Skip to main content

Systems Administrator II – Microsoft Cloud & Endpoint Administration

About FPPA

The Fire & Police Pension Association was created by legislative mandate in the 1980s. Our leadership team guides us in fulfilling our mission, vision and values while achieving our strategic objectives. We administer a statewide multiple employer public employee retirement system providing defined benefit plan coverage as well as death & disability coverage for police officers and firefighters throughout the State of Colorado.

We are a small association of only 70 staff located in Denver, CO. We work hard and have a culture that supports staff to establish a well‐balanced relationship between their personal needs and work commitments.

Position Summary

The Fire & Police Pension Association of Colorado (FPPA) is seeking an experienced Systems Administrator II to administer, support, and continuously improve the organization’s Microsoft cloud, endpoint, identity, and productivity platforms. This hands-on role helps ensure reliable, secure, available, and effective enterprise technology services.

The position provides advanced technical expertise across Microsoft Intune, Microsoft Entra ID, Microsoft 365, Azure services, enterprise file services, patch management, backup and recovery, and infrastructure automation. It also leads assigned technology projects, resolves complex issues, establishes sustainable support practices, and collaborates with IT staff, business stakeholders, vendors, consultants, and Microsoft partners.

Key Responsibilities


Endpoint Management & Identity

  • Administer Microsoft Intune for device enrollment, configuration, compliance, application deployment, updates, and lifecycle management.
  • Administer Microsoft Entra joined and hybrid device environments, Windows Autopilot, Windows Hello for Business, and enterprise Windows endpoints.
  • Maintain endpoint configuration standards, device profiles, compliance policies, security baselines, and accurate inventories and procedures.
  • Administer Microsoft Entra ID accounts, groups, device identities, enterprise applications, administrative roles, multifactor authentication, Conditional Access, and role-based access controls.
  • Support identity lifecycle processes and troubleshoot complex enrollment, authentication, synchronization, access, application, policy, and device issues.
  • Coordinate identity and endpoint requirements with cybersecurity, information governance, human resources, and business stakeholders.

Microsoft Azure, File Services & Microsoft 365

  • Administer assigned Azure services, including virtual machines, storage, Azure Files, networking, monitoring, backup, recovery, and related cloud resources.
  • Monitor availability, capacity, performance, resource utilization, and service health and troubleshoot infrastructure incidents with internal and external partners.
  • Configure Azure resources and enterprise file services in accordance with approved architecture, cybersecurity, governance, access, retention, and operational standards.
  • Administer assigned Microsoft 365 services, including Exchange, Teams, SharePoint Online, OneDrive, Intune, Entra ID, licensing, groups, tenant settings, and service integrations.
  • Support hybrid integrations and contribute to cloud optimization, resiliency, modernization, and continuous improvement initiatives.
  • Maintain technical documentation for resources, configurations, dependencies, ownership, permissions, and operating procedures.

Patching, Automation, Backup & Recovery

  • Administer and optimize enterprise patch management and software update processes across supported endpoint and infrastructure platforms.
  • Manage Windows Update for Business, Intune update policies, maintenance schedules, deployment status, exceptions, testing, failed deployments, and remediation activities.
  • Develop and maintain PowerShell scripts and other approved automation to improve consistency, reliability, reporting, and administrative efficiency.
  • Administer Azure Backup, Recovery Services vaults, backup policies, schedules, retention settings, alerts, monitoring, and recovery documentation.
  • Monitor backup operations, investigate failures and capacity concerns, and perform and document routine restoration testing.
  • Support disaster recovery planning, exercises, technical recovery activities, and continuous improvement of recovery capabilities. PAS Data Readiness & Migration

Operations, Projects & Collaboration

  • Monitor assigned services and provide advanced troubleshooting, root-cause analysis, and escalation support for infrastructure, endpoint, identity, and Microsoft 365 incidents.
  • Lead and participate in endpoint, identity, cloud, file services, backup, patching, automation, and Microsoft 365 projects.
  • Develop technical requirements, test plans, implementation and rollback procedures, project documentation, and sustainable operational support models.
  • Evaluate Microsoft technologies and recommend improvements that enhance security, reliability, efficiency, supportability, and user experience.
  • Follow change, incident, problem, configuration, and asset-management processes and coordinate work with business units, vendors, consultants, and technology partners.
  • Partner with cybersecurity staff to implement assigned technical controls, support vulnerability remediation and authorized reviews, and escalate material risks or suspected incidents.
  • Participate in approved after-hours maintenance or support activities and mentor service desk personnel through technical guidance and knowledge sharing.

Qualification Summary

Education & Experience

  • Bachelor’s degree in Computer Science or a related field preferred. An equivalent combination of education, certifications, and relevant experience may be considered.
  • Five or more years of progressively responsible experience administering Microsoft enterprise technology environments.
  • Hands-on production experience with Microsoft Intune, Microsoft Entra ID, enterprise Windows endpoints, Microsoft 365, and Microsoft Azure services.
  • Experience with endpoint configuration, enterprise patch management, backup and restoration, PowerShell automation, and complex technical troubleshooting.
  • Experience leading or participating in infrastructure implementations, service improvements, migrations, or technology projects.
  • Strong understanding of systems administration, identity and access management, documentation, change control, cybersecurity collaboration, and operational support practices.

Technical Qualifications

  • Microsoft Intune, Windows Autopilot, Windows 10/11, Entra joined and hybrid device management, Windows Hello for Business, Windows Update for Business, endpoint compliance, application deployment, and device lifecycle management.
  • Microsoft Entra ID, multifactor authentication, Conditional Access, passwordless authentication, role-based access control, identity lifecycle administration, and device identities.
  • Azure virtual machines, Azure Storage and Azure Files, Azure Backup, Recovery Services vaults, monitoring, alerts, networking fundamentals, resource groups, subscriptions, tagging, and Azure role-based access control.
  • Exchange Online, Microsoft Teams, SharePoint Online, OneDrive, Microsoft 365 administration, licensing, service health, and support.
  • PowerShell, configuration and patch management, monitoring, recovery procedures, technical documentation, and operational runbooks.

Preferred Certifications

  • Microsoft Certified: Azure Administrator Associate (AZ-104)
  • Microsoft 365 Administrator Expert (MS-102)
  • Endpoint Administrator Associate (MD-102)
  • Identity and Access Administrator Associate (SC-300)

Knowledge, Skills & Abilities

  • Strong analytical, diagnostic, troubleshooting, organization, project coordination, documentation, testing, and change-control skills.
  • Excellent written and verbal communication skills, including the ability to explain technical information to non-technical stakeholders.
  • Ability to independently manage priorities, follow work through completion, collaborate across teams, and appropriately escalate operational, security, and project risks.
  • Service-oriented mindset and commitment to continuous learning as Microsoft technologies and organizational needs evolve.

Working Conditions

  • Hybrid position requiring a combination of on-site and remote work and regular use of cloud administration, automation, and remote-support technologies.
  • Occasional work outside standard business hours may be required for maintenance, deployments, incident response, recovery testing, or project activities.
  • Occasional lifting, movement, installation, or replacement of computer and infrastructure equipment may be required.

 

Salary and Benefits

The salary range for this position is $100K ‐ $120K. Placement within the range will be based on directly relevant experience, qualifications, certifications, and demonstrated expertise across Microsoft cloud, endpoint, identity, automation, backup, and Microsoft 365 technologies. Benefits include group medical, dental, vision, 401K, 457, defined benefit though Colorado PERA, life insurance and long‐term disability.

How Do You Apply?

Please complete the form below or send your cover letter and resume to Human Resources, humanresources@fppaco.org.

There was a problem saving your submission. Please try again later.
Please wait while your submission is being saved...
Thank you, your submission has been received.