Senior Microsoft Endpoint Management Engineer
Role details
Job location
Tech stack
Job description
This senior role is intentionally balanced across Microsoft Endpoint Configuration Manager (MECM/SCCM) and Microsoft Intune, with responsibilities split between traditional endpoint management and modern cloud-based endpoint management., The Senior Microsoft Endpoint Management Engineer is responsible for designing, implementing, maintaining, and supporting enterprise endpoint management solutions using both Microsoft Endpoint Configuration Manager (MECM/SCCM) and Microsoft Intune.
This role serves as a subject matter expert for traditional and modern endpoint management, including operating system deployment, application lifecycle management, device compliance, security controls, endpoint analytics, and cloud-based device management., Microsoft Endpoint Configuration Manager (MECM / SCCM)
- Design, implement, administer, and maintain MECM infrastructure, including site systems, boundaries, boundary groups, distribution points, and client settings.
- Monitor MECM health, performance, and availability; perform upgrades, hotfix installations, and environment maintenance.
- Design and maintain Windows 10/11 operating system deployment task sequences for bare-metal, refresh, and in-place upgrade scenarios.
- Manage boot images, driver repositories, deployment media, and PXE/task sequence troubleshooting.
- Package, test, deploy, and maintain enterprise applications using MSI, EXE, PowerShell, scripts, and establish detection methods, dependencies, supersedence, and deployment requirements.
- Manage Windows and third-party patching solutions, including deployment rings, maintenance windows, compliance monitoring, and remediation.
Microsoft Intune / Cloud Endpoint Management
- Design, implement, and administer Microsoft Intune environments for Windows, macOS, iOS, and Android device management.
- Configure device enrollment, Microsoft Entra ID join, hybrid join, compliance policies, configuration profiles, device restrictions, and endpoint security policies.
- Design and implement Windows Autopilot scenarios, including user-driven, pre-provisioned, and self-deploying deployments.
- Configure Enrollment Status Page behavior, Autopilot profile assignments, and troubleshoot enrollment and provisioning issues.
- Package and deploy Win32, Microsoft Store, Microsoft 365 Apps, and line-of-business applications; manage application lifecycle and update processes.
- Configure and maintain security baselines, BitLocker management, Endpoint Privilege Management, Microsoft Defender integration, and Conditional Access integration.
Co-Management & Endpoint Modernization
- Design and implement MECM/Intune co-management solutions and migrate workloads between MECM and Intune.
- Develop endpoint modernization roadmaps that guide customers from traditional device management to cloud-native management.
- Assess customer endpoint environments and recommend best-practice architectures for modern management, compliance, and security.
- Lead technical workshops, design sessions, implementation efforts, and customer-facing endpoint management projects.
Automation, Documentation & Reporting
- Develop PowerShell scripts for endpoint automation, administration, reporting, and remediation.
- Integrate endpoint management workflows with Microsoft Graph API where applicable.
- Create and maintain technical documentation, SOPs, runbooks, architecture diagrams, and implementation guides.
- Develop reports using MECM, Intune, Power BI, SQL, and Microsoft reporting tools to track deployment success, compliance, and endpoint metrics.
- Provide Tier 3 escalation support and mentor junior engineers or support staff.
Requirements
The ideal candidate possesses deep expertise in both MECM and Intune and can help organizations modernize endpoint management through co-management, Microsoft Entra ID integration, Windows Autopilot, and cloud-native management strategies., * 5+ years of hands-on experience administering MECM/SCCM in enterprise environments.
- 5+ years of hands-on experience administering Microsoft Intune.
- Strong experience with Windows 10 and Windows 11 deployment, management, and troubleshooting.
- Experience with operating system deployment, application packaging/deployment, patch management, endpoint security, and device compliance.
Benefits & conditions
Pulled from the full job description
- Referral program
- Health insurance
- 401(k) matching
- Paid time off
- Vision insurance
- Dental insurance
- Life insurance, * Medical, dental, and vision insurance plans.
- Company-paid life insurance and long-term disability coverage.
- Optional supplemental benefits.
- Paid time off (PTO) starting in your first year of employment.
- Seven (7) paid holidays annually.
- 401(k) plan with safe harbor match, including both traditional and Roth options.
- Business casual office environment.
- Employee referral program with bonus opportunities.