Systems Administrator

See's Candy Shops, IncorporatedCarson, CaliforniaOn-siteFull-timeMid level, 2–5 yearsListed 1 hour ago

Apply now

About this role

Work is Sweet!

'Quality without Compromise' is not just a motto at See’s Candies. It is the most important ingredient in our recipe for success. See’s Candies has been in business since 1921 and maintains a reputation for producing the highest quality candy and providing superior customer service.

See’s is a leader in the confectionery industry with over 250 retail shops across the USA, a growing e-commerce business, and expanding opportunities internationally. We are seeking friendly, enthusiastic individuals who are passionate about helping us grow and thrive in our second century.

Job Description Summary:
Position Objective:

Responsible for endpoint security, patch management, and enterprise client administration across an environment of 1,000+ users and Windows endpoints. The position monitors and remediates endpoint security threats and events; ensures computers remain patched, secure, compliant, and protected; and develops and supports systems required for reliable and effective technology operations.

The pay range for this position is expected to be $40.77-$55.96 an hour; however, base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience.

Job Description:

POSITION RESPONSIBILITIES:

Endpoint Security and Threat Management

• Manage and maintain endpoint security solutions, including firewall, antivirus, endpoint protection, disk encryption, multifactor authentication, and related security technologies.

• Monitor, investigate, remediate, document, and report endpoint security threats, vulnerabilities, alerts, and protection-related events in a timely manner.

• Ensure endpoints remain protected and compliant with company security standards and applicable requirements.

Patch Management and Software Deployment

• Review, test, and deploy operating system updates, security patches, software releases, and application revisions in a timely manner.

• Package, test, deploy, update, and maintain Win32, MSI/PKG, driver, and other required software through enterprise endpoint management platforms.

• Ensure Windows endpoints remain fully patched, secure, current, and operational.

Endpoint Management and Microsoft Intune Administration

• Administer Microsoft Intune and other client management platforms used to deploy and maintain applications, drivers, configuration profiles, compliance policies, and remediation scripts.

• Troubleshoot device enrollment across supported operating systems, application detection and updates, device compliance, synchronization, and endpoint management issues.

• Maintain an accurate and current inventory of managed clients, software, and device status within the client management platform.

• Resolve issues within the client management environment and apply platform patches and upgrades to support smooth, efficient operations.

Windows Systems Administration and Imaging

• Administer and support Windows operating systems in an enterprise environment of 1,000+ users and endpoints.

• Prepare, build, test, maintain, and deploy standardized Windows images for each operating environment.

• Provide advanced troubleshooting and technical support for Windows client and endpoint management issues.

Directory Services and Identity Management

• Administer Active Directory and Microsoft Entra ID (Azure AD) in accordance with user provisioning, deprovisioning, security, and Group Policy guidelines.

• Manage user and group access and support identity technologies, including single sign-on and multifactor authentication.

Email and Account Administration

• Administer the enterprise email environment, including provisioning, decommissioning, archiving, and maintaining email user accounts.

• Perform account administration in accordance with organizational access, retention, and security requirements

Network Administration and Monitoring

• Support wired and wireless network administration, including installation, configuration, connectivity, and access control.

• Monitor, investigate, and address network-related alerts and operational issues.

Reporting, Documentation, and Operational Excellence

• Prepare endpoint security, compliance, patching, inventory, and other operational reports as required.

• Develop, document, and maintain procedures for client management activities that align with operational requirements and recognize best practices.

• Drive continuous improvement by identifying and implementing opportunities to enhance technology, innovation, security, service delivery, and departmental effectiveness.

Collaboration and Additional Responsibilities

• Collaborate with IT Support, IT Managers, and other technology teams to improve client management infrastructure, endpoint security, and operational effectiveness.

• Work independently with limited direct supervision while communicating effectively with technical and nontechnical stakeholders.

• Perform other duties and special projects as assigned by management.

• Demonstrate commitment to the company’s core principles and workplace values, including diversity and inclusion

MINIMUM QUALIFICATIONS

• Minimum three years of patch management and software deployment experience using an enterprise-level management platform to patch and deploy software to multiple clients.

• Minimum three years of endpoint security and protection experience using an enterprise-level platform to manage, protect, monitor, alert on, and remediate security vulnerabilities and threats.

• Minimum three years of Windows operating system administration and management experience.

• Minimum three years of Active Directory administration experience, preferably including Microsoft Entra ID (Azure AD), user provisioning, Group Policy, and security.

• Minimum three years of experience using a client management application for endpoint protection and patch-level maintenance in an environment of 1,000+ Windows clients.

• Minimum three years of Microsoft Intune experience, including deployment and maintenance of Win32 applications, MSI/PKG applications, drivers, configuration profiles, compliance policies, and remediation scripts.

• Experience troubleshooting Intune enrollment across supported operating systems, application detection and updates, device compliance, and synchronization issues.

• Experience or expertise with disk encryption, single sign-on, or multifactor authentication.

• Minimum three years of Windows support experience, including preparing, building, and testing Windows images.

• Strong analytical skills with demonstrated problem-solving ability.

• Ability to communicate effectively and collaborate across teams.

• Ability to work independently with limited direct supervision.

• Proven ability to learn new technologies quickly and manage change efficiently, proactively, and positively.

The total compensation package for this position may also include other elements, in addition to a full range of generous medical, financial, and/or other benefits (including 401(k) eligibility and various paid time off benefits, such as vacation, sick time, and parental leave), dependent on the position offered. Details of participation in these benefit plans will be provided if an employee receives an offer of employment. If hired, employee will be in an “at-will position” and the Company reserves the right to modify base salary (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.

See's is an EOE
See’s will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable local, state or federal law (including San Francisco Ordinance #131192 and Los Angeles Municipal Code 189.00).