Modern Endpoint & Intune Project Engineer

Preferred Business Systems, Inc.
Hanover, United States of America
13 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Compensation
$ 78K

Job location

Hanover, United States of America

Tech stack

Microsoft Windows
Application Lifecycle Management
Application Packaging
Audio Video Distribution
Azure
Configuration Management
System Configuration
Image Management
Virtual Private Networks (VPN)
Virtual Desktops
Powershell
Azure
Zero Trust Network Access
Software Troubleshooting
Firewalls (Computer Science)
Microsoft InTune
Deployment Automation
CIS Benchmarks
REST

Job description

We are seeking a Modern Endpoint & Intune Project Engineer to standardize and modernize our clients' environments using Microsoft Intune, Azure Active Directory, Azure Virtual Desktop (AVD), and related tools such as Nerdio and Autopilot.

This role is responsible for executing client standardization projects, enrolling and configuring devices in Intune and Autopilot, and aligning client environments with our best-practice reference architecture. You will work closely with the Project Engineering team, AI Automation team, and Server team to deliver consistent, secure, and streamlined environments for our clients.

This is an execution-focused role with a strong emphasis on project delivery, standardization, and repeatable implementation., Client Environment Standardization

  • Assess existing client environments (AD, Intune, AVD, Autopilot) and identify gaps against our standards.
  • Implement standardized configurations for:
  • Azure AD / Hybrid AD join
  • Intune device configuration and compliance policies
  • Security baselines and conditional access
  • Assist in migrating clients from legacy/on-premise models to modern, cloud-centric endpoint management.

Intune & Autopilot Implementation

  • Configure and manage Intune tenants, profiles, and policies for multiple clients.
  • Design and deploy Autopilot configurations (profiles, deployment groups, enrollment methods).
  • Standardize application packaging and deployment via Intune.
  • Ensure devices are enrolled, compliant, and aligned with defined build standards.
  • Troubleshoot enrollment, policy application, and device configuration issues.

Azure AD, AVD, and Nerdio

  • Configure and maintain Azure AD and AD Connect / AD Sync in alignment with project requirements.
  • Assist with the design and implementation of Azure Virtual Desktop environments, including:
  • Host pools, session hosts, and user assignments
  • Image management and scaling policies
  • Use Nerdio (or similar platforms) to streamline AVD deployment and lifecycle management.
  • Work with the Server team on directory, identity, and networking dependencies for AVD and Azure services.

Project Delivery & Collaboration

  • Execute project tasks according to defined designs, standards, and timelines.
  • Collaborate with:
  • Project Engineering team to ensure consistent delivery across clients.
  • AI Automation team to identify automation opportunities (e.g., scripting, policy templates).
  • Server team to coordinate dependencies related to AD, file services, and infrastructure.
  • Provide clear status updates and documentation for ongoing projects.
  • Contribute to the continuous refinement of our standard build, templates, and best practices.

Automation & Repeatability

  • Develop and maintain reusable scripts (primarily PowerShell) to automate:
  • Intune configuration
  • Device onboarding
  • AVD/Nerdio tasks
  • Work with the AI Automation team to convert manual processes into automated workflows.
  • Maintain standardized templates for policies, profiles, and configurations across clients.

How You'll Work

  • Execute against defined reference architectures and standards for Intune, AVD, and Azure AD.
  • Suggest improvements with clear problem statements and proposed solutions to the Project and Automation teams.
  • Prototype lightweight solutions (scripts, standardized configs) where appropriate.
  • Deploy changes in a controlled, documented manner, especially for multi-client impact.
  • Maintain documentation for:
  • Client-specific configurations
  • Standard builds and templates
  • Scripts and automation used across clients, * Client environments are consistently aligned to our standard Intune / AVD / Azure AD reference architecture.
  • New devices are onboarded via Autopilot in a predictable, repeatable manner.
  • Intune policies, profiles, and applications are standardized and reusable across clients.
  • AVD deployments are stable, scalable, and documented.
  • Internal teams rely on you for Intune/AVD-related project execution and guidance.
  • Automation and scripting reduce manual effort for recurring tasks.
  • Documentation is accurate, up to date, and usable by other team members.

Role Boundaries

  • This role focuses on project execution and environment standardization, not overall platform or security strategy.
  • Platform strategy, architecture, and security baselines are defined by senior engineering and Automation teams.
  • Limited direct end-user communication; primary interaction is with internal teams and project stakeholders.

Pay: $65,000.00 - $78,000.00 per year

Requirements

Do you have experience in Windows?, * Hands-on experience with Microsoft Intune for device and application management.

  • Experience with Azure Active Directory and AD Connect / AD Sync.
  • Experience with Windows Autopilot deployment and configuration.
  • Familiarity with Azure Virtual Desktop (AVD); Nerdio experience strongly preferred or willingness to learn quickly.
  • Strong PowerShell scripting skills for automation and configuration management.
  • Experience working with Windows endpoint builds, imaging, or modern provisioning.
  • Strong troubleshooting and problem-solving mindset, especially in multi-tenant environments.
  • Ability to build reusable, standardized solutions rather than one-off fixes.
  • Comfortable working in a project-driven environment with defined timelines and deliverables.

Preferred (Nice to Have)

  • Experience working in an MSP environment or multi-tenant setup.
  • Experience with:
  • Conditional Access, security baselines, and Zero Trust concepts.
  • Group Policy and migration to Intune-based policies.
  • Familiarity with:
  • Azure networking basics (VNets, VPN, firewalls) in the context of AVD.
  • REST APIs for automation and integration.

Benefits & conditions

20 Leslie Court, Whippany, NJ 07981 Hybrid work $65,000 - $78,000 a year - Full-time, Pulled from the full job description

  • Referral program
  • Professional development assistance
  • 401(k)
  • Health insurance
  • Retirement plan
  • 401(k) matching
  • Paid time off, * 401(k)
  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Life insurance
  • Paid time off
  • Professional development assistance
  • Referral program
  • Retirement plan
  • Vision insurance

About the company

Preferred Business Systems, Inc. has been a trusted provider of office automation and IT services since 1997. With a strong focus on customer satisfaction and technical excellence, the company offers a comprehensive range of office equipment, IT support, and managed services to help businesses operate efficiently and securely.

Apply for this position