Systems Administrator

Location
Conshohocken
Workplace
Hybrid

About this role

Suveto is a dynamic and growing veterinary organization dedicated to supporting our hospitals and teams with innovative strategies.

We are seeking an experienced and skilled Systems Administrator to join our growing IT team. The Systems Administrator owns the day-to-day administration, engineering, and automation of the Company's Microsoft platform estate — Windows Server, Microsoft Azure infrastructure and platform services, Microsoft 365, Microsoft Entra ID, and Microsoft Intune. This is a hands-on senior individual contributor role for someone who has already run production Microsoft workloads and is ready to own systems end to end rather than execute tickets.

Working independently with general supervision, the Systems Administrator designs and implements system changes, builds automation in PowerShell and infrastructure as code, administers identity and endpoint management, maintains monitoring and alerting through Azure Monitor, and supports the security and compliance posture of the estate through Microsoft Defender and Microsoft Purview. The role is expected to reduce manual operational work over time — the measure of success is not how many tasks are completed but how many stop needing to be done by hand.

This is a hybrid position, must be a commutable distance to our office in Conshohocken, PA.

PLATFORM SCOPE

The Company's environment is Microsoft-centric across both Azure infrastructure and Microsoft 365. The named platforms below define the working scope of this role.

Identity & Access

  • Microsoft Entra ID (formerly Azure Active Directory) — users, groups, enterprise applications, app registrations, Conditional Access, Multi-Factor Authentication
  • Microsoft Entra ID Governance and Privileged Identity Management (PIM) — access reviews, just-in-time role elevation
  • Microsoft Entra Connect and Microsoft Entra Cloud Sync — hybrid directory synchronization
  • Microsoft Entra ID Protection — risk-based sign-in and user risk policies
  • Windows Server Active Directory Domain Services (AD DS), Group Policy, AD FS where still in use

Azure Infrastructure & Platform (IaaS/PaaS)

  • Azure Virtual Machines, Azure Virtual Network, Network Security Groups, Azure Bastion, Azure Load Balancer, Azure Firewall
  • Azure Storage, Azure Files and Azure File Sync, Azure Blob Storage
  • Azure App Service, Azure Functions, Azure Key Vault
  • Azure Backup, Azure Site Recovery, Azure Update Manager
  • Azure Arc — extending Azure management to on-premises and non-Azure servers
  • Azure Local (formerly Azure Stack HCI) and Azure Virtual Desktop where deployed
  • Azure Policy, Azure Resource Manager, management groups and subscription governance

Microsoft 365 & Endpoint

  • Exchange Online, SharePoint Online, Microsoft Teams, OneDrive for Business
  • Microsoft 365 Apps for enterprise; Microsoft 365 admin center
  • Microsoft Intune — compliance policies, configuration profiles, Windows Autopilot, application deployment, Endpoint Privilege Management
  • Windows 11 Enterprise servicing and update rings

Security, Compliance & Monitoring

  • Microsoft Defender XDR — Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps, Defender for Cloud
  • Microsoft Defender Vulnerability Management; Microsoft Security Exposure Management
  • Microsoft Purview — data loss prevention, retention, sensitivity labels, audit, eDiscovery
  • Microsoft Sentinel (formerly Azure Sentinel) — SIEM analytics rules and incident triage
  • Azure Monitor, Log Analytics workspaces, Kusto Query Language (KQL), Workbooks, Azure Monitor Agent, Application Insights

Automation & Tooling

  • PowerShell 7, Microsoft Graph PowerShell SDK, Exchange Online PowerShell (note: Azure AD PowerShell and MSOnline are deprecated — Graph is the forward path)
  • Infrastructure as code — Bicep, ARM templates, or Terraform
  • Azure Automation runbooks, Azure Logic Apps, Windows Task Scheduler for legacy on-premises jobs
  • Git and Azure DevOps or GitHub — source control, pull requests, pipelines
  • Windows Admin Center, Azure Migrate

RESPONSIBILITIES

· Azure Infrastructure & Platform Engineering

· Identity & Access Administration

· Microsoft 365 & Endpoint Management

· Automation & Infrastructure as Code

· Monitoring, Alerting & Operational Health

· Security & Compliance

· Documentation & Mentorship

COMPETENCIES & QUALIFICATIONS

Essential

  • Four (4) year bachelor's degree in related area
  • Three (3) to five (5) years of relevant experience administering Microsoft Windows Server and Microsoft cloud platforms with growing responsibilities.
  • Hands-on production experience with Microsoft Azure IaaS and PaaS — Virtual Machines, Virtual Network, Storage and Azure Files, App Service, Key Vault, Backup, and Site Recovery.
  • Hands-on production experience administering Microsoft Entra ID, including Conditional Access, MFA, enterprise applications, and hybrid identity via Microsoft Entra Connect or Entra Cloud Sync.
  • Hands-on production experience administering Microsoft 365 — Exchange Online, SharePoint Online, Teams, and OneDrive — and managing endpoints through Microsoft Intune.
  • Strong Windows Server administration, including Active Directory Domain Services, Group Policy, DNS, DHCP, certificate services, and IIS.
  • Proficiency in PowerShell, including the Microsoft Graph PowerShell SDK, sufficient to automate multi-step administrative processes unsupervised.
  • Working knowledge of infrastructure as code (Bicep, ARM templates, or Terraform) and source control in Git.
  • Working knowledge of Azure Monitor and Log Analytics, including writing KQL queries.
  • Working knowledge of Microsoft Defender XDR and Microsoft Purview in an operational capacity.
  • Solid networking fundamentals — IP addressing, DNS, DHCP, routing, firewalls, VPN, and hybrid connectivity troubleshooting.
  • Excellent verbal and written communication skills, and the ability to discuss technical issues with non-technical audiences.
  • Demonstrated ability to work independently, own systems end to end, and exercise judgment about what requires escalation or change control.
  • Professional judgment when working with sensitive systems, sensitive data, and production infrastructure.

Core Competencies

  • Customer Focus
  • Interpersonal Savvy
  • Communicates Effectively
  • Decision Quality
  • Being Resilient

BENEFITS

Our employment package for full-time employees includes unlimited PTO/vacation, paid holidays, medical, dental and vision insurance, pet care discounts, 401K with a true match up to 4%. In addition, all full-time hospital team members receive VSOP® grants, SUVETO’S VETERINARY STOCK OWNERSHIP PLAN, at no cost to team members. VSOP® is an ownership program that tracks the value of the entire Suveto organization.

Suveto is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?

Top Benefits

  • Unlimited PTO
  • Paid holidays
  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Pet care discounts
  • 401k
  • VSOP veterinary stock ownership plan