Cloud Systems Administrator Lufkin US Acquisition Company LLC Missouri City, TX Job Details 8 hours ago Qualifications Cloud identity and access management (IAM) Azure IaaS Public Cloud Endpoint Detection and Response (EDR) Production systems Azure AD Cloud compliance Cross-functional collaboration Cross-functional communication Identity & access management Full Job Description The Cloud Systems Administrator is responsible for the day-to-day administration of the organization's Microsoft cloud environment, including Azure, Microsoft 365, Intune, and NinjaRMM. Reporting to the Director of Information Technology, this role works closely with the Cloud Cybersecurity Engineer on security alignment and serves as the primary internal point of contact for the MSP providing Help Desk and NOC support. Responsibilities Manage day-to-day Azure resources including VMs, virtual networks, storage accounts, and resource groups. Administer Entra ID with hybrid identity sync, RBAC, Privileged Identity Management, and Conditional Access in partnership with the Cybersecurity Engineer. Monitor environmental health using Azure Monitor and Log Analytics; escalate security anomalies to the Cybersecurity Engineer. Administer Exchange Online, SharePoint, Teams, OneDrive, and full M365 user and license lifecycle. Configure M365 tenant settings as directed by the Cybersecurity Engineer, including integrations with Abnormal AI and Defender for Office 365. Monitor M365 service health and communicate impactful changes to the MSP and business stakeholders. Own Intune policy configuration including compliance policies, configuration profiles, Endpoint Security, and App Protection Policies. Manage Windows Autopilot and Apple Business Manager for device enrollment and zero-touch provisioning. Ensure all managed endpoints maintain active SentinelOne agent coverage. Maintain NinjaRMM for endpoint monitoring, remote management, and scripted task execution in coordination with the MSP. Own the patch lifecycle for Windows, macOS, and mobile endpoints using Intune and Windows Update for Business. Maintain deployment rings (test pilot production) aligned to Patch Tuesday cadence. Coordinate patch prioritization with the Cybersecurity Engineer and communicate upcoming rollouts to the MSP Help Desk Document changes to Intune policies, Azure configurations, and patch rings with sufficient detail to support rollback or handoff. Triage SentinelOne alerts and escalate active threats to the MDR service. Review and action high-priority Abnormal AI email quarantine decisions. Apply emergency Conditional Access changes in Entra ID when required. Serve as the internal contact for the NOC on security escalations. Other duties as assigned
Essential Characteristics:
Endpoint Management
- Maintains fully patched, compliant, and consistently enrolled endpoints across the environment. Process Improvement
- Actively identifies opportunities to reduce manual work, streamline workflows, and strengthen collaboration with the MSP. Judgment & Escalation
- Demonstrates sound judgment in knowing when to take independent action and when to escalate issues appropriately. EDR Expertise
- Familiar with modern EDR platforms such as SentinelOne and capable of supporting endpoint security operations. Automation Skills
- PowerShell scripting experience for M365 and Intune automation is a strong plus. Cross-Team Collaboration
- Builds and maintains positive, service-oriented relationships with employees across all departments.
Requirements Education and Training:
Bachelor's degree in IT or a related field, or equivalent hands-on experience or as deemed sufficient by management
Technical Requirements:
Working knowledge of Azure, Entra ID, and Microsoft 365 administration. Familiarity with NinjaRMM or a comparable RMM platform. Basic familiarity with EDR platforms. Sound experience with compliance policies, configuration profiles, Autopilot, and app deployment.
Experience:
At least 3 to 5 years of hands-on experience administering Microsoft cloud environments in a production setting, or as deemed sufficient by management Disclaimer The above information on this description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted, as a comprehensive inventory of all duties, responsibilities, qualifications required of employees assigned to this job.
LUFKIN US
Acquisitions Company LLC is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or any other protected category under applicable law. We celebrate diversity and are dedicated to creating an inclusive atmosphere for all employees. Experience Preferred 3
- 5 years: Hands-on experience administering Microsoft cloud environments in a production setting Education Preferred Bachelors or better in Information Technology or related field
Behaviors Preferred Innovative:
Consistently introduces new ideas and demonstrates original thinking
Functional Expert:
Considered a thought leader on a subject
Enthusiastic:
Shows intense and eager enjoyment and interest
Detail Oriented:
Capable of carrying out a given task with all details necessary to get the task done well
Dedicated:
Devoted to a task or purpose with loyalty or integrity Equal Opportunity Employer This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights (https://www.eeoc.gov/poster) notice from the Department of Labor.