Senior Systems Administrator
- Full-time
- Quick Apply
Title: Senior Systems Administrator
Location: Hybrid (Chandler, AZ)
Reports to: Infrastructure Manager
Employment Type: Exempt | Full-Time
About StrongMind
StrongMind is a remote-first education and technology company on a mission to transform learning for students, families, and educators across the country. For more than 25 years, we’ve partnered with schools and districts to deliver innovative, student-centered learning experiences powered by technology, compassion, and bold thinking.
We believe education should be flexible, human, and built for real life. That belief shapes how we design our products, support our partners, and work together as a team. At StrongMind, you’ll find smart people doing meaningful work, a culture rooted in trust and accountability, and leaders who genuinely care about both outcomes and people.
You’ll be part of the Data and Technology Operations, team on the SysOps side of the house, working closely with the Service Desk, Engineering and Platform, Security and Compliance, People Success, Facilities, and the schools and organizations we support, including Primavera, Valor Preparatory Academy, American Virtual Academy, and StrongMind Learning Partners Philippines.
Our team supports the technology, systems, infrastructure, and security tools that employees and school staff rely on every day: identity, endpoint, network, telephony, physical security, and email and endpoint security. In this role, you’ll serve as the senior technical seat in IT, owning key platforms outright and helping establish the standards that keep our environment secure, reliable, and efficient.
The team culture is collaborative, solutions-oriented, and focused on continuous improvement. You’ll have opportunities to take ownership of complex technical challenges, mentor teammates, improve systems through automation, and help shape how our technology environment evolves.
The Difference You Will Make
As a Senior Systems Administrator, you’ll be the senior technical problem solver on the SysOps team, reporting to the Infrastructure Manager. You’ll go beyond administering established systems: you’ll design solutions, set technical standards, and take end-to-end ownership of critical platforms rather than installing and configuring to a standard set by someone else.
You own the corporate and school-facing estate. Our production product infrastructure is owned by the Engineering organization, and you’ll be the partner on that boundary, including developer access and the systems that connect the two environments.
You’ll execute routine administration and approved maintenance independently, recommend and implement technical standards within agreed policies, and take authorized containment actions duringsecurity incidents. Changes with significant business impact, spending commitments, or policy implications are escalated, with the risks and options laid out clearly so leadership can make informed decisions.
You’ll also play an important role in our AI-forward organization by using approved AI tools daily to improve automation, documentation, and analysis, while helping the broader team adopt these tools responsibly and effectively.
A Typical Day Looks Like
While no two days are exactly the same, you can expect to:
Identity and access
- Own corporate identity administration end to end across our Microsoft 365 and Google
- Workspace tenants: directory and account architecture, groups, roles, licensing, conditional access, and multifactor enforcement across all supported organizations.
- Design and maintain the access model, including entitlement definitions by role and department, so that provisioning is consistent and repeatable.
- Define and grant the delegated administrative access that lets the Service Desk resolve requests without escalating for a permission, and review that boundary as platforms change.
- Own periodic access reviews and produce the evidence that access was removed when people leave or change roles, and own technical onboarding, role changes, and offboarding in coordination with People Success and managers.
- Support Microsoft-based SSO to AWS and other applications, coordinating application-side permissions with the appropriate system owners.
- This position requires availability to work core business hours of 8:00 AM to 5:00 PM Arizona time, Monday through Friday.
- Must be available to work in person for approximately six weeks each year to support Arizona state testing, including travel to assigned testing locations.
- Valid IVP Clearance Card
Endpoint and device management
- Own endpoint management platforms across Windows, macOS, and ChromeOS, including enrollment, configuration profiles, compliance policy, patch cadence, and application deployment.
- Own the imaging and deployment pipeline and standard builds, and maintain them as operating systems and hardware change.
- Own disk encryption standards and key escrow, including reporting on coverage across the fleet.
- Maintain device and asset inventory, ownership records, configuration standards, and lifecycle plans; provision devices and securely retire, wipe, or reassign equipment.
- Network, telephony, and physical infrastructure
- Administer the corporate network: firewalls, routing, wireless, VLANs, DNS, DHCP, certificates, and remote access.
- Own on-premises server and network hardware where it remains, including the server room, and maintain backup and recovery for the systems in scope.
- Plan and execute infrastructure changes with a written change record, a maintenance window, a rollback path, and communication to the people affected.
- Administer cloud telephony and contact center configuration, and administer physical security and access control systems (badging, cameras, door access) in partnership with Facilities.
Email and endpoint security
- Administer our deployed email security platforms and their Microsoft 365 integrations, maintaining protections against spam, phishing, impersonation, malicious attachments, and unsafe links.
- Operate our endpoint protection / EDR platform, including policy tuning, alert triage, and remediation.
- Review and maintain email authentication (SPF, DKIM, DMARC); investigate delivery issues, quarantine events, false positives, and reported malicious messages; and make, document, and periodically review targeted policy exceptions.
Security monitoring and incident response
- Monitor assigned security alerts across identity, endpoint, email, and network tooling, and ensure each alert source has an owner and an escalation path through our on-call and alerting platform.
- Investigate suspicious sign-ins, compromised accounts, malicious email, endpoint threats, and network intrusion attempts; perform containment and remediation within established incident response procedures.
- Implement and evidence the technical controls the organization commits to, working to the standards set by Security and Compliance; maintain incident records and track corrective actions to completion.
Automation, documentation, and AI
- Automate repeatable administration with scripting (PowerShell, Bash, or Python), favoring durable solutions over one-off fixes.
- Own runbooks, standard operating procedures, and architecture documentation for the platforms in scope and keep them current. Documentation is a deliverable of this role.
- Use company-approved AI tools daily to draft and maintain documentation, generate and refine scripts, analyze logs and request patterns, and accelerate research, verifying output before relying on it, and working within StrongMind’s AI usage policy and governance framework.
Team, vendor, and program work
- Act as the technical escalation point for the Systems Administrator and Service Desk team members; review the work of less experienced technicians and mentor them toward independent ownership.
- Act as a technical contact for IT and security providers; track vendor issues through resolution and evaluate technical recommendations.
- Maintain visibility into licensing, equipment needs, and service renewals, and recommend improvements with an explanation of business value, risk, cost, and effort.
- Support audits and security reviews by providing accurate configuration evidence and remediation status.
- Support seasonal, high-volume work such as device staging for statewide student assessment, device loan programs, graduation and promotion events, and office and site changes.
- Lead department projects such as platform migrations, device refreshes, decommissions, and office build-outs.
- Participate in the SysOps after-hours on-call rotation (see Additional Info).
- This role balances hands-on technical execution, independent problem-solving, collaboration, and technical leadership and is well-suited for someone who enjoys owning complex systems, improving processes, automating repetitive work, and helping others grow.
Your Expertise Includes
We’re looking for someone who brings:
- Five or more years in systems administration or infrastructure engineering, or equivalent demonstrated experience, with at least two years at a senior or lead level.
- Demonstrated end-to-end ownership of at least one significant platform: you designed it, ran it, documented it, and were accountable for it.
- Deep working knowledge of cloud identity and productivity administration, including directory services, groups, roles, licensing, conditional access, and multifactor authentication, across
- Microsoft 365 and Google Workspace.
- Deep working knowledge of endpoint management at enterprise scale across Windows, macOS, and ChromeOS, using platforms such as Microsoft Intune and Jamf, including configuration profiles, compliance policy, patching, and application deployment.
- Strong network administration: firewalls, VLANs, routing, wireless, DNS, DHCP, certificates, and remote access.
- Hands-on administration of enterprise email security and endpoint protection / EDR platforms, including policy tuning, alert triage, and remediation.
- Experience administering an environment serving multiple organizations, entities, or tenants.
- Strong change-management practice: written change records, maintenance windows, rollback plans, and communication.
- Scripting for automation (PowerShell, Bash, or Python) sufficient to replace recurring manual work.
- Ability to create clear architecture documentation, runbooks, and procedures that enable other administrators to operate systems independently.
- Demonstrated practical use of AI tools in a technical work setting, and the judgment to verify output before relying on it.
- Discretion with confidential staff and student information, and handling of student data in accordance with FERPA and company policy.
- Strong troubleshooting, documentation, prioritization, and communication skills.
Equivalent practical experience is valued alongside formal education and certifications.
Bonus points if you also have:
- Direct experience with our deployed platforms or their equivalents: Barracuda, Mimecast, Sophos
- Central MDR, or comparable email security and EDR/MDR products.
- Cloud telephony and contact center administration, such as RingCentral.
- Physical security platform administration, such as badging, camera, and door access systems.
- On-premises virtualization, storage, and backup experience (e.g., VMware, SAN/NAS storage, backup software such as Veeam), including recovery testing and business continuity planning.
- Experience administering multiple Microsoft 365 / Google Workspace tenants with differing licensing tiers.
- Identity platform migration experience, or experience running more than one identity provider.
- Experience integrating Entra ID with AWS IAM Identity Center or AWS SAML federation, and experience partnering with Engineering teams on cloud infrastructure.
- Experience managing asset management systems and hardware lifecycles at scale.
- Experience supporting standardized testing or large-scale seasonal device deployments.
- Experience preparing technical evidence for a security audit or compliance framework.
- Experience supporting a school, district, or education technology environment.
- Experience mentoring technicians or leading technical initiatives without formal authority.
- Relevant certifications such as Microsoft Certified Identity and Access Administrator, Endpoint Administrator, Azure Administrator, Jamf, or networking/security certifications.
- An associate or bachelor’s degree in a technology-related field. Demonstrated capability matters more here than credentials
Our Commitment to Inclusion & Belonging
At StrongMind, we believe the best ideas come from bringing together people with different perspectives, experiences, and ways of thinking. A diverse and inclusive workplace fuels creativity, strengthens collaboration, and helps us build better solutions for the students, families, and communities we serve.
We are committed to welcoming a broad range of talent and encouraging all qualified individuals to apply. We strive to create an environment where everyone feels a sense of belonging and is empowered to contribute, grow, and do meaningful work.
How We’ll Take Care of You
We believe that when people feel supported, they do their best work. At StrongMind, your well-being isn’t a perk—it’s part of our culture.
Our commitment to you includes:
- A competitive total compensation package, including medical, dental, vision, and voluntary benefits
- Well-being that works for real life—from an on-site gym, virtual wellness programs, and wellness coaching to flexible work options for select roles, because your well-being fuels your brilliance
- Unlimited PTO for exempt roles, plus additional “life happens” days when you need flexibility
- A fully paid holiday week off at Christmas, so you can truly rest, reset, and reconnect
- Recognition and rewards that celebrate birthdays, meaningful milestones, legendary work, and community service hours that let you give back
- Quarterly Town Halls that keep communication transparent, honest, and human
- Annual social events and traditions we genuinely look forward to—like Halloween celebrations, Wellness Fairs, and other moments that bring our community together
We’re intentional about building a workplace where people feel valued, connected, and empowered to thrive—at work and beyond.
Additional Info
Work Environment: StrongMind operates as a remote-first organization. This role is Arizona-based with on-site presence required for server room and network infrastructure work, equipment staging, school events, and the annual student assessment window.
After-Hours Work: Infrastructure changes that affect availability are scheduled outside business hours, typically evenings or weekends. Participation in these maintenance windows is part of the role.
Travel: Seasonal in-state travel is required. During the spring assessment window, this role supports school sites across Arizona, including driving to sites, transporting and setting up equipment, and occasional early start times.
Physical Requirements: The role may require lifting and moving computer and network equipment, working in equipment staging areas, and performing rack and cabling work.
Seasonality: Work volume peaks in late summer and early autumn for back-to-school activities and again in spring for student assessment. Comfort with predictable seasonal peaks is important.
We welcome all qualified candidates eligible to work in the United States. At this time, we are unable to sponsor visas.
We are proud to be an Equal Opportunity Employer and provide consideration to all applicants regardless of race, religion, color, sex, gender, national origin, age, veteran status, marital status, or disability protected by law.
PI744fa454a6e0-30511-41649924