Salt Lake City metro. Onsite at our facility, with regular travel to client locations.
Employment type:
Full-time, exempt
Travel:
Weekly local travel along the Wasatch Front. Periodic multi-state travel supporting client onboardings and acquisition integrations. Position summary The Senior Systems Administrator holds primary technical ownership of assigned client environments. You are accountable for the health, security, recoverability, and documentation of the infrastructure, and for the accuracy of what we communicate to our clients.
You are the senior technical escalation point for our desktop support team and the resolution owner for issues that reach you. You will also be the senior technical voice in client conversations and a working partner to the Director of Information Systems on architecture and remediation planning. The environments you inherit will not all be well built. A meaningful portion of this role is assessing what you've been handed, prioritizing correctly, and bringing it up to a standard we can defend.
We are hiring at the senior level deliberately. This posting reflects capabilities you are expected to bring with you, not a development plan. Core responsibilitiesEscalation ownership. Serve as the technical escalation point for desktop support and junior administrators. Take issues to resolution rather than routing them onward, and close the loop with root cause and documentation so the same ticket doesn't return next month. Microsoft 365 and identity administration. Full tenant ownership across Entra ID, conditional access, MFA and authentication policy, licensing optimization, Exchange Online, and Teams. Execute tenant-to-tenant migrations, domain cutovers, and hybrid identity remediation as clients acquire, divest, or restructure. SharePoint Online and information architecture. Design and implement site structures and permission models that survive turnover. Lead file-server-to-SharePoint migrations, govern external sharing, and remediate sprawl in tenants that were never architected. Microsoft Purview and data governance. Implement retention, sensitivity labeling, DLP policy, and eDiscovery holds for clients carrying regulatory or contractual obligations. Windows Server and virtualization. Build, harden, patch, and lifecycle-manage physical and virtual server infrastructure. Active Directory Domain Services, DNS, DHCP, Group Policy, file and print, certificate services. Hyper-V and VMware host administration, capacity planning, and hardware refresh forecasting. Backup, recovery, and business continuity. Own the backup estate for your accounts. Maintain verified job status, execute scheduled restore testing, document RTO and RPO by client, and be able to state without hesitation what an outage would cost a given business in downtime and data loss. Network and security operations. Firewall policy administration, segmentation, VPN, wireless, and switching. Vulnerability and patch remediation across the managed fleet. EDR alert triage and response. Execute control improvements as part of our
NIST CSF 2.0
assessment and remediation program. Endpoint management. Intune, Autopilot, compliance and configuration policy, and application deployment across a multi-tenant estate. Project delivery. Lead the technical execution of client onboardings, acquisition integrations, platform migrations, office builds, and relocations. Scope accurately, schedule realistically, and communicate slippage early. Documentation. Maintain the system of record for every environment you touch. Documentation is a deliverable, not an afterthought, and it is part of what our clients pay for. Client engagement. Communicate directly with owners, controllers, and operations leadership. Translate technical risk into business terms, present options with costs and tradeoffs, and support quarterly business reviews with accurate environment data. Mentorship. Provide technical direction to desktop support staff and junior administrators. Raise the standard of the work around you. Required qualifications Five or more years administering Windows Server and Microsoft 365 in production environments, with at least two years in a managed services, multi-tenant, or multi-site setting. Demonstrated Microsoft 365 depth: domain and mail cutovers, tenant migrations, conditional access design, licensing rationalization, and hybrid identity troubleshooting. SharePoint Online administration, including at least one completed file-server-to-SharePoint migration you can describe in detail. Microsoft Purview administration covering retention, DLP, or eDiscovery in a live compliance context. Windows Server 2016 through 2025, Active Directory, and Group Policy at a design and troubleshooting level. PowerShell scripting for administration, reporting, and automation. You should be automating anything performed more than twice. Enterprise backup administration on a mainstream platform such as Veeam, Datto, Acronis, or Azure Backup, including documented restore testing. Hypervisor administration on Hyper-V or VMware, including host maintenance and capacity management.
Applied networking:
subnetting, routing, VLAN design, firewall rule administration, and structured troubleshooting across the stack. Practical experience with UniFi, Meraki, Fortinet, or SonicWall. Microsoft Intune and modern endpoint management in production. Security operations experience including patch and vulnerability management, endpoint protection administration, and remediation work against a recognized framework such as
NIST CSF
2.0 or CIS Controls. Professional discipline in a PSA or ticketing system: accurate time entry, proactive status communication, and SLA management. Client-facing communication skills sufficient to hold a technical conversation with a business owner who is not technical, and to be believed. Valid driver's license, reliable transportation, and the physical ability to rack and handle equipment. Ability to pass a background check. Several client contracts require it. Relevant certifications, including MS-102, AZ-800/801, Security+, or equivalent, strengthen an application but do not substitute for demonstrated production experience. How this team operates We do not close tickets that leave a client worse off in six months. Correct takes priority over fast, and we would rather you spend the extra hour than hand a recurring problem to the next person on call.
We escalate early and honestly. There is no penalty here for saying you're stuck. There is a real one for spending half a day in silence on a question someone could have answered in two minutes.
You will hold production access to organizations that stop operating without their systems. That access carries an expectation of change discipline, communication before the work, and immediate disclosure when something goes wrong. It happens to everyone eventually. What matters is what we hear and when.
This is a lean team carrying a substantial book of business. Judgment about what matters most, on a day when everything is urgent, is a genuine requirement of the role. Expectations in the first 90 days Day 30. Fluent in our stack, documentation standard, and service process. Independently resolving escalations from desktop support. Introduced to and oriented within your assigned accounts. Day 60. Full ownership of your assigned environments. Backups verified, patch posture current, documentation gaps identified with a closure plan. Leading client conversations without support. Day 90. Carrying project delivery alongside operational load, contributing to onboarding or remediation initiatives, and recognized by clients as their primary technical contact. On-call Rotating after-hours and weekend on-call shared across the team. Maintenance windows fall outside business hours and are scheduled in advance. Application requirement Submit a resume along with a written response to the following: Describe a client or corporate environment you inherited in poor condition. What did you find, what did you address first, and why did you sequence it that way? Responses that catalog technologies will not advance. We are evaluating how you triage.
Pay:
$60,000.00 - $75,000.00 per year
Benefits:
401(k) 401(k) matching Dental insurance Employee discount Health insurance Paid time off Professional development assistance