Senior Windows Endpoint Engineer

Fannie Mae
Reston, VA, United States
16 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$123,000.0 - $161,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Application Programming Interfaces (APIs) Cloud Engineering System Center Configuration Manager Windows PowerShell Azure Active Directory Zero Trust Network Access Workspace ONE Microsoft InTune Deployment Automation 3-tier Architectures CIS Benchmarks
+1 more
Unified Endpoint Management

Job description

  • Design, implement, and maintain enterprise endpoint management solutions using Microsoft Intune.
  • Manage endpoint lifecycle processes including provisioning, deployment, configuration, maintenance, and retirement.
  • Develop and maintain device configuration profiles, compliance policies, update rings, and security baselines.
  • Support migration and coexistence strategies between Workspace ONE and Microsoft Intune.

Windows Engineering

  • Administer and support Windows 11 enterprise environments.
  • Create and manage standardized endpoint configurations and operating system deployment strategies.
  • Evaluate new Microsoft endpoint technologies and recommend improvements to the workplace computing environment.
  • Provide advanced troubleshooting for complex Windows platform issues.

Automation & Scripting

  • Develop PowerShell automation solutions to improve operational efficiency.
  • Create automated remediation, reporting, compliance validation, and deployment processes.
  • Use Microsoft Graph APIs to automate endpoint administration, reporting, and device lifecycle activities.

Endpoint Security & Compliance

  • Implement endpoint security standards and compliance controls.
  • Manage device compliance policies, encryption, security baselines, and conditional access requirements.
  • Partner with cybersecurity teams to remediate vulnerabilities and maintain regulatory compliance.
  • Monitor endpoint health, risk, and policy adherence across enterprise device fleets.

Autopilot & Provisioning

  • Design and support Windows Autopilot deployments.
  • Troubleshoot enrollment, provisioning, and Enrollment Status Page issues.
  • Implement zero-touch deployment and device onboarding strategies.
  • Optimize user experience during provisioning and device refresh initiatives.

Advanced Troubleshooting

  • Lead root cause analysis of complex endpoint management and policy deployment issues.
  • Troubleshoot Microsoft Intune, MDM, compliance, device registration, and identity integration issues.
  • Support Tier 3 escalation activities for endpoint-related incidents and outages.

Requirements

  • 2 years of Windows endpoint engineering or endpoint management experience.
  • Microsoft Intune administration experience.
  • Windows 11 engineering and troubleshooting expertise.
  • Experience with Microsoft Graph API.
  • Hands-on experience with Windows Autopatch.
  • Advanced PowerShell scripting and automation skills.
  • Experience managing Configuration Profiles and Compliance Policies.
  • Knowledge of Microsoft Entra ID device management.
  • Strong understanding of endpoint security and compliance frameworks.
  • Experience supporting large enterprise endpoint environments.
  • Shows curiosity and adaptability in learning and responsibly applying new technologies, including artificial intelligence, to reimagine how we work.

Desired Experiences:

  • Bachelor degree or equivalent
  • Workspace ONE administration experience.
  • SCCM/MECM experience.
  • Windows Autopilot deployment expertise.
  • Experience with Conditional Access and Zero Trust initiatives.
  • Endpoint analytics and reporting experience.
  • Microsoft certifications in Intune, Endpoint Administrator, or related technologies.
  • Experience supporting hybrid and cloud-native device management architectures., Bachelor’s Level Degree (Required)

The future is what you make it to be. Discover compelling opportunities at Fanniemae.com/careers.

For most roles, employees are expected to work onsite on a regular basis at their designated office location. In-office work cadence is determined by your manager. Proximity within a reasonable commute to your designated office location is preferred unless the job is noted as open to remote.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

5:24 min

Adopting integrated workspace environments instead of standard plugins

Chris Heilmann +2 · LIVE

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · WWC 2023

2:39 min

Contextualizing the why and how of security requirements

Nazneen Rupawalla · WWC 2022

Videos

See all

Related articles

See all