Browngibbonslangcompany

Open

Systems and Cloud Administrator

Location
Chicago, IL
Posted
Jul 14, 2026
Last seen
Aug 6, 2026

About the role

Brown Gibbons Lang & Company (BGL) is a leading independent investment bank and financial advisory firm focused on the global middle market. We advise private and public corporations and debt and equity sponsors on mergers and acquisitions , capital markets , financial restructurings , valuations and opinions , real estate , and other strategic matters. BGL has investment banking offices in Boston, Chicago, Cleveland, Los Angeles, and New York, and real estate offices in Chicago and Cleveland. The firm is also a founding member of REACH Cross-Border Mergers & Acquisitions, enabling BGL to service clients in 30 countries around the world. On every engagement, our clients receive senior-level attention from experienced bankers who bring a wealth of industry knowledge, transaction expertise, and deep relationships with key players in a broad range of industries.

Our success and growth is due to the expertise, passion, and commitment of our team. We value our employees and invest in their development, recognizing that their talent is the foundation of the exceptional service we deliver to BGL clients.

The Systems & Cloud Administrator works in support of the Director of Information Technology across BGL’s core platforms: identity, endpoint, and security operations in Microsoft 365; cloud infrastructure and governance in Azure; and managed data integration and warehousing in Fivetran and Snowflake. The Director leads strategy and most initiatives; this role assists with day-to-day administration and execution while building enough depth across each domain to operate the environment independently and provide continuity for the organization should the Director be unavailable. The position is a key part of BGL’s IT capability buildout and is intended to reduce single-person dependency (bus-factor risk) as the firm scales.

Over time, there will be opportunities to contribute to the firm’s broader technology and AI initiatives, helping ensure the data environment is well-governed and ready to support new tools and capabilities as they emerge. The ideal candidate pairs hands-on cloud and Snowflake administration experience with a security-first mindset and an interest in how data infrastructure supports emerging technologies.

Key Responsibilities

Working under the direction of the Director of Information Technology, the Systems & Cloud Administrator assists across the areas below while developing the cross-domain familiarity needed to provide independent coverage and organizational continuity.

Microsoft 365 & Identity Administration

  • Tenant administration — Support administration of the Microsoft 365 E7 tenant, including Exchange Online, SharePoint Online, Teams, and OneDrive, maintaining enough familiarity to operate the tenant independently when needed.
  • Microsoft Entra ID — Assist with identity and access management in Entra ID, including Conditional Access policies, Multi-Factor Authentication, SSO/SAML enterprise applications, group and license assignment, and SCIM-based user provisioning.
  • Identity governance — Help operate Privileged Identity Management, Access Reviews, and Entitlement Management to support least-privilege access and periodic access certification for regulated systems.
  • Microsoft Entra Suite — Assist with administration of the Entra Suite included with the E7 tier, including Entra Internet Access and Entra Private Access (Security Service Edge / Zero Trust network access) and Entra ID Governance access packages and lifecycle workflows.
  • Lifecycle automation — Help build and maintain onboarding, offboarding, and role-change automation (e.g., Azure Automation runbooks, PowerShell, Graph API) to support a growing analyst population with minimal manual effort.

Endpoint Management & Device Deployment

  • Microsoft Intune — Assist with device enrollment, compliance policies, configuration profiles, and application deployment across Windows endpoints.
  • Windows Autopilot — Support zero-touch provisioning for new workstations, help maintain deployment profiles and Enrollment Status Page configuration.
  • Application & patch delivery — Assist with software packaging, deployment, and patching across the fleet, working with existing tooling (PDQ Connect) and endpoint controls (ThreatLocker) for application allowlisting.
  • Endpoint analytics — Monitor device health, performance, and utilization to inform hardware refresh decisions and help remediate at-risk endpoints.

Security & Compliance Operations

  • Microsoft Defender — Assist with administration of Defender XDR across endpoint, identity, Office 365, and cloud apps; triage and respond to alerts, support investigation and threat hunting under the direction of the Director of IT.
  • Incident response support — Support investigation and containment of security incidents, and participate in tabletop exercises under the direction of the Director of IT.
  • Microsoft Purview — Help configure and maintain Data Loss Prevention, retention policies, sensitivity labels, Communication Compliance, eDiscovery, and audit — supporting the firm’s FINRA and SEC recordkeeping and supervision obligations.
  • Microsoft 365 Copilot governance — Assist with administration and governance of Microsoft 365 Copilot, helping ensure Copilot honors sensitivity labels and that prompts and responses remain within Purview audit, retention, Data Loss Prevention, and Communication Compliance controls; AI compliance controls are owned within IT, coordinating with the Enterprise Intelligence & AI team on adoption.
  • Insider Risk Management — Support configuration of Microsoft Purview Insider Risk Management and Adaptive Protection to detect and respond to risky data handling and potential exfiltration, reinforcing the firm’s supervision obligations.
  • Regulated archiving — Support electronic communications capture and archiving (Smarsh) and help ensure retention and supervision configurations align with broker-dealer requirements.
  • Security posture & awareness — Help track Secure Score and exposure findings, maintain security baselines, and support the security-awareness and phishing-simulation program (Defender Attack Simulation Training). &l