IT Support Specialist
We are seeking an IT Support Specialist to join our growing team. This role owns day-to-day IT support, user lifecycle management (onboarding/offboarding), and identity & access management (IAM), with hands-on device management and light compliance support.
You'll be the go-to person for end-user technical issues across a distributed, remote-first team, while also owning the processes that keep access to our systems secure and audit-ready. This is a hands-on role: you'll be provisioning and deprovisioning accounts, managing devices through Intune, and making sure the right people have the right access at the right time.
The ideal candidate has hands-on experience with Microsoft Intune, Google Workspace administration, and IAM/access control, and thrives in a fast-paced, compliance-driven environment (SOC 2, HIPAA). You're comfortable working independently, documenting your work, and balancing reactive support tickets with proactive process improvements.
Schedule: Mon-Fri 8am-5pm ET, and as needed to respond to urgent issues.
Key Responsibilities
IT Support & Operations:
Serve as the primary point of contact for Tier 1-2 technical support requests via ticketing systems (e.g., HappyFox)
Support end users across both Windows and macOS environments, including hardware, OS, and application issues
Troubleshoot connectivity, printing, email, and general software/access issues
Triage and resolve tickets within defined SLAs, escalating complex issues as needed
Maintain clear documentation of common issues, fixes, and internal how-to guides
User Lifecycle Management & IAM:
Own end-to-end onboarding/offboarding: bi-weekly training new hires on company systems, attend onboarding meetings, account provisioning, device setup, and access control for new hires and departing employees
Manage identity and access management (IAM), including periodic user access reviews, role/permission assignment, and timely deprovisioning
Apply least-privilege principles when granting or reviewing access to systems and applications
Support SSO configuration and troubleshoot SaaS application access issues
Maintain accurate records of who has access to what, for audit and compliance purposes
Device, Hardware, and Endpoint Management:
Administer Microsoft Intune (MDM) and O365 for a remote, multi-OS device fleet
Enforce security policies across endpoints, including encryption, patching, and compliance configurations
Support and monitor Microsoft Defender across managed devices
Handle physical logistics for company devices, including shipping/receiving equipment via UPS or other carriers for new hires, offboarding, and repairs
Track device inventory and assist with procurement and lifecycle management of company hardware
Systems Administration:
Manage Google Workspace users, groups, and settings
Maintain and troubleshoot core SaaS tools used across the organization
Automation & Scripting:
Create and maintain scripts (PowerShell, Bash) to automate repetitive IT and access-management tasks
Identify opportunities to streamline onboarding/offboarding and device provisioning workflows
Security & Compliance:
Support SOC 2 and HIPAA controls relevant to IT operations and access management
Assist with audit evidence collection and enforcement of security policies
Work closely with the CISO on access-related audit requests and remediation items
Required Qualifications
2-5+ years of IT support experience supporting a remote or distributed workforce in the healthcare field
1-3+ years experience in startup environment
Experience handling PHI and working in HIPAA-regulated environments
Strong written and verbal communication skills, with the ability to explain technical issues to non-technical staff
Customer service experience with a deep ability to remain patient, empathetic, and reassuring when supporting our team
Hands-on experience with Microsoft Intune
Experience supporting both Windows and macOS environments
Experience with IAM / access management and end-to-end onboarding-offboarding processes
Experience with ticketing systems and managing work within SLAs
Solid understanding of endpoint security fundamentals (encryption, patching, MDM policies)
Scripting experience (PowerShell, Bash) for task automation
Willingness to ship, receive, and temporarily store company equipment (e.g., laptops) at their home as part of device lifecycle logistics
Ability to work independently and manage competing priorities in a remote environment
Must be based in the United States, Eastern Time Zone
Preferred Qualifications
Familiarity with least-privilege access principles
SOC 2 familiarity (nice to have, not required)
Experience with Microsoft Defender, Azure AD
Google Workspace administration experience
Preferred Certifications
Microsoft Endpoint Administrator
Google Workspace Administrator
CompTIA Security+
ITIL Foundation
What Success Looks Like
New hires are fully onboarded and productive on day one, with no access gaps or delays
Offboarding is complete and access is revoked promptly, with no orphaned accounts left behind
IAM access reviews are conducted on schedule, with clean, audit-ready documentation
Tickets are resolved consistently within SLA, with a track record of clear communication back to end users
Endpoints remain compliant, patched, and properly enrolled in Intune
The CISO can rely on this role for accurate, timely access and compliance evidence without having to chase it down
Compensation range for this position is between $60K-$70K. The exact amount will depend on direct, relevant experience.
Our Interview Process
At Nadia Care, we value transparency and want you to feel prepared at every stage of your candidate journey. Below is our standard interview process for this role:
Recruiter Interview | 30 minutes
Hiring Manager Interview | 1 hour