Senior Microsoft Endpoint Management Engineer

All Lines Technology
Pittsburgh, PA, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$132,709.0 - $151,667.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Application Programming Interfaces (APIs) Android Software Development Apple IOS Apple Mac Systems Application Lifecycle Management Application Packaging BitLocker Drive Encryption Microsoft Online Services Business Software Cloud Computing
+21 more
Dynamic Host Configuration Protocol Domain Name System (DNS) Microsoft Security Essentials System Center Configuration Manager Windows API Public Key Infrastructure Windows PowerShell Power BI Azure Active Directory SQL Databases Microsoft Reporting Enterprise Software Applications Software Troubleshooting Microsoft InTune Azure Security Center Deployment Automation Bare Metal Patch Management 3-tier Architectures CIS Benchmarks Unified Endpoint Management

Job description

The Senior Microsoft Endpoint Management Engineer is responsible for designing, implementing, maintaining, and supporting enterprise endpoint management solutions using both Microsoft Endpoint Configuration Manager (MECM/SCCM) and Microsoft Intune. This role serves as a subject matter expert for traditional and modern endpoint management, including operating system deployment, application lifecycle management, device compliance, security controls, endpoint analytics, and cloud-based device management. The ideal candidate possesses deep expertise in both MECM and Intune and can help organizations modernize endpoint management through co-management, Microsoft Entra ID integration, Windows Autopilot, and cloud-native management strategies., Microsoft Endpoint Configuration Manager (MECM / SCCM)

  • Design, implement, administer, and maintain MECM infrastructure, including site systems, boundaries, boundary groups, distribution points, and client settings.
  • Monitor MECM health, performance, and availability; perform upgrades, hotfix installations, and environment maintenance.
  • Design and maintain Windows 10/11 operating system deployment task sequences for bare-metal, refresh, and in-place upgrade scenarios.
  • Manage boot images, driver repositories, deployment media, and PXE/task sequence troubleshooting.
  • Package, test, deploy, and maintain enterprise applications using MSI, EXE, PowerShell, scripts, and establish detection methods, dependencies, supersedence, and deployment requirements.
  • Manage Windows and third-party patching solutions, including deployment rings, maintenance windows, compliance monitoring, and remediation.

Microsoft Intune / Cloud Endpoint Management

  • Design, implement, and administer Microsoft Intune environments for Windows, macOS, iOS, and Android device management.
  • Configure device enrollment, Microsoft Entra ID join, hybrid join, compliance policies, configuration profiles, device restrictions, and endpoint security policies.
  • Design and implement Windows Autopilot scenarios, including user-driven, pre-provisioned, and self-deploying deployments.
  • Configure Enrollment Status Page behavior, Autopilot profile assignments, and troubleshoot enrollment and provisioning issues.
  • Package and deploy Win32, Microsoft Store, Microsoft 365 Apps, and line-of-business applications; manage application lifecycle and update processes.
  • Configure and maintain security baselines, BitLocker management, Endpoint Privilege Management, Microsoft Defender integration, and Conditional Access integration.

Co-Management & Endpoint Modernization

  • Design and implement MECM/Intune co-management solutions and migrate workloads between MECM and Intune.
  • Develop endpoint modernization roadmaps that guide customers from traditional device management to cloud-native management.
  • Assess customer endpoint environments and recommend best-practice architectures for modern management, compliance, and security.
  • Lead technical workshops, design sessions, implementation efforts, and customer-facing endpoint management projects.

Automation, Documentation & Reporting

  • Develop PowerShell scripts for endpoint automation, administration, reporting, and remediation.
  • Integrate endpoint management workflows with Microsoft Graph API where applicable.
  • Create and maintain technical documentation, SOPs, runbooks, architecture diagrams, and implementation guides.
  • Develop reports using MECM, Intune, Power BI, SQL, and Microsoft reporting tools to track deployment success, compliance, and endpoint metrics.
  • Provide Tier 3 escalation support and mentor junior engineers or support staff.

Requirements

  • 5+ years of hands-on experience administering MECM/SCCM in enterprise environments.
  • 5+ years of hands-on experience administering Microsoft Intune.
  • Strong experience with Windows 10 and Windows 11 deployment, management, and troubleshooting.
  • Experience with operating system deployment, application packaging/deployment, patch management, endpoint security, and device compliance.
  • Strong understanding of Microsoft Entra ID, Active Directory, Group Policy, DNS, DHCP, and PKI/certificates.
  • Advanced PowerShell scripting and automation experience.
  • Experience implementing MECM and Intune co-management.
  • Strong troubleshooting, communication, documentation, and customer-facing consulting skills.

Preferred Qualifications

  • Experience with Microsoft Defender for Endpoint, Defender XDR, Microsoft Cloud PKI, Endpoint Privilege Management, and Microsoft security baselines.
  • Experience with Microsoft Graph API, Power BI reporting, tenant-to-tenant migrations, endpoint modernization projects, and third-party patching solutions.
  • Experience supporting SMB, education, healthcare, government, or enterprise organizations.
  • Ability to lead discovery sessions, translate technical needs into project scopes, and present recommendations to customers and internal stakeholders., The ideal candidate has extensive experience managing both MECM and Intune environments and understands how to bridge traditional endpoint management with modern cloud-based management. They can independently lead customer implementations, support large-scale device deployments, automate administrative processes, and provide strategic guidance around endpoint modernization and endpoint security. This is a senior technical position requiring strong consulting skills, customer engagement experience, and the ability to lead endpoint management projects from design through implementation and support. Powered by JazzHR

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

1:11 min

Running high-performance edge computing on bare metal servers

Josip Stuhli Josip Stuhli · Coffee With Developers

2:25 min

Testing the AI generated Apple iOS Flashcards application

MIlan Todorović MIlan Todorović · WWC Europe 2026

1:24 min

Moving the semantic layer upstream to avoid vendor lock-in

Piotr Menclewicz Piotr Menclewicz · Europe 2026 Virtual

2:59 min

Why existing security and device management tools fail

Marcus Wermuth Marcus Wermuth · WWC Europe 2026

4:24 min

Evaluating bare metal versus cloud computing costs

Jens Happe Jens Happe · LIVE

Videos

See all

Related articles

See all