Endpoint Engineer

Fitch Ratings Ltd
London, UK
2 days ago
Apply on www.adzuna.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
£65,000.0 - £105,000.0
Working hours
Regular working hours

Tech stack

IEEE 802.1X Microsoft Windows Active Directory Artificial Intelligence Data Analysis Application Lifecycle Management Application Packaging Microsoft Azure BIOS Mobile Application Development Cloud Computing System Configuration
+27 more
Dynamic Host Configuration Protocol Programming Tools Domain Name System (DNS) Firmware Identity and Access Management Virtual Private Networks (VPN) Python (Programming Language) Microsoft Office System Center Configuration Manager Windows API Networking Basics Windows PowerShell Azure Active Directory Zero Trust Network Access Runbook Visual Studio Online Software Vulnerability Management Wi-Fi Technology Scripting Enterprise Software Applications Performance Testing Large Language Models Hardware Testing Git Microsoft InTune Git Flow Deployment Automation

Job description

  • Provide advanced Tier 2/3 support, endpoint management, and platform engineering across Windows, Microsoft Intune, and related technologies.
  • Migrate legacy Group Policy configurations to modern CSP-based Intune policy and resolve policy conflicts.
  • Design and maintain governed CSP policy structures across the fleet.
  • Drive vendor-led firmware and driver lifecycle management to improve stability and user experience.
  • Troubleshoot and remediate audio, video, and conferencing reliability issues.
  • Perform hardware and performance testing and benchmarking to support fleet standardization decisions.
  • Modernize Windows Autopilot and provisioning workflows to reduce legacy dependencies and improve consistency.
  • Resolve drive-mapping dependencies and CSP conflicts affecting the provisioning pipeline.
  • Complete remaining GPO-to-CSP transitions in support of provisioning consistency.
  • Package, test, and deploy enterprise applications using MECM and Intune.
  • Collaborate with engineering leadership to design, implement, and operationalize endpoint policies, configurations, and standards.
  • Configure, package, and support developer tooling across the fleet.
  • Define and support endpoint requirements for AI/ML workloads, including GPU driver management, containerization/WSL2, and local model runtime sizing.
  • Partner with engineering and data teams to evaluate, standardize, and roll out AI-assisted developer tools within governance guardrails.
  • Deliver advanced incident and problem resolution with a focus on user experience and root-cause elimination.
  • Execute patching, vulnerability remediation, compliance reporting, and endpoint health monitoring.
  • Partner with the Service Desk to improve workflows and reduce recurring issues through automation or policy enhancements.
  • Participate in an on-call rotation for critical after-hours incidents and high-priority escalations.
  • Create and maintain technical documentation, runbooks, and cross-team knowledge resources.
  • Engage in cross-functional project work spanning cloud identity, automation, security hardening, and software lifecycle management.
  • Proactively drive issues to resolution across business teams.

Technologies:

  • AI
  • Active Directory
  • Azure
  • Cloud
  • Firmware
  • Git
  • Hardware
  • Support
  • LLM
  • Microsoft 365
  • Microsoft Intune
  • PowerShell
  • Python
  • Security
  • VPN
  • VS Code
  • Windows
  • Office 365
  • Claude Code
  • Copilot
  • Embedded
  • Network

Requirements

  • 3-5+ years of experience in enterprise endpoint engineering or advanced support.
  • Hands-on experience with Windows 11, Azure AD / Entra ID, Microsoft Intune, MECM, and co-management services.
  • Experience with Active Directory and Directory Services, including Group Policy and RSAT tools.
  • Strong knowledge of Intune configuration and compliance policy management.
  • Experience with LAPS and least-privilege or privilege elevation models.
  • Experience deploying, configuring, and servicing Microsoft 365 Apps.
  • Understanding of networking fundamentals, including DNS, DHCP, VPN, and proxy.
  • Strong experience with modern Intune management, including Windows Autopilot and zero-touch provisioning.
  • Experience with Intune application management, including Win32, MSI, MSIX, store apps, and managed apps.
  • Experience with Settings Catalog, Compliance Policies, Configuration Profiles, Device Filters, Dynamic Groups, and scalable targeting strategies.
  • Experience with Endpoint Analytics and digital experience monitoring.
  • Experience with hardware validation, lifecycle management, firmware and BIOS updates, and Wi-Fi driver troubleshooting.
  • Experience troubleshooting 802.1X / WPA2-Enterprise authentication issues.
  • Proficiency with Windows PowerShell, including scripting, process and service management, command syntax, and error troubleshooting.
  • Experience supporting Zero Trust, conditional access, and identity-based access controls.
  • Experience configuring and troubleshooting developer tooling such as VS Code, Python, Git, and common CLI environments.
  • Experience supporting endpoint requirements for AI/ML workloads, including GPU drivers, WSL2/containers, local model runtimes, and resource sizing.
  • Ability to apply governance and device-management guardrails to developer and AI tooling without reducing productivity.
  • Strong collaboration, communication, documentation, and runbook writing skills.
  • Demonstrated ownership mindset focused on root-cause elimination and user experience improvement.
  • Experience with PowerShell App Deployment Toolkit is a plus.
  • Advanced MECM collection design and query creation are a plus.
  • Experience with Windows imaging modernization, such as Autopilot, zero-touch provisioning, and DISM, is a plus.
  • Familiarity with software packaging technologies such as EXE, MSI, MSIX, and INTUNEWIN is a plus.
  • Experience with third-party patching platforms is a plus.
  • Strong PowerShell automation expertise and familiarity with Git-based workflows are a plus.
  • Experience with vulnerability management tools and endpoint telemetry or observability platforms is a plus.
  • Experience supporting local AI/LLM developer tooling and GPU-accelerated workstations is a plus.
  • Microsoft certifications related to Endpoint, Azure, or Security are a plus.

About the company

We are Fitch Group, a global financial information services provider delivering credit and risk insights, robust data, and dynamic tools that help create more efficient and transparent financial markets. Based in our London office, this Endpoint Engineer role sits within our global infrastructure organization and supports a modern, AI-enabled Technology & Data team across a diverse international business. We offer a hybrid work environment with 2 to 3 days in the office each week, along with learning and mobility opportunities, leadership development, mentorship, retirement planning, financial wellness support, tuition reimbursement, comprehensive healthcare, generous global parental leave, paid volunteer days, and a culture recognized as a Best Place to Work in Technology for three years in a row.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

2:50 min

Introduction and the value of runbooks

Hila Fish · World Congress 2023

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann +1 · LIVE

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

1:32 min

Structuring automated incident workflows between runbooks and raw models

Aram Hakobyan Aram Hakobyan +1 · World Congress 2026 Europe

Videos

See all

Related articles

See all