Onsite Deskside Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+3 more
Job description
We’re looking for a hands-on Endpoint & Identity Engineer to own and mature our device management and security tooling. This role is primarily onsite at our San Francisco HQ and sits at the intersection of endpoint engineering, IT security, and automation. You’ll be the primary owner of our Microsoft Intune environment and will work closely with our security and IT teams to clean up legacy configurations, modernize device onboarding, and ensure our endpoint fleet is healthy, patched, and compliant., Own the day-to-day administration and long-term strategy for Microsoft Intune, including device enrollment, compliance policies, configuration profiles, and conditional access. Audit and remediate existing Intune policies - consolidating redundant configurations, resolving conflicts, and establishing clean, well-documented baselines. Design, refine, and maintain Windows Autopilot workflows for zero-touch device provisioning. Manage and improve application deployment pipelines, including Win32 app packaging, LOB apps, and Microsoft Store for Business integrations. Drive ongoing cleanup and hygiene across the Intune tenant - stale devices, orphaned policies, misconfigured profiles.
Patching & Vulnerability Management
Administer Automox for cross-platform patching across Windows, macOS, and Linux endpoints. Define and maintain patching policies, schedules, and SLAs to meet compliance requirements. Work with security tools such as Rapid7 to correlate vulnerability findings with patching coverage and close gaps. Produce regular reporting on patch compliance and endpoint health for stakeholders.
Identity & Access
Work within an Okta environment to support device trust integrations, SSO, and lifecycle management as it relates to endpoint posture. Collaborate on Conditional Access policies that tie Intune compliance to Okta-managed application access.
Collaboration & Projects
Partner with IT, Security, and Engineering teams on projects requiring endpoint or identity expertise. Document configurations, runbooks, and procedures to ensure knowledge continuity. Identify opportunities to automate repetitive tasks using PowerShell, Graph API, or similar tooling.
Requirements
- 3+ years of hands-on experience administering Microsoft Intune in a mid-to-large enterprise environment.
- Proven track record cleaning up or restructuring an Intune environment - policy rationalization, conflict resolution, device hygiene.
- Solid experience with Windows Autopilot, including profile configuration, deployment troubleshooting, and hardware hash management.
- Experience with Automox or a comparable cross-platform patching solution.
- Familiarity with Okta, including understanding of how device trust and MDM integration work within an Okta-managed identity environment.
- Exposure to vulnerability management tools such as Rapid7 InsightVM or similar.
- Proficiency with PowerShell and/or Microsoft Graph API for automation and reporting.
- Strong documentation habits and a methodical approach to change management.
Nice to Have
- Microsoft certifications (MD-102, MS-102, or similar).
- Experience with macOS management within Intune or alongside Jamf.
- Familiarity with CIS benchmarks or NIST frameworks as applied to endpoint hardening.
- Experience in a high-growth tech or hybrid-workforce environment.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 120 - Apple and peers
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Fully Remote Software Engineer Jobs
Why Upskilling And Reskilling is Important For Developers