> Markdown version of [/jobs/ext/1450321-desktop-engineering-lead-endpoint-security](https://www.wearedevelopers.com/jobs/ext/1450321-desktop-engineering-lead-endpoint-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Desktop Engineering Lead - Endpoint Security - **Company:** T. Rowe Price - **Location:** Owings Mills, MD, United States (Remote available) - **Experience:** Expert - **Salary:** $110,000.0 - $188,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, System Center Configuration Manager, Windows PowerShell, Zero Trust Network Access, Software Vulnerability Management, Policy as Code, Microsoft InTune - **Published:** July 26, 2026 - **Apply:** https://www.juju.com/job/00000000gjdxse ## About the Role + BS or MS degree (or equivalent experience) and 8+ years of experience in endpoint engineering, EUC, or desktop platform management within a large enterprise environment. + Deep hands-on expertise with Intune, MECM (SCCM), Microsoft Defender, Entra ID, and Windows endpoint security controls. + Strong experience operating in regulated environments (financial services, healthcare, highly regulated enterprise). + Proven ownership of endpoint patching, vulnerability remediation, OS lifecycle, and compliance controls at scale. + Demonstrated experience serving as a technical decision authority for high-risk or high-impact changes. + Strong understanding of Zero Trust principles, device posture, and conditional access. + Excellent troubleshooting and root cause analysis skills for complex endpoint issues. Preferred: + Experience supporting environments with 10k+ endpoints. + Familiarity with audit, risk, and compliance frameworks impacting endpoint controls. + Experience driving automation and standardization initiatives (PowerShell, policy-as-code, reporting, etc.). + Hands-on experience with Intune, MECM (SCCM), Microsoft Defender, Entra ID, and Windows endpoint management. + Strong communication skills with the ability to engage security, audit, and senior leadership audiences. What This Role Is + Atrue accountability owner for endpoint health, compliance, and security. + A senior technical authority trusted to make risk-based decisions. + A bridge between engineering, operations, and security. What This Role Is Not + A ticket-driven desktop support role. + A purely strategic role without hands-on ownership. + A delegated or advisory-only position without decision authority. ## Description We are seeking a Lead Desktop Engineer to own the technical direction, operational health, and security posture of our endpoint environment across approximately 14,000 managed devices. This role serves as the senior technical authority for endpoint engineering, operations, and security-ensuring consistent design, execution, and control ownership in a regulated enterprise environment. The Desktop Engineering Lead will be accountable for endpoint compliance, vulnerability remediation, configuration standards, and high-risk technical decision-making. This role partners closely with Security, Infrastructure, Risk, and Audit teams to reduce operational risk, maintain audit readiness, and deliver a stable, secure end-user computing platform. Responsibilities Endpoint Engineering & Platform Ownership: + Serve as the technical lead for endpoint engineering, operations, and security across ~14k devices, ensuring standardized design, implementation, and enforcement. + Own the endpoint management stack, including Intune, MECM (SCCM), Microsoft Defender, Entra ID, and related tooling. + Define and maintain endpoint architecture, configuration baselines, and OS lifecycle standards in alignment with security and regulatory requirements. Security, Risk & Compliance: + Own endpoint health and compliance, including patching, OS upgrades, configuration baselines, device posture, and conditional access enforcement. + Own application control capabilities, including Windows Defender Application Control (WDAC), to enforce secure execution policies and reduce endpoint risk. + Provide decision authority for high-risk endpoint changes (patching, policy updates, security remediations), minimizing the risk of misconfiguration or large-scale impact. + Ensure timely remediation of vulnerabilities and adherence to firm-defined SLAs, reducing exposure windows and maintaining audit readiness. + Enforce secure baseline configurations and compliance controls across all managed endpoints. Operations & Vulnerability Management: + Partner with Security and Vulnerability Management teams to prioritize, plan, and execute endpoint remediation activities. + Ensure endpoint controls and processes are measurable, defensible, and auditable. + Act as the escalation point for complex or high-impact endpoint incidents, driving root cause analysis and long-term corrective actions. Automation & Continuous Improvement: + Drive operational efficiency through automation, standardization, and reduction of manual processes. + Improve consistency, reliability, and scale of endpoint operations through policy-driven management and modern endpoint practices. + Identify opportunities to modernize endpoint engineering practices and tooling while maintaining regulatory compliance. Leadership & Collaboration: + Provide technical mentorship and leadership within the desktop/endpoint engineering team. + Collaborate with L1/L2 support, infrastructure, identity, security, and audit partners to ensure clear ownership and smooth execution. + Translate technical risk and trade-offs into clear, actionable recommendations for leadership. ## Related Videos - [Policy as [versioned] code - you're doing it wrong](https://www.wearedevelopers.com/videos/532-policy-as-versioned-code-you-re-doing-it-wrong) - [Fake or News: Translating Dog Barks, Notepad Gets an Upgrade and Michelin-Star Robots - Paul Tregoing](https://www.wearedevelopers.com/videos/1802-fake-or-news-translating-dog-barks-notepad-gets-an-upgrade-and-michelin-star-robots-paul-tregoing) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Decoupled Authorization using Policy as Code](https://www.wearedevelopers.com/videos/35-decoupled-authorization-using-policy-as-code) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [How Lufthansa Industry Solutions is preparing for the Quantum Age! ](https://www.wearedevelopers.com/videos/1443-how-lufthansa-industry-solutions-is-preparing-for-the-quantum-age) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)