Job Description
A Brief Overview
The Senior IT Systems Analyst is responsible for the day-to-day administration, support, and maintenance of Hunt's Microsoft 365 environment, with primary focus on Microsoft Intune (endpoint management) and Microsoft Entra ID (identity and access management). Working under the direction of the Service Desk Director, this hands-on technical role supports the configuration, operation, and continuous improvement of device management, identity management, and access control solutions across the organization. The role serves as an escalation point for complex Tier 2 and Tier 3 support issues received from the outsourced Tier 1 service desk and internal users. In addition to troubleshooting and resolving technical issues, the Senior IT Systems Analyst contributes to service effectiveness by documenting processes, developing knowledge base content, identifying recurring issues, and implementing practical improvements that enhance support efficiency and reduce repeat incidents.
What you will do
- Microsoft Intune / Endpoint Management:
- Administers and supports Intune across Windows, iOS/iPadOS, Android, and macOS: enrollment, compliance policies, configuration profiles, and device lifecycle.
- Supports the administration and maintenance of Windows Autopilot — profile design, Enrollment Status Page, ESP/hash management, and coordination with the hardware supplier and imaging process.
- Packages, deploys, and maintains applications (Win32/.intunewin, LOB, Microsoft Store, Company Portal), including detection rules, dependencies, and supersedence.
- Administers Windows Update for Business / Autopatch rings, driver and firmware update policies, and feature update deferrals; reports on device compliance and patch status.
- Implements and maintains security baselines, Defender for Endpoint policy, BitLocker/FileVault encryption policies, and Local Administrator Password Solution (LAPS).
- Supports the administration of app protection (MAM) policies for corporate data on unmanaged and BYOD devices.
- Assists with endpoint management initiatives, including support for technology migrations and device management improvements.
- Troubleshoots enrollment, configuration, compliance, and synchronization issues and documents resolutions.
- Microsoft Entra ID / Identity & Access:
- Administers Entra ID: users, groups, dynamic group rules, administrative units, and license assignment via group-based licensing.
- Supports the implementation, testing, and maintenance of Conditional Access policies; uses report-only mode and What If analysis before enforcement, and documents exclusions with an owner and review date.
- Administers authentication methods and MFA rollout, passwordless/Windows Hello for Business, Temporary Access Pass, and self-service password reset.
- Supports enterprise application SSO (SAML/OIDC), app registrations, service principals, API permissions, and SCIM provisioning for third-party SaaS.
- Assists with privileged access administration and access review activities in alignment with established security policies and procedures.
- Supports identity lifecycle automation for joiner/mover/leaver processes in coordination with HR systems.
- Reviews sign-in and audit logs to assist with troubleshooting access-related issues and account investigations.
- Microsoft 365 Tenant Administration:
- Provides administration and support for Microsoft 365 services, including Exchange Online, SharePoint Online, OneDrive, and Teams.
- Monitors Microsoft 365 service health and communicates relevant service disruptions and updates to stakeholders.
- Maintains software licensing data and assists with license assignment reviews and reporting activities.
- Assists with data protection controls in scope for the role: retention policies, sensitivity labels, and DLP policies, in coordination with Security and Legal.
- Maintains tenant configuration documentation, change records, and a current architecture/runbook set.
- Tier 2 / Tier 3 Escalation & Service Desk Support:
- Serves as the escalation point for Intune, Entra, and Microsoft 365 issues raised by the outsourced Tier 1 provider and internal Tier 2 staff.
- Investigates and resolves escalated incidents within agreed service levels. Documents findings with clear written root cause and resolution notes in the ticketing system.
- Identifies recurring technical issues and recommends improvements to reduce repeat incidents and support requests.
- Develops and maintains knowledge base articles, work instructions, and training material that let Tier 1 and Tier 2 resolve issues without escalation; measure and report deflection.
- Provides technical guidance and knowledge sharing to support employees on Microsoft 365-related technologies and processes.
- Participates in an on-call or after-hours rotation for critical identity and endpoint incidents.
- Automation, Security & Continuous Improvement:
- Develops and maintains PowerShell (Microsoft Graph PowerShell SDK, Exchange Online module) for reporting, bulk changes, and repeatable administrative tasks.
- Assists with process-improvement initiatives to streamline provisioning, access management, and support functions.
- Follows established change management processes: tests in a pilot or non-production ring, documents rollback, and obtains approval before tenant-wide changes.
- Supports audit and compliance evidence requests related to access, device compliance, and privileged accounts.
- Participates in business continuity and recovery activities related to supported systems and services.
Education Qualifications
- Bachelor's Degree in Information Technology, Computer Science, or a related field required.
- In lieu of a degree, an equivalent combination of education and directly relevant experience required.
Experience Qualifications
- 4-6 years experience in IT operations, systems administration, or endpoint/identity engineering, including a minimum of three years of hands-on Microsoft 365 tenant administration required.
- Demonstrable production experience administering Microsoft Intune at scale, including Autopilot, compliance and configuration policies, and Win32 application packaging and deployment required.
- Demonstrable production experience administering Microsoft Entra ID, including Conditional Access, MFA/authentication methods, group-based licensing, and hybrid identity via Entra Connect required.
- Working knowledge of on-premises Active Directory, Group Policy, DNS, and certificate services, and how each interacts with cloud identity required.
- Practical PowerShell scripting ability for administration and reporting; familiarity with Microsoft Graph required.
- Experience working within a tiered support model and an ITSM ticketing platform, with an understanding of incident, problem, and change management required.
- Ability to produce clear written technical documentation for both engineers and non-technical staff required.
- Track record of handling elevated/global administrative privileges responsibly, including discretion with sensitive employee and business data required.
Knowledge, Skills, and Abilities
- One or more current Microsoft certifications: MD-102 (Endpoint Administrator), SC-300 (Identity and Access Administrator), MS-102 (Microsoft 365 Administrator), or AZ-104 (Azure Administrator).
- Experience supporting or overseeing an outsourced/managed service desk provider, including quality review and knowledge transfer.
- Microsoft Defender for Endpoint, Defender for Office 365, or Microsoft Sentinel experience.
- Microsoft Purview experience — retention, sensitivity labels, DLP, eDiscovery.
- macOS and/or iOS management at scale, including Apple Business Manager and ADE.
- Experience migrating from Configuration Manager/Group Policy to Intune, or from AD-joined to Entra-joined endpoints.
- Experience in real estate, property management, financial services, or another regulated or multi-entity environment.
- Takes an issue to root cause rather than closing the symptom; follows through without prompting.
- Understands the blast radius of tenant-wide changes and tests before enforcing.
- Explains technical constraints and risk in terms that a business stakeholder or an end user can act on.
- Treats runbooks and knowledge base details.
- Partners effectively with the outsourced provider and Tier 2 rather than working around them.
- Keeps current with a Microsoft cloud platform that is continuously evolving and assesses what matters to the environment.
Compensation
We are committed to offering competitive and equitable compensation. Final salaries will be determined based on factors such as geographic location, skills, education, licenses, certifications, and/or experience. In addition to these factors – we believe in the importance of pay equity. We consider internal and external factors as a part of every final offer. We also offer a generous total compensation and benefits package.
Benefits
A competitive salary is only one part of your total rewards. We also offer a comprehensive benefits package, including paid time off, medical, dental, life and disability insurance, HSA/FSA accounts, retirement, rewards programs, and so much more!
Click Here for Benefits Overview
https://www.huntmilitarycommunities.com/careers/benefits
EEO/ADA
The Company and its affiliates provides equal employment opportunity to all individuals regardless of their race, color, creed, religion, gender, age, sexual orientation, national origin, disability, veteran status, or any other characteristic protected by state, federal, or local law. Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions.
#INDHUNT