About this Systems Administrator role at Abtrace
Abtrace is tackling one of the hardest problems in healthcare: helping primary care deliver proactive, preventative care at scale.
Based in Paddington, London, our team of doctors, researchers, engineers and data scientists builds clinical algorithms that continuously scan patient records to detect deterioration, spot the early onset of disease, and surface opportunities for preventative intervention. We automate the delivery of measurements, vaccinations, blood tests and routine reviews, helping GP practices, PCNs and ICBs improve outcomes, reduce operational burden and maximise funding.
We work with over 600 primary care practices across the UK, covering 7.5 million patients.
The Role
We are seeking a Systems Administrator to own our internal infrastructure, identity and endpoint estate, and to keep the internal support pipeline moving alongside it.
This is a hands-on role in a small team. You will be responsible for the systems and also for the tickets they generate. There is no separation here between designing a control and being the person who applies it, or between owning the endpoint estate and unlocking an account at short notice.
As a company processing NHS patient data, we operate to a high security and compliance standard. You will own defined control areas within our certification programme and be accountable for the evidence behind them.
Responsibilities
Infrastructure and cloud
- Own our AWS environment across development and production: IAM, networking, EC2 and managed services, patch compliance through Systems Manager, tagging, monitoring and cost control.
- Maintain and improve backup, restore testing and disaster recovery, including documented and rehearsed recovery procedures.
- Build and maintain automation in PowerShell, Bash or Python to remove manual work from routine administration.
- Manage internal networking, DNS, VPN and firewall configuration.
Identity and collaboration
- Own Microsoft 365 and Entra ID: conditional access policy, privileged role design, licensing, Exchange Online, Teams and SharePoint permissions.
- Apply and enforce least privilege, and run the periodic access review cycle.
- Manage SSO and provisioning integrations for internal SaaS applications.
Endpoint estate
- Own device management across a mixed Windows and macOS estate in Microsoft Intune and Kandji: baseline configuration, hardening, patching, encryption and application deployment.
- Maintain joiner, mover and leaver processes end to end, including timely revocation and device recovery or wipe on exit.
- Keep the asset register accurate and audit ready.
Internal support pipeline
- Action the internal support queue in Jira day to day: triage, prioritise, resolve and keep tickets updated. This is a core part of the role, not an occasional overflow duty.
- Work to agreed response and resolution SLAs and flag any ticket at risk of breach in advance.
- Handle access requests directly: password and MFA resets, account lockouts, licence and permission changes, mailbox and distribution list administration.
- Reduce recurring ticket volume through automation, self-service and better defaults rather than absorbing it indefinitely.
- Maintain runbooks and documentation to a standard that allows work to be delegated as the team grows, and support and mentor junior support staff.
Security, compliance and audit
- Own assigned control areas within our certification and audit programme, covering ISO 27001, Cyber Essentials Plus, the NHS Data Security and Protection Toolkit and DTAC assessments.
- Prepare for and take part in external audits and surveillance visits, and drive remediation of findings to closure.
- Lead on client and prospect security questionnaires and due diligence requests.
- Participate in incident response, including out of hours where the severity requires it.
Requirements
Essential
- 5 or more years in systems administration, infrastructure or IT engineering, including time spent working a support queue rather than only project work.
- Production experience administering AWS.
- Strong Microsoft 365 and Entra ID administration, including conditional access.
- Endpoint management at scale with Intune and Jamf, Kandji or a comparable macOS MDM.
- Scripting and automation in PowerShell, Bash or Python.
- Solid networking fundamentals: DNS, DHCP, VPN, TLS and firewall configuration.
- Genuine willingness to hold both ends of the role, taking a routine unlock as seriously as an infrastructure change.
- Ability to work at pace across concurrent priorities without loss of accuracy.
- Disciplined approach to process, change control and documentation. In a regulated environment, the record is as important as the fix.
- Right to work in the UK.
Desirable
- Direct experience of ISO 27001, Cyber Essentials Plus, DSPT, DTAC or SOC 2 audits as an implementer rather than an observer.
- Infrastructure as code, ideally Terraform.
- Jira administration and automation.
- Backup, DR or business continuity ownership at a previous employer.
- Background in healthcare, fintech or another sector handling sensitive personal data.
Benefits
- Motivated, highly functioning, multi-disciplinary team
- High trust, ownership, and the opportunity to shape meaningful healthcare software
- Competitive salary, depending on experience
- Private pension
- Generous maternity/paternity leave
- Office in Paddington with hybrid-working model
- Laptop and any necessary equipment