Mac System Administrator
Nsight Health
- Location
- Remote (US)
- Compensation
- $95k - $125k/yr
- Employment
- Full-time
- Level
- Mid Level
About the Role
Nsight Health is transforming healthcare through Remote Patient Monitoring and AI-enabled technology. As a Mac System Administrator, you will own the internal IT platform, ensuring a seamless experience for a fast-growing, fully remote team dedicated to improving patient outcomes.
Skills
Benefits
- Medical Insurance
- Dental Insurance
- Vision Insurance
- 401(k) Plan
- PTO
Perks
- Company-provided Equipment
- Performance-Based Bonus
Full job details
Mac System Administrator
Remote
Employment Type: Full-Time
About Nsight Health
Nsight Health is transforming how care is delivered through Remote Patient Monitoring (RPM), Chronic Care Management (CCM), and Behavioral Health Integration (BHI). We empower healthcare providers to manage chronic conditions using real-time data, AI-enabled technology, and 24/7 clinical support. Our HIPAA-compliant platform connects patients and care teams nationwide—improving outcomes, adherence, and peace of mind. Join a fast-growing, mission-driven team that blends healthcare and technology to make a measurable difference in people’s lives.
Nsight Health — Where Technology Meets Compassion.
Position Summary
At Nsight Health, the Mac Systems Administrator is the engine of internal IT. You will own the macOS endpoint platform, operate the identity provider and Google Workspace day-to-day, and lead the technical project work that keeps a fully remote, fast-growing healthcare technology company running at its best. You will work alongside a managed service partner in a co-managed model where the MSP handles high-volume support and you own the platform they run on.
This is not a help desk role. It is not a ticket-taker role. It is a platform ownership role for someone who writes runbooks, automates repetition, documents everything, and takes genuine pride in building an IT environment that just works. Reporting to the Director of IT, you will be a trusted technical resource for the team, the MSP, and the security organization.
AI Fluency Requirement - Non-Negotiable
Nsight Health is an AI-first organization. Every member of our leadership and operations team is expected to actively use AI tools in their day-to-day work - not as a novelty, but as a core productivity multiplier. This role requires genuine curiosity about AI, comfort experimenting with tools like Claude, ChatGPT, and workflow automation platforms, and the judgment to know when AI helps and when it doesn't. If AI makes you uncomfortable, this is not the right role.
Key Responsibilities
Endpoint Platform Ownership: Own the Iru (formerly Kandji) environment from top to bottom including blueprints, configuration profiles, patch management, vulnerability response, and fleet health. Manage the full macOS lifecycle from imaging and deployment through refresh and retirement. Triage endpoint detection and response alerts in partnership with the CISO and the MSP.
Identity and Access Management: Operate the identity provider (Okta strongly preferred) day-to-day across groups, applications, SCIM provisioning, lifecycle workflows, and MFA policies. Own the platform that makes joiner, mover, and leaver workflows effortless for the business. Maintain access reviews and audit-ready records in partnership with the Security team.
Google Workspace Administration: Administer Google Workspace at depth across users, groups, organizational unit design, DLP rules, security center monitoring, Vault retention, and application access policies. Build and maintain automations using GAM, Apps Script, or equivalent.
Project and Platform Work: Lead technical projects including identity provider rollouts, MDM migrations, integrations, and automation initiatives. Write scripts and tooling in Bash, Python, AppleScript, the Iru API, Okta Workflows, and GAM that reduce ticket volume and make the environment easier to operate for everyone.
Co-Managed Partnership and Escalation: Serve as Tier 3 escalation for the managed service partner, solving what they cannot. Participate in a light on-call rotation for genuine emergencies and work alongside the Director to set clear expectations, provide accurate documentation, and give the MSP the feedback they need to perform.
Documentation and Compliance: Document everything. If it is not in a runbook, it does not exist. Operate inside an active HIPAA, SOC 2, and HiTrust environment and partner with Security and Engineering to support audit evidence and control attestation.
The Impact You’ll Make
Platform Owner: Within your first six months, Iru and the identity provider will be healthy, documented, and instrumented. Runbooks will be written down and not living in anyone's head. The team will know exactly how the environment works because you built it that way.
Employee Experience Driver: Joiner, mover, and leaver workflows will run on rails so that onboarding day one feels effortless to every new hire. The IT experience at Nsight will be something people notice in a good way.
Automation Builder: Ticket volume on routine work will be measurably lower because you automated the repetitive things. The MSP will spend their time on real problems, not process gaps, because you gave them a platform worth running on.
Trusted Technical Resource: Your name will come up when something needs to be done well. The Director, the MSP, and the security team will trust your work because you document it, own it, and stand behind it.
Qualifications
Required:
4 or more years of hands-on systems administration experience with at least 2 years in a macOS-first environment
Strong working knowledge of macOS internals, command line, scripting in Bash and Python, and deep troubleshooting ability
Production experience with an enterprise MDM; Iru (formerly Kandji) is strongly preferred and comparable depth in another MDM is acceptable
Deep Google Workspace administration experience across users, groups, DLP, security center, Vault, OU design, and application access policies; surface-level admin is not enough for this role
Working knowledge of a modern identity provider with Okta strongly preferred; SSO, MFA, SCIM provisioning, and lifecycle workflows should be part of your daily vocabulary
Working knowledge of endpoint detection and response using SentinelOne or equivalent
A genuine documentation habit; we will look for evidence of it in the interview
Preferred:
Direct production experience with Iru (formerly Kandji), Okta Workforce Identity Cloud, and SentinelOne Singularity
Apple certifications such as ACSP or ACMT
Experience in healthcare or another regulated environment
Comfort working in a co-managed model alongside a managed service partner
Compensation & Benefits
Competitive base pay: $95,000 – $125,000 annually.
Additional Compensation:
Performance-Based Bonus: Eligible for an annual bonus based on company and individual performance.
Benefits Include:
Accrual-based PTO
Medical, Dental, Vision, and supplemental insurance options
401(k) Plan with 3.5% Company Match
Company-provided equipment