Overview
The IT Support Engineer is responsible for the secure configuration, maintenance, and support oflaptops, mobile devices, networks, and email systemsin aHITRUST-compliantenvironment. This role ensures all corporate endpoints and communications are compliant withHITRUST CSF,SOC 2, andHIPAAsecurity standards, enabling safe handling of protected health information (PHI) across the platform.
Key Responsibilities
Endpoint Management (Laptops & Workstations)
- Configure, deploy, and maintain company laptops (Windows/macOS) usingMicrosoft Intune,Jamf, or equivalent MDM tools.
- Enforcefull-disk encryption (BitLocker/FileVault), password complexity, and auto-lock policies.
- Manage OS and software updates, patching schedules, and EDR (e.g., Microsoft Defender for Endpoint).
- Maintain a completeasset inventorywith encryption, patch, and compliance status.
- Support secure decommissioning anddata sanitizationof retired devices (NIST 800-88 compliant).
Mobile Device & BYOD Management
- Administermobile device management (MDM)for both corporate and BYOD users via Intune or Google Endpoint Management.
- Enforce encryption, PIN/biometric lock, OS update, and remote-wipe policies.
- Ensure onlymanaged, compliant devicescan access corporate email or Google Workspace.
- Train users onmobile security awarenessand BYOD compliance.
Network Administration
- Manage corporate VPN (Azure VPN Gateway / OpenVPN), firewall, and access control configurations.
- EnforceMFA, AES-256 encryption, and loggingfor all VPN users.
- Maintain network segmentation and ensure no split tunneling.
- Collaborate with the Security Officer to monitor and investigate network security events.
- Oversee connectivity between remote offices, developers, and cloud infrastructure.
Microsoft Outlook & Google Workspace Management
- AdministerMicrosoft Outlook (Microsoft 365)orGmail (Google Workspace)accounts under SSO and MFA policies.
- Manage mailbox permissions, shared mailboxes, and group access through Azure AD.
- Implementdata loss prevention (DLP),email encryption, and phishing protection policies.
- Coordinate user onboarding/offboarding for email and collaboration tools.
- Support integration between Outlook and mobile MDM policies.
Security & Compliance Operations
- Ensure all systems comply withHITRUST CSF Control Domains(Access Control, Endpoint Security, Network Security, Logging, and Monitoring).
- Participate ininternal audits, providing evidence of compliance (e.g., asset logs, patch reports, incident tickets).
- Maintain and update IT policies and procedures related to network, endpoint, and remote access.
- Support theincident response plan, including triage of security events related to endpoints or network.
- Conduct quarterlyaccess reviewsfor laptops, VPN, and cloud services.
User Support & Training
- Provide Tier-1/Tier-2 support for hardware, software, VPN, and Outlook/Google Workspace issues.
- Document and resolve support tickets in the IT service management system (e.g., Jira Service Desk).
- Educate employees on secure practices and acceptable use policies.
- Develop quick-reference guides for onboarding and device setup.
Required Qualifications
- Bachelor's degree in Information Technology, Computer Science, or equivalent experience.
- 35 years of IT Support or Systems Administration experience in aregulated or healthcareenvironment.
- Proven experience with: Microsoft Intune, Azure AD, Windows 10/11 and macOS management, Google Workspace or Microsoft 365 administration, VPN and network configuration (IPsec, SSL, DNS, firewall)
- Familiarity withHITRUST CSF,SOC 2, orHIPAAcompliance frameworks.
- Excellent troubleshooting, documentation, and communication skills.
- Ability to work cross-functionally with Compliance, Security, and Engineering teams.
Preferred Qualifications
- CompTIA Security+, Network+, or equivalent certifications.
- Microsoft Certified: Modern Desktop Administrator Associate.
- Experience with SIEM tools (Azure Sentinel, Splunk).
- Knowledge of NIST 800-53 / ISO 27001 standards.
- Experience in a healthcare or SaaS cloud environment (Azure, GCP, AWS).
Key Performance Indicators (KPIs)
- 100% of laptops and mobile devices encrypted and MDM-compliant.
- 0 unapproved devices accessing VPN or email.
- 100% MFA enforcement on all remote access and email systems.
- 100% completion of quarterly access and patch reviews.
- <24-hour SLA for device provisioning and termination access removal.
Reporting Structure
This role reports to theSecurity & Compliance Officer (HITRUST)and collaborates with:
- DevOps / Cloud Teamfor network configurations
- HRfor onboarding/offboarding workflows
- Compliance Officerfor audit readiness and evidence collection
- Support Teamfor ticketing and service delivery metrics