Senior IT Administrator
Finzly
Let the right jobs find you
Get personalised suggestions from verified company career pages, matched to your role, location, level, and skills.
Overview
Position Type
Full Time
Experience
7+ years
Job Description
We are seeking a Senior IT Systems Administrator to own day-to-day endpoint, identity, network, and cloud infrastructure operations during a high-impact contract engagement. The role spans the full device lifecycle — Autopilot provisioning, Intune policy management, Defender for Endpoint hardening, Zscaler secure access, Fortinet network infrastructure, patching, vulnerability remediation, and asset management — all within a regulated financial services environment. You will partner with Information Security, DevOps, and Infrastructure teams to maintain zero-trust posture, endpoint compliance, and audit readiness.
Key Responsibilities:
- Manage the full endpoint lifecycle via Microsoft Intune and Windows Autopilot — zero-touch provisioning, compliance policies, configuration profiles, app deployment, BitLocker enforcement, USB blocking and selective wipe.
- Own patching and vulnerability management program — Intune ring-based deployment, third-party patching (Autopilot) and remediation & SLA compliance.
- Administer Microsoft Entra ID and on-premises Active Directory — Conditional Access Policy, Attack Surface Reduction, PIM, MFA and SSO enforcement.
- Deploy and operate Microsoft Defender for Endpoint (AV/AM, EDR, ASR, AIR) and Zscaler (ZIA/ZPA) to maintain endpoint security and zero-trust network access.
- Manage and maintain Fortinet network infrastructure — FortiGate firewalls (policy rules, VPN tunnels, NAT, IPS/threat protection), FortiSwitch (VLAN configuration, port security, link aggregation), and FortiAP wireless access points (SSID management, RF optimization, guest networks).
- Coordinate ISP circuit management — liaison with service providers on circuit provisioning, outage escalation, bandwidth upgrades, and SLA tracking for primary and redundant WAN links.
- Administer Microsoft 365 services and the SharePoint Admin Center — Exchange Online, Teams, OneDrive, site permissions and retention policies.
- Manage IT asset inventory across the full lifecycle — procurement, assignment, warranty tracking, and secure disposal/decommissioning.
- Develop PowerShell automation for remediation, compliance reporting, configuration-drift detection, and bulk operations.
- Maintain runbooks, SOPs, network diagrams, and knowledge-base articles; provide audit evidence for SOC 1/2, PCI DSS, FFIEC, and NYDFS examinations.
- Provide support for network, VPN, Wi-Fi, and Zscaler connectivity issues; participate in incident response as needed. Maintain IP address management.
Requirements:
- 8–10+ years of progressive IT systems administration or endpoint engineering experience, preferably in financial services or equivalent.
- Expert-level Microsoft Intune and Autopilot — enrollment, compliance/ configuration profiles, Win32 app packaging, and all deployment modes.
- Strong Entra ID / Active Directory skills — Conditional Access, PIM, etc.
- Proven Defender for Endpoint and Zscaler (ZIA/ZPA) administration — EDR investigation, ASR tuning, policy configuration, and client troubleshooting.
- Hands-on Fortinet experience — firewall administration (policies, VPN, NAT, IPS), FortiSwitch management, and FortiAP wireless deployment and troubleshooting.
- Experience with ISP circuit coordination (provisioning, outage management, SLA tracking) and IP address management (DHCP scoping, DNS, subnet planning).
- Hands-on patching and vulnerability management experience — scan triage, risk-based prioritization, and compliance reporting.
- Proficient in PowerShell scripting; BitLocker enforcement, recovery-key escrow, and TPM management.
- Working knowledge of Microsoft 365 administration, SharePoint Online, Exchange Online, and IT asset lifecycle management.
- Strong documentation, communication, and cross-functional collaboration skills.
Education Qualification:
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field — required.
Certifications:
- Mandatory (at least 2): Microsoft Certified: Endpoint Administrator Associate; Microsoft Certified: Modern Desktop Administrator Associate (MD-102); Microsoft Certified: Identity and Access Administrator Associate (SC-300); CompTIA Security+; CompTIA CySA+; Systems Security Certified Practitioner (SSCP).
- Recommended / Preferred: Microsoft Certified: Security Operations Analyst Associate (SC-200); CompTIA Network+; Cisco Certified Network Associate (CCNA); Fortinet NSE 4 — Network Security Professional (FortiGate); Zscaler Certified Cloud Practitioner (ZCCP) or Zscaler Certified Engineer (ZCE).
Apply:
- Interested candidates can send their resume to Finzly at [email protected]