Junior Systems Administrator
outcomesWest Des Moines (IA)
About the role
Job Summary:
The Jr. Systems Administrator provides second and third-tier technical support and systems administration across Outcomes’ distributed environment, serving as the escalation point for associates and other front-line developers/vendors when issues exceed the scope of desktop-tier support. This role administers core infrastructure; Active Directory, Intune Policy, Windows Server, and Azure/Entra ID identity services, etc., while continuing to resolve complex endpoint, application, and connectivity issues. It plays a supporting role in site-level endpoint lifecycle and associate onboarding/offboarding activities. This position sits at the second tier of the Outcomes IT Skills and Competency Framework, immediately above Desktop Technician; the candidate is expected to build toward Systems Administrator proficiency through the development and certification path defined in this description. Systems Administration and Escalated Support: 45%Serves as the primary escalation point for issues raised by Access One and other front-line support staff that require deeper systems knowledge, Active Directory and Intune Policy troubleshooting, Windows Server role and dependency issues, Azure/Entra ID identity and SSO problems, and complex network connectivity faults. Administers associates and group objects in Active Directory and Entra ID, manages Intune settings, and performs Windows Server administration tasks under the guidance of a Sr./Principal Systems Administrator and/or Director of IT. Documents escalated issues and resolutions and provides backup coverage for site-level as needed. Identity, Access, and Cloud Infrastructure: 25%Administers Entra ID and Active Directory identity objects, group memberships, and access levels in accordance with least-privilege guidance; registers and troubleshoots MFA; and resolves escalated SSO configuration issues. Maintains working familiarity with Outcomes’ AWS, Azure, and Google Cloud footprint, and develops hands-on exposure to Azure IaaS resources (VMs, networking, others) under supervision. Assists the security team with baseline security configuration and compliance review tasks. Endpoint and Device Lifecycle Support: 20%Supports and, where needed, backstops the site-level endpoint lifecycle — imaging and provisioning through Intune and Autopilot, workstation patch management, endpoint security agent (EDR) health and remediation, and hardware repair/warranty/RMA coordination for escalated cases. Maintains the accuracy of asset inventory records for systems under this role’s administration and supports device recovery for associate offboarding at the systems level. Automation, Documentation, and Mentoring: 10%Writes and adapts Power Shell scripts to automate routine administration tasks; documents standard operating procedures and knowledge base articles; mentors Access One on troubleshooting technique and escalation criteria; and contributes to process improvements within the IT Skills and Competency Framework. KNOWLEDGE & REQUIREMENTSProficiency levels below follow the Outcomes IT Skills and Competency Framework. Required = strong working knowledge, performed independently. Intermediate = solid understanding, performs with minimal guidance. Basic = foundational knowledge, developing. Awareness = understands the concepts with limited hands-on exposure. Technical – Endpoint and Device Management Windows and macOS desktop/laptop administration – Required Intune, Autopilot, and imaging software, including MDT and Endpoint Central – Required Hardware diagnostics, component replacement, and warranty/RMA coordination – Required Device inventory accuracy and asset record maintenance – Required Peripheral, printer, and conference-room AV support – Intermediate Technical – Core Systems Active Directory and Intune Policy – Intermediate: creates and modifies user and group objects, manages OU structure, applies and troubleshoots GPO-applied settings Windows Server Administration – Intermediate: manages server roles and routine maintenance under guidance; escalates architectural changes to a Systems Administrator Backup and Disaster Recovery – Basic: performs scheduled backup jobs and assists with restore testing Virtualization – Basic: provisions and manages VMs under supervision Linux/Unix Administration – Awareness Technical – AWS, GCS and Azure Azure Identity, Entra ID – Intermediate: manages users, groups, and conditional access; troubleshoots SSOAzure Infrastructure, IaaS – Basic: provisions and manages VMs, storage, and networking resources under guidance Azure Security and Compliance – Basic: applies baseline security configurations and assists with compliance reviews Working familiarity with AWS and Google Cloud services, which Outcomes’ infrastructure also spans Technical – NetworkingTCP/IP, DNS, and DHCP – IntermediateVPN and Remote Access – Intermediate: configures and troubleshoots client and site-to-site connections Network Monitoring and Troubleshooting – Intermediate: wired and wireless connectivity across sites, patching to the closet Firewalls and Network Security – Basic Switching and Routing – Basic Technical – Security Endpoint Security – Required: EDR (Sentinel 1), remediation of flagged endpoints Patch Management – Required: manages patch schedules across the supported environment, not workstation-level only Security Incident Response – Intermediate: contains and remediates escalated incidents; coordinates directly with the security team Access Control and IAM – Intermediate: applies least privilege, contributes to access reviews; does not independently approve elevated access Ensures security protocols are followed to protect company data Automation and Scripting Power Shell – Intermediate: writes and adapts scripts for administration and automation tasks Bash/Shell Scripting – Basic Python for Automation – Awareness Soft Skills Problem Solving and Troubleshooting – Required: analyzes escalated issues systematically and resolves them effectively Documentation – Required: ticket notes, knowledge base articles, and asset records Communication – Required: explains technical concepts to non-technical associates and coordinates with Systems, Network, and Security teams Time Management and Prioritization – Required: manages an SLA-driven queue independently, including escalated tickets Mentoring and Knowledge Transfer – Basic: mentors Desktop Technicians and front-line support staff Works effectively both independently and within a distributed team; assists other team members with projects and assigned tasks Professional DevelopmentITIL and Service Management – Intermediate Continuous Learning – Required: stays current with technology trends and updates Relevant Certifications – Pursuing: see Education and Experience RequirementsEDUCATION & EXPERIENCE REQUIREMENTSMinimum years of work experience: 3 years Minimum 2 years of desktop or systems support experience, including at least 1 year performing escalated or Jr. Systems Administrator-level work Certifications held at hire (preferred): CompTIA Network+ and AZ-900: Microsoft Azure Fundamentals, or equivalent demonstrated systems administration experience Target certifications: CompTIA Security+ — security baseline, applies to all IT rolesAZ-104: Microsoft Azure AdministratorITIL 4 Foundation — service management Development path toward Systems Administrator: AZ-802: Windows Server Hybrid Administrator — advanced Windows Server administrationCCNA — networking fundamentals for infrastructure roles
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
