System Administrator II
QE Solar Scottsdale, Arizona, United States · $80K–$100K/yr
Services for Renewable Energy · 201-500 employees
Applying here? Try the free cover letter tool — paste this posting and your résumé, no account needed.
About the role
The Systems Administrator II serves as an escalation point for the Service Desk, proactively identifying and resolving platform issues. They are responsible for automating manual tasks, managing identity lifecycles, and leading security incident responses.
What they look for
Requirements
Candidates must have 4+ years of experience in IT systems or security operations, with at least 2 years at Tier 2 or above. Proficiency in Intune, identity provider integrations, and scripting languages like PowerShell is required.
Full description
You'll join QE Solar's Site Reliability Engineering (SRE) team, which runs the corporate technology our office and field employees use every day: laptops, tablets and iPads, identity and sign-in, Microsoft 365, endpoint security and IT asset inventory.
For this team, reliability means four things:
- Devices are compliant and patched.
- Accounts are correct on an employee's first day and removed on their last.
- Security alerts are handled promptly, day or night.
- Every task is written down so someone else can run it.
- This is a systems and security operations role. It is not a cloud, Kubernetes or software engineering role.
The role:
- The Systems Administrator II is the escalation point behind our Service Desk:
- You go looking for problems and fix them before anyone reports them.
- You own platforms end to end.
- You resolve what Tier 1 cannot, and fix the cause, not only the ticket.
- You automate the manual work you find, in code others can run.
- You bring the team up with you: you teach what you know and help teammates get certified on the platforms they work on.
- Everything we run should live in a standard operating procedure (SOP). Team members certify on each SOP by running it with a teammate observing, so knowledge is shared and anyone can cover.
Our environment:
Endpoints: Windows laptops and tablets in Microsoft Intune with Autopilot; iPads in JAMF; patching through Intune update rings, manufacturer update tools and a remote monitoring and management (RMM) platform
- Identity: Okta (single sign-on for Microsoft 365, Device Access, Lifecycle Management) and Microsoft Entra ID
- Microsoft 365: Exchange Online, Defender for Office 365, SharePoint, Teams
Security: managed detection and response (MDR) with SIEM, privilege elevation, DNS filtering, and security awareness training
Service management: Jira Service Management with Assets as the inventory of record, Confluence for SOPs, PagerDuty for on-call
Network: firewalls and switching, owned by network engineering, but you are willing to step in to support when needed.
What you'll own:
- Finding problems first. Don't wait for tickets. Look through the systems you own for issues before they become tickets. Fix them, or bring a fix with its cost.
- Platform lead. Serve as lead for platforms we run. Own the design, configuration baselines, change records, SOPs and health metrics, and help teammates get certified on them. Support patch management across all of our environments, including restricted ones once authorized and trained.
- Design and build. Design and build Intune compliance and configuration baselines, Autopilot profiles, update rings and Conditional Access policies, plus Okta app integrations with SCIM provisioning and group rules.
- Incidents. Lead P1 and security incidents through containment, keep your lead informed, and write up the root cause and fix.
- Security alerts. Triage MDR, SIEM and phishing alerts. Contain threats to accounts and devices. Take your turn in the weekly after-hours on-call rotation.
- Automation. Write PowerShell and Microsoft Graph automation that runs in production on a schedule. Build it so others can run and maintain it, and document it so others understand it.
- Projects. Deliver projects end to end through change control, each with a plan, a change record and a tested rollback. Examples: platform migrations and onboarding acquired companies' users, devices and tenants. Work across the company with HR, finance, field operations, and our network, OT and product teams to plan the work, support their needs and land changes with the people they affect.
- Identity lifecycle. Automate joiner, mover and leaver changes across Okta and Entra, including license assignment by role and access reviews.
- Inventory. Keep our asset inventory accurate, and automate the reconciliation wherever you can.
- Escalations and coaching. Take Tier 2 tickets through to root cause. Turn repeat issues into SOP changes, and coach Service Desk staff and junior administrators to run them.
Your first 90 days:
- Day 30, learn and baseline: certified on the core SOPs; working the Tier 2 queue; shadowing on-call; your lead platforms assigned, with a health baseline for each.
- Day 60, deliver: primary on-call; one design change delivered on one of your platforms through change control; one PowerShell or Microsoft Graph automation running in production; patch ownership mapped across Intune, manufacturer tools and the RMM, with one source of truth for patch compliance; at least one problem found and fixed that no one had reported.
- Day 90, own and lead: led a tabletop exercise as incident lead; the full SOP set for your platforms current, with at least one teammate certified on it; a six-month roadmap for your platforms approved by the IT Operations Manager.
Required Experience:
- 4+ years in IT systems or security operations, including 2+ years at Tier 2 or above, in an environment of several hundred users or more
- A record of finding and fixing problems no one had reported, with specific examples and results
- A record of raising the people around you: teammates you trained or mentored into new skills and certifications, and knowledge you shared rather than kept
- Designed and built Intune compliance and configuration baselines, Autopilot enrollment and Conditional Access in a production tenant
- Built identity-provider integrations (Okta preferred): SAML or OIDC apps, SCIM provisioning, group rules and lifecycle automation
- Incident lead on at least one security incident, from detection through containment and post-incident review
- PowerShell (or an equivalent scripting language) automation running in production, using Microsoft Graph and vendor APIs, that you built and maintain, with scheduling, logging and error handling
- At least one infrastructure project delivered end to end through change control, such as an MDM, EDR or tenant migration
- SOPs you wrote that others run, and change records with tested rollback plans
- Available for the weekly after-hours on-call rotation
- Live within commuting distance of Scottsdale, AZ, or relocate before your start date. This role is on-site.
Preferred Experience:
- Microsoft MD-102 or SC-300, or CompTIA CySA+. We value certifications as a signal, but we hire and certify on demonstrated skill.
- Okta Workflows or Lifecycle Management; JAMF; an RMM platform
- Jira Service Management Assets or another CMDB
- Support for a distributed field workforce on tablets and mobile devices
Education:
Bachelor's degree in an IT or security field, or equivalent experience
Other requirements:
Authorized to work in the United States
ADA / Physical Demands
QE Solar is committed to providing equal employment opportunities and reasonable accommodations in accordance with the Americans with Disabilities Act (ADA) and applicable state and local laws. The physical and mental demands described below are representative of those required to successfully perform the essential functions of this position. Reasonable accommodations may be made to enable qualified individuals with disabilities to perform these essential functions.
This is an in office position and requires:
- Prolonged periods of sitting while working at a computer workstation.
- Frequent use of hands and fingers to operate a computer, keyboard, mouse, telephone, and other standard office equipment.
- Ability to view multiple monitors and analyze data for extended periods.
- Effective verbal and written communication skills, including participation in virtual meetings and technical discussions.
- Occasional travel for meetings, training, audits, or company events, as business needs require.
- Ability to lift and carry up to 15 pounds, as needed.
Statement to Third-Party Agencies
QE Solar accepts resumes only from contracted recruiting agencies with formal service agreements. Please do not send unsolicited resumes or outreach emails to QE Solar employees, hiring managers, or team members without expressed consent or contract for services. QE Solar is not responsible for any fees or charges associated with unsolicited resumes or services.
Similar roles
-
Cleared Information System Administrator in Camden, AR
Virtual Service Operations Camden, Arkansas, United States · $110K–$120K/yr
-
System Administrator
ASEC Fallon Station, Nevada, United States
-
System Administrator
AAR Corp Wood Dale, Illinois, United States · $90K–$120K/yr
-
System Administrator
MANTECH Nellis AFB, Nevada, United States · $77K–$129K/yr
-
Linux System Administrator (Top Secret SCI)
Intrepid Solutions and Services, LLC Bath Township, Ohio, United States · $100K–$120K/yr
-
Senior System Administrator
Akira Technologies Inc. Aberdeen Proving Ground, Maryland, United States · $120K–$145K/yr