Lead Endpoint Engineer

Jfc Global
Lancaster, PA, United States
13 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$120,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows JIRA BitLocker Drive Encryption HP Thin Clients Azure Active Directory Software Deployment Software Vulnerability Management EndPointSecurity Microsoft InTune Deployment Automation CIS Benchmarks U-Boot

Job description

We are seeking a Lead Endpoint Engineer to own the design, deployment, security posture, and lifecycle management of end user devices across a multi-site manufacturing environment. This is an engineering and project execution role, not a ticket-only or break/fix role. You will lead endpoint initiatives end to end, partner closely with security and infrastructure teams, and drive standards through change management.This role is a backfill for a lead who was running major endpoint programs at scale (for example: large Windows 11 upgrades, mobile device and BYOD MDM design, Autopilot rollout, carrier migrations across 1,000+ devices, and security tooling ownership). We need someone who can step into that kind of ownership and keep the roadmap moving., * Own and improve Microsoft Intune configuration profiles, compliance policies, security baselines, and application deployment strategy.

  • Lead Autopilot enrollment and provisioning workflows (including shared device and specialized user group models).
  • Design and manage Windows update strategy (update rings, feature updates, quality updates, rollout controls, and remediation).
  • Drive endpoint standardization and hygiene across device populations (policy consistency, profile cleanup, scoping, documentation).

Endpoint security and vulnerability remediation

  • Own day to day endpoint security posture and remediation work tied to security findings and defined timelines.
  • Administer and tune endpoint security tools and policies (including Defender for Endpoint and Carbon Black App Control style allowlisting/approval workflows).
  • Maintain encryption and platform trust posture (BitLocker, Secure Boot related considerations, tamper protection, and policy enforcement).

Identity and access alignment (Entra ID / Conditional Access / SSO)

  • Support and improve endpoint-related identity integrations with Entra ID (Azure AD), Conditional Access alignment, and device-based access controls.
  • Assist with MFA initiatives and identity audits in partnership with security/infrastructure teams.

Thin clients and specialized manufacturing site devices

  • Support thin client management (including Dell/WYSE management tooling) and standards across manufacturing sites.
  • Help troubleshoot urgent incidents impacting operations, with focus on fast recovery and prevention through better engineering.

Change management and project leadership

  • Author and own changes through a formal change process (CAB), from design through implementation and validation.
  • Lead concurrent projects independently, drive timelines, and coordinate across teams.
  • Build and maintain runbooks, standards, and technical documentation (tools referenced include Jira Service Management).

Requirements

  • Strong hands on endpoint engineering background (not just service desk escalation).
  • Proven experience owning Intune at scale, including: configuration profiles, compliance, app deployment, Autopilot, and rollout strategy.
  • Solid endpoint security experience (Defender for Endpoint and similar tooling, remediation workflows, policy enforcement).
  • Experience supporting hybrid enterprise identity environments (AD + Entra ID concepts, device identity, access controls).
  • Comfort operating in a multi-site environment where onsite coordination and operational urgency matter.
  • Ability to lead, prioritize, and execute with minimal day to day task assignment.

Nice to have

  • Thin client management experience (WYSE / Dell WMS).
  • Manufacturing or production environment exposure (24/7 mindset, low downtime tolerance).
  • Experience leading large programs like OS upgrades, carrier migrations, or acquisition integrations.

Benefits & conditions

Pay: Up to $120,000.00 per year

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

1:06 min

Developer experience and project variety at scale

Alexandra Petri · WWC 2023

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · WWC 2023

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all