About Us
Company is a US-based, venture-backed Digital Health company transforming virtual healthcare delivery. Our integrated Hardware, Cloud, and AI-powered Virtual Care platforms help healthcare providers unlock proactive and continuous care opportunities while generating recurring revenue streams. With customers across multiple US states and rapid growth momentum, We offer an opportunity to work on cutting-edge product technologies in a fast-paced and innovation-driven environment.
We are seeking a hands-on IT & Cloud Systems Administrator to own our identity, device, endpoint, and productivity stack end-to-end, while acting as a key contributor to our cloud infrastructure operations. In this role, you will administer Microsoft 365 and Entra ID, manage Windows and macOS endpoints across a distributed global workforce, support Azure Remote Desktop and AWS environments, enforce security controls, and provide support across multiple time zones.
This is a generalist role with high ownership and high visibility. You will not be just a ticket resolver—you will be the individual designing onboarding workflows, enforcing zero-trust access controls, automating routine management tasks, and presenting evidence to security auditors.
Administer Microsoft Entra ID : manage user accounts, administrative roles, dynamic groups, and group-based licensing.
Configure and maintain Conditional Access policies, Multi-Factor Authentication (MFA), and Self-Service Password Reset (SSPR).
Own Single Sign-On (SSO) integrations for our SaaS ecosystem using SAML/OIDC app registrations and SCIM provisioning (including AWS IAM Identity Center federation).
Manage the complete Joiner–Mover–Leaver (JML) lifecycle with zero-day automated provisioning, role updates, and immediate access revocation on offboarding.
Perform periodic access reviews and enforce strict least-privilege principles across all administrative roles.
Administer Exchange Online (mail flow rules, connectors, shared mailboxes), SharePoint Online , OneDrive , and Microsoft Teams .
Maintain email authentication records ( SPF, DKIM, DMARC ) to optimize deliverability and mitigate domain spoofing/phishing risks.
Configure SharePoint/Teams permissions, external sharing rules, and sensitive content labels via Microsoft Purview .
Operate Microsoft Defender for Office 365 and Defender for Endpoint : triage quarantine items, respond to phishing reports, and tune Safe Links/Attachments policies.
Monitor license utilization, perform right-sizing audits, and optimize SaaS cost structures.
AWS: Administer IAM, IAM Identity Center, EC2, VPCs, Security Groups, S3 bucket policies, Route 53, CloudWatch, and AWS Secrets Manager.
Azure: Oversee Azure subscriptions, resource groups, RBAC permissions, virtual machines (VMs), NSGs, and Azure Backup routines.
Build, isolate, and tear down secure cloud environments for internal systems and customer projects.
Track cloud infrastructure expenditure, identify unattached or idle resources, and optimize monthly operational costs.
Administer Windows Server environments operating as remote virtual workstations for clinical and operational teams.
Manage remote desktop technologies at scale ( Remote Desktop Services / RDS or Azure Virtual Desktop / AVD with FSLogix profile containers).
Secure remote access by design: enforce zero public RDP exposure using Azure Bastion or Just-In-Time (JIT) access policies.
Apply PHI-compliant session controls: idle timeouts, clipboard/printer redirection policies, drive restrictions, and detailed log auditing.
Manage hardware procurement, imaging, enrollment, and offboarding for Windows and macOS devices.
Enforce device compliance rules via Microsoft Intune or modern MDM tooling (full-disk encryption with BitLocker/FileVault, patch policies, firewall enforcement, and screen locks).
Maintain a real-time, audit-ready global hardware asset inventory.
Automate manual system administration tasks using PowerShell (including Microsoft Graph API), Bash , or Python .
Deliver Tier 1/2 technical support across hardware, VPN, VoIP platforms, EMR software, and core internal SaaS tools.
Maintain complete runbooks, system architecture diagrams, credential stores, and compliance audit evidence.
Days 1–30: Take ownership of the internal helpdesk queue, map out the current identity and SaaS landscape, and document existing onboarding/offboarding workflows.
Days 31–60: Deploy a standardized, automated Joiner–Mover–Leaver runbook, and execute an initial access review of all privileged Entra ID and AWS roles.
Days 61–90: remediate high-priority device compliance and Conditional Access gaps, producing an audit-ready asset, license, and third-party access register.
Experience: Up to 10 years in IT administration, systems engineering, or cloud operations—ideally in an SMB, startup, or high-growth environment where you managed a broad technical stack.
M365 & Entra ID: Advanced, hands-on administrative skills across Entra ID (Conditional Access, MFA, SCIM, SSO) and M365 core services (Exchange, Teams, SharePoint).
Cloud Operations: Practical experience administering RBAC, compute, storage, networking, and security policy in AWS or Microsoft Azure .
Windows & Remote Desktop: Proven experience configuring and securing Windows Server, RDS, or AVD session hosts without exposing public ports.
Endpoint Management: Hands-on experience administering both Windows and macOS environments using an enterprise MDM (e.g., Microsoft Intune).
Automation: Proficiency in scripting ( PowerShell , Bash , or Python ) to eliminate manual administrative workflows.
Compliance Instincts: Practical experience working in a regulated domain (HIPAA, SOC 2, HITRUST, or ISO 27001), prioritizing least-privilege security and detailed audit logs.
Communication & Hours: Excellent written and spoken English skills, with the flexibility to work US-aligned operating hours alongside a distributed global team.
Background in Healthcare IT or digital health technologies handling PHI.
Cross-cloud expertise in both AWS and Microsoft Azure.
Hands-on experience with Azure Virtual Desktop (AVD), FSLogix, Azure Bastion, or Microsoft Defender for Cloud.
Familiarity with Infrastructure-as-Code (IaC) tools such as Terraform , CloudFormation , or Bicep .
Experience with Microsoft Purview, eDiscovery, and automated DLP policy creation.
Relevant industry certifications: MS-102 , SC-300 , AZ-104 , AWS SysOps Administrator , or CompTIA Security+ .
Employment Type: Full-time
Location: Hybrid (Bengaluru, India) / US-Aligned Hours
Industry: Digital Health / Cloud Operations / Information Security