrollment, compliance policies, application deployment, patch/update rings, and device wipe for lost or separated-employee hardware.
- Maintain Microsoft Teams Phone (PSTN calling, auto attendants, call queues, e911 records) for corporate and practice locations; phones are patient-facing and treated as a production system.
Network & Infrastructure Operations
- Operate and maintain the SD-WAN topology connecting corporate HQ and affiliated practice locations, including IPSec tunnels, failover circuits, and site turn-ups for new practices.
- Manage firewall rulesets, VLAN/Layer 2–3 switching, wireless infrastructure, DNS/DHCP, and remote access.
- Administer Azure resources (VNets, VMs, storage, resource groups) with attention to right-sizing and reserved-instance coverage; report monthly on cloud spend.
- Own backup and disaster recovery: verify backups actually restore, maintain immutable/air-gapped copies, and run a documented restore test at least annually.
Security & HIPAA Compliance
- Serve as (or directly support) the designated HIPAA Security Official under 45 CFR §164.308(a)(2).
- Maintain and update the HIPAA Security Risk Analysis and remediation plan; maintain the policy set, workforce security-awareness training, and access-audit logs.
- Administer endpoint detection and response, email security, and DLP; triage alerts and escalate confirmed incidents.
- Maintain the incident response and breach-notification runbook and participate in tabletop exercises.
- Track Business Associate Agreements for every vendor that touches PHI — including AI vendors.
- Support annual cyber-insurance attestations and any payer, partner, or franchise security questionnaires.
End-User & Practice Support
- Serve as escalation point for corporate staff and practice office managers; own the ticket queue, SLAs, and asset inventory.
- Onboard and offboard employees and practice staff, including same-day access revocation on termination.
- Support EMR/practice-management, e-prescribing, e-signature, telehealth, and payment-processing integrations at the connectivity and identity layer.
AI Governance & Enablement
- Administer Microsoft Copilot and other approved AI tooling: licensing, data-boundary configuration, and ensuring PHI is only processed under a signed BAA.
- Enforce acceptable-use policy for AI tools and monitor for unsanctioned “shadow AI” use with patient or employee data.
- Identify and implement practical automation — ticket deflection, documentation, reporting, script generation — that reduces manual IT labor.
Required Qualifications
- 5+ years in systems/network administration, at least 2 of which in a Microsoft 365 + Azure environment.
- Demonstrated hands-on ownership of Entra ID, Exchange Online, Intune, and Windows Server.
- Working knowledge of routing, switching, VPN/IPSec, and firewall administration (SD-WAN experience strongly preferred).
- Direct experience operating under HIPAA or an equivalent regulated framework, including risk analysis and audit-log discipline.
- Proven backup/DR ownership with real restore experience.
- Scripting for automation (PowerShell required; Python or Graph API a plus).
- Ability to be on call for after-hours outages and to travel occasionally to practice locations.
Certifications Required — at least one of:
- Microsoft MS-102 (Microsoft 365 Administrator Expert) or AZ-104 (Azure Administrator Associate)
- CompTIA Security+
Strongly preferred:
- Microsoft SC-300 (Identity & Access Administrator) — most directly aligned to daily work
- Microsoft SC-200 (Security Operations Analyst)
- Microsoft AZ-800/801 (Windows Server Hybrid Administrator)
- Cisco CCNA or your firewall vendor's equivalent (Fortinet NSE, Palo Alto PCNSA, Meraki CMNA)
- CompTIA Network+, CySA+
Healthcare security (preferred, not required):
- HCISPP (ISC2) or CISSP for senior candidates
Benefits:
- 401(k)
- Dental insurance
- Flexible spending account
- Health insurance
- Life insurance
- Paid time off
- Vision insurance
Work Location: Hybrid remote in Boca Raton, FL 33431