> Markdown version of [/jobs/ext/1316768-systems-engineer-ii-endpoint](https://www.wearedevelopers.com/jobs/ext/1316768-systems-engineer-ii-endpoint). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Systems Engineer II - Endpoint - **Company:** Space Coast Credit Union - **Location:** Melbourne, FL, United States - **Experience:** Expert - **Salary:** $113,900.0 - $120,628.0 - **Contract:** Temporary contract - **Skills:** Microsoft Windows, Apple IOS, Apple Mac Systems, Application Packaging, Systems Engineering, App Store (IOS), Bash Shell, Cyber Security, Information Systems, Computer Engineering, Virtual Private Networks (VPN), Python (Programming Language), System Center Configuration Manager, Windows API, Windows PowerShell, Software Deployment, Scripting, Enterprise Software Applications, Microsoft InTune, Tanium Platform Expertise, Information Technology, Deployment Automation, 3-tier Architectures, CIS Benchmarks, Qualys, Vulnerability Analysis - **Published:** July 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e976b4bb21f7e91d ## About the Role 5 to 8 years of progressively responsible endpoint engineering experience in enterprise environments, including strong hands-on administration of Tanium for endpoint management and patching, Microsoft Intune for Windows/macOS/iOS, Group Policy (GPO) and Intune policy administration and deployment, third-party application patching, software packaging, scripting (PowerShell), and Tier 3 troubleshooting. Experience with SCCM/MECM, Kaseya VSA, or similar platforms is a plus. A 4-year degree in Information Systems, Computer Science, Computer Engineering, or a related field is preferred. Equivalent combinations of education, certifications, and directly related enterprise endpoint engineering experience will also be considered. Experience in regulated industries such as financial services, healthcare, or government is strongly preferred. ## Description As a Systems Engineer II, you will be responsible for designing, implementing, maintaining, and securing the enterprise workstation and mobile endpoint estate, including Windows, macOS, and iOS devices managed through Microsoft Intune. This role owns operating system and third-party application patching, OS lifecycle management, software packaging and deployment, Group Policy (GPO) and Intune policy administration, configuration baselines, and endpoint security tooling across on-premises, cloud-managed, and remote endpoints in a regulated financial services environment., * Administer, maintain, and optimize Tanium as the primary endpoint management and patching platform, including module configuration (Patch, Deploy, Comply, Asset, Interact), sensor/package authoring, content distribution, and operational reporting. * Design, execute, and continuously improve enterprise patching strategies for Windows and macOS operating systems and third-party applications, including monthly Patch Tuesday cycles, out-of-band releases, zero-day remediation, and Windows feature update servicing. * Coordinate patch testing, pilot rings, phased production deployment, validation, and rollback procedures across on-site and remote/VPN workstations; monitor patch compliance dashboards and remediate failures or non-reporting devices promptly. * Package, test, and deploy enterprise applications for Windows (MSI, EXE, MSIX, Win32), macOS (PKG, DMG), and iOS (App Store and line-of-business apps) using Tanium Deploy and Microsoft Intune (with SCCM/MECM where applicable); maintain a curated software catalog and self-service application access. * Manage endpoint provisioning and enrollment workflows for Windows (Autopilot), macOS (Automated Device Enrollment via Apple Business Manager / Intune), and iOS (ADE via ABM / Intune), including driver libraries, in-place feature upgrades, and zero-touch provisioning experiences. * Own the full lifecycle of Group Policy Objects (GPOs) and Microsoft Intune policies for endpoints across Windows, macOS, and iOS. This includes configuration profiles, compliance policies, security baselines, endpoint protection policies, app configuration and protection policies, update rings, and conditional access. Design policies, test in pilot rings, deploy to production, troubleshoot, document, and continuously tune them to align with CIS-based hardening standards and business requirements. * Develop and maintain automation for endpoint provisioning, software deployment, patch orchestration, health checks, and reporting using Tanium sensors/packages, PowerShell, Python, and Bash/shell scripting for macOS. * Manage workstation lifecycle activities including provisioning, refresh, decommissioning, asset reconciliation, and timely retirement of unsupported operating systems and applications. * Partner with the Cybersecurity team to analyze vulnerability scan results (e.g., Qualys, Tenable, Rapid7), prioritize remediation based on risk and exploitability, and track remediation to closure within defined SLAs. * Provide Tier 3 escalation support for complex endpoint, software deployment, OSD, patch compliance, and client health issues; perform root cause analysis and drive permanent remediation. * Participate in platform upgrades and migrations (e.g., Tanium module rollouts, Windows 10 to 11, macOS major version transitions, Intune co-management and cloud-native moves) while following established operational, risk, and change control processes. * Create and maintain technical documentation, runbooks, standards, procedures, and change records to support operational consistency, audit readiness, and knowledge transfer to peers and the service desk. * Collaborate with cybersecurity, network, identity, cloud, and application teams to support secure, resilient, and high-performing endpoint services; other duties as assigned. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Xcode development redefAIned](https://www.wearedevelopers.com/videos/100195-xcode-development-redefained) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Harnessing Apple Intelligence: Live Coding with Swift for iOS](https://www.wearedevelopers.com/videos/1515-harnessing-apple-intelligence-live-coding-with-swift-for-ios) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Basic And Advanced Networking in Dart and Flutter](https://www.wearedevelopers.com/magazine/112-basic-and-advanced-networking-in-dart-and-flutter) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs)