Skip to content
Skip to content
Sysadmin Jobs
Birch Gold Group

Sr. System Administrator

Birch Gold Group

Location
Remote (Burbank, California)
Compensation
$105k - $135k/yr
Employment
Full-time
Level
Senior Level
Posted 2 days ago

About the Role

Birch Gold Group seeks a Senior System Administrator to own the entire IT environment for a cloud-first financial services company. The role involves leading the help desk team and managing Azure, Microsoft 365, and security operations for a distributed workforce.

Skills

Microsoft Entra ID Azure Administration Microsoft 365 Identity Architecture Endpoint Management Security Tooling Incident Response PowerShell Microsoft Graph ITSM Platform Administration VoIP Administration Zero-trust Access Cloud Infrastructure Team Leadership Mentorship Compliance

Full job details

Sr. System Administrator

Department: Information Technology

Employment Type: Full Time

Location: Remote

Reporting To: Henry Esparza

Compensation: $105,000 - $135,000 / year



Description


You would own IT at Birch Gold Group. Not a slice of it — the function.


We're a cloud-first company in the precious metals and retirement savings industry, supporting a fully distributed workforce and handling sensitive customer financial data. There's no data center, no domain controller, no VMware cluster — everything runs on Microsoft Azure and Microsoft 365, wrapped in a modern security stack.

This role is the senior technical authority for that entire environment, and the leader and mentor of our help desk team. You'll report directly to the CTO.


Be clear-eyed about what this job is: it is broad.
Identity and access, endpoint management across Windows and macOS, security tooling, voice and communications, remote access, service management, the business platforms our sales organization runs on, and developing the people on your team. Some weeks you're deep in conditional access policy. Others you're diagnosing call quality for a sales floor, or teaching a technician to find root cause instead of restarting the service.


We need someone whose experience is genuinely cloud-native — if your depth is on-premises Active Directory, Exchange Server, and virtualization with Azure added recently, this isn't the right match. But we're hiring an operations leader who works in Azure, not a cloud architect. If you want to specialize narrowly in cloud engineering, you'll be frustrated here.



Key Responsibilities


Microsoft Entra ID and identity architecture — conditional access, privileged access, identity governance, phishing-resistant authentication, SSO and automated provisioning across our SaaS portfolio. Exchange Online and SharePoint Online administration. Endpoint management across Windows, macOS, iOS, and Android, including zero-touch provisioning, disk encryption, and patch and vulnerability management.


Security and resilience


Day-to-day operation and tuning of our endpoint, network, email, and zero-trust access security tooling. Alert triage and incident response from detection through documented remediation. Administration of our enterprise backup platform — with verified coverage, documented recovery objectives, and restore tests that actually get run. Data loss prevention, retention, eDiscovery, and support for audit and regulatory data requests.


AI governance and tooling


We're an AI-forward technical team. You'll be expected to use AI-assisted tooling to move faster — writing automation, reading unfamiliar code, and turning manual processes into scripted ones. You'll also own the other side of it: sanctioned tooling, visibility into shadow-AI usage, data protection controls for LLM tools, and the policy for how the rest of the company uses AI safely in a regulated industry.


The cloud platform


Azure administration: RBAC and role design, Azure Policy, Key Vault, monitoring and alerting, network and data security, and cost management. Operational support for the Azure SQL databases, serverless functions, and scheduled workloads our reporting depends on — you keep the platform healthy and the failures visible. Application development stays with the CTO and data team.


Voice and connectivity


VoIP and unified communications administration — user and device provisioning, call routing, number management, E911, and call quality for a sales organization that lives on the phone. Zero-trust remote access: client deployment across Windows and macOS, per-application access policy, connector health, and the connectivity troubleshooting that reaches you as “the internet is slow.”


The service function and the team


Ownership of our ITSM platform and the incident, request, change, and problem management practices that run on it. And — this is a core part of the job, not an add-on — leading and developing our help desk. You'll be the senior technical mentor they currently don't have: setting the standard for how problems get diagnosed, building their skills, and creating a path for them to grow into more senior work. We want someone who genuinely wants to build a team's capability, not just manage a queue.



Skills, Knowledge & Expertise

•    7+ years in IT operations, systems engineering, or cloud infrastructure, including 4+ years in a Microsoft cloud-first environment (Entra ID, Azure, Microsoft 365) and 2+ years leading or managing others. Equivalent demonstrated depth considered in place of exact tenure.

•    You've owned a whole IT environment, not one tower of it. You've been the person accountable when something broke and there was nobody more senior to escalate to.

•    Strong hands-on Microsoft Entra ID and Microsoft 365 administration. Conditional access, app registrations, enterprise SSO, Exchange Online, and SharePoint Online are daily tools, not concepts.

•    Production Azure administration — RBAC, Policy, Key Vault, managed identity, monitoring, and cost management. Certification is welcome; operational experience is required.

•    Endpoint management across Windows and macOS at scale, plus mobile device and application management.

•    Hands-on security tooling ownership — endpoint detection and response, email security, and network or zero-trust access. You've run an incident, not just read about one.

•    Zero-trust access or VPN administration for a remote workforce, and VoIP or unified communications administration.

•    Enterprise backup administration, including a restore test you personally ran.

•    ITSM platform administration — SLA design, workflow automation, asset management. You've configured one, not just worked tickets in it.

•    Strong PowerShell and Microsoft Graph scripting. You automate reflexively.

•    Demonstrated success developing technical staff. You can point to people who are measurably better engineers because they worked for you, and describe how you did it.

•    Security-first instincts and real experience with compliance or audit obligations.

•    Exceptional written communication. In a remote, autonomous role, your documentation is your presence.