IT MANAGER/SENIOR SYSTEMS ADMINISTRATOR
3Core Systems , IncRole: IT MANAGER/SENIOR SYSTEMS ADMINISTRATOR
Location: New York City, NY or Old Greenwich, CT (5
Days a Week Onsite)
Duration: Fulltime
Core
responsibilities
· Identity and access
governance: Lead the administration of Active
Directory architecture, group design, and the service-account estate: service
principal names, Entra ID application registrations, Graph API access, and
credential rotation through our password vault. Maintain existing access standards,
run periodic access and service-account reviews, and evaluate and process
access exceptions in accordance with established approval procedures.
· File and storage
services: administer the Windows and Samba
file-server estate across headquarters, the offsite datacenter, and remote
offices; manage capacity, quotas, and monitoring; plan and execute server and
share migrations; oversee archiving, backup, and data-governance tooling.
· Email and
collaboration platforms: administer Microsoft 365 and
Exchange Online, including mail routing, mail security and filtering, DLP,
retention and journaling, and the Teams, SharePoint, and OneDrive estate.
· Server and
virtualization infrastructure: build,
patch, and maintain the Windows Server estate on VMware vSphere; hands-on work
with physical server hardware including racking, cabling, diagnostics, and
component replacement.
· Network and
perimeter: Administer and troubleshoot TCP/IP, DNS,
DHCP, VLANs, wireless networks, certificates, and infrastructure-monitoring
platforms. Configure, monitor, and manage firewalls to enforce access controls
and protect the corporate network against unauthorized access and cyber
threats. Manage telecom and ISP vendor relationships.
· Security operations: administer endpoint protection,
data-governance, and email-security platforms; manage multi-factor
authentication, conditional access, and geographic access restrictions; run the
security-awareness and phishing-simulation program; respond to alerts and vulnerabilities.
· eDiscovery and
legal hold: perform mailbox and file searches in
support of subpoenas, regulatory requests, and litigation; preserve, collect,
and produce data under the direction of counsel and Compliance, handling all of
it with strict confidentiality.
· Telephony and voice
services: support the current Avaya PBX, associated
analog lines, and voice-service vendors; troubleshoot and coordinate resolution
of telephony incidents, provisioning, and office moves. Assist with the planned
transition of PBX operations to an outsourced provider and oversee the vendor
relationship thereafter.
· Automation: use PowerShell and Python to automate provisioning, reporting, and
task scheduling, and maintain our enterprise job scheduling platform.
· License, subscription,
and vendor governance: Oversee software
and cloud-service entitlements, licensing, renewals, procurement, and vendor
relationships. Review user licensing and assignments across platforms such as
Adobe, Box, Microsoft 365/Intune, Visual Studio, Verizon, Bloomberg, and
similar services. Recommend and implement subscription changes that
appropriately align user access, device-management, security, operational
needs, and vendor-licensing requirements.
· Project and vendor
coordination: Own the technical delivery of internal
and vendor-led infrastructure and security projects from requirements
gathering, scoping, resource planning, testing, and implementation through
acceptance and documentation. Define and maintain project plans, timelines,
dependencies, risks, action items, and internal and vendor resource needs;
track progress, escalate issues, and coordinate stakeholders through
completion.
· Change management
and IT control reviews: Maintain accurate
records of material infrastructure, configuration, and access changes across
on-premises systems, AWS, and managed-service-provider environments. Perform
monthly reviews of Active Directory group membership, workstation
configuration, local administrator access, server assignments, and system usage
and monitoring; investigate and remediate discrepancies; and document findings,
approvals, exceptions, and follow-up actions.
· IT security
oversight and policy compliance: Maintain
operational controls that support IT policies, client and regulatory
due-diligence questionnaires (DDQs), and external security representations.
Ensure documented policies, DDQ responses, and day-to-day practices remain
aligned. Monitor and validate controls for password and credential rotation,
service accounts, least-privilege access, patching and reboot compliance, and
the documentation, approval, and periodic review of exceptions.
· Technical
leadership and escalation: Route and
prioritize support tickets, help coordinate support coverage and issue
resolution, and serve as the technical escalation point for IT support staff.
Mentor junior team members and promote clear documentation, consistent
operational practices, and timely risk escalation.
· Facilities and
critical-environment infrastructure: monitor and
coordinate the power, cooling, and environmental systems supporting office
technology rooms and server rooms, including UPS units, PDUs, circuits,
temperature/humidity monitoring, and HVAC. Coordinate with building management,
datacenter providers, electricians, and HVAC vendors during incidents,
maintenance, capacity changes, and planned shutdowns.
Skills
and qualifications
- In-depth knowledge of Microsoft
Windows Server, Active Directory, Microsoft 365, MS Teams, and
Multi-Factor Authentication.
- Hands-on experience administering
non-human identity: service accounts, service principal names, Entra ID
app registrations, and credential lifecycle management.
- Experience with VMware vSphere
virtualization.
- Strong experience administering
Windows file servers and network storage at scale - permissions, quotas,
capacity monitoring, and migrations.
- Strong understanding of email flow
and mail security, including routing, spam, malware, and DLP; hands-on
experience with a secure email gateway (Proofpoint, Mimecast, or similar).
- Strong understanding of networking
concepts and protocols (TCP/IP, DNS, DHCP, VLANs, etc.), coupled with
experience in configuring, monitoring, and managing firewalls to secure
the corporate network, and enforce access controls.
- Experience with endpoint protection
and data-governance platforms (CrowdStrike, Varonis, or similar).
- Proficiency with PowerShell for
infrastructure automation, reporting, and administration.
- Hands-on experience with physical
server hardware, including racking, structured cabling, hardware
diagnostics, and component replacement (disks, memory, power supplies,
etc.).
- Working knowledge of the power and
environmental requirements of server rooms and network closets, including
UPS systems, rack PDUs, electrical capacity, cooling, temperature/humidity
monitoring, and escalation to facilities, datacenter, and building
vendors.
- Proven experience as a Systems
Administrator or similar role, with 7+ years managing enterprise IT
infrastructure in a hands-on environment.
- Experience supporting DR,
backup/restore testing, infrastructure monitoring, change control, and
documented operational procedures.
- Experience operating and evidencing
IT controls in a regulated or audited environment, including access
reviews, change management, exception management, and policy compliance.
- Demonstrated experience with
software and cloud-license governance, entitlement reviews, vendor
renewals, and cost-conscious subscription management.
- Proven ability to lead technical
projects and coordinate internal stakeholders, managed service providers,
and other vendors from scope through implementation.
- Strong organizational skills, with
the judgment to identify control gaps, document risks, drive remediation,
and communicate status clearly to technical and non-technical
stakeholders.
Preferred
qualifications
- Bachelor's degree in Computer
Science, Information Technology, or related field (or equivalent
experience).
- Experience in financial services or
another regulated, audited environment.
- Exposure to eDiscovery, legal hold,
or regulatory production processes.
- Experience with cloud computing
platforms such as AWS or Azure is a plus.
- Experience with configuration
management tooling (Ansible, PowerShell DSC, or similar) is beneficial.
- Familiarity with market data
platforms, particularly Bloomberg administration and entitlements.
- Familiarity with Avaya PBX
administration, analog/POTS lines, and telecom vendor coordination.
What
we’re looking for
- Excellent problem-solving skills and
attention to detail.
- Strong communication and
interpersonal skills, including the ability to explain technical issues to
non-technical stakeholders.
- Discretion and sound judgment when
handling confidential company, employee, and legal data.
- A practical, service-oriented approach;
able to balance competing priorities, document work clearly, and escalate
risks appropriately.
- Comfortable serving as a technical
escalation point and mentoring junior IT staff.
Working
arrangements
- On-site only — this is not a remote
or hybrid role.
- Occasional scheduled after-hours
work for patching windows and recovery testing.
- Ability to move and install IT
equipment and work in server rooms, wiring closets, and office locations
as needed.
- If located in NYC, must have ability
to travel to CT or our DR site in Westchester as needed.