Senior Windows Endpoint Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+20 more
Job description
The Senior Windows Endpoint Engineer owns the Windows client end-to-end, from bare-metal builds to the everyday user experience. This hands-on build engineering role is accountable for image and task sequence architecture in Microsoft Configuration Manager (SCCM), Group Policy, and Microsoft Intune cloud management, ensuring endpoints provision predictably, stay secure, and maintain optimal performance across their lifecycle., * Design, engineer, and troubleshoot Windows OS deployment across imaging, WinPE, task sequences, drivers, USMT, BitLocker, and firmware integration.
- Manage Configuration Manager (ConfigMgr/SCCM) site health, roles, PXE, boot images, boundaries, client settings, collections, software updates, and co-management workloads.
- Architect and implement Microsoft Intune capabilities, including Autopilot provisioning, settings catalogs, compliance policies, security baselines, and proactive remediations.
- Own Windows cloud patch management using Windows Update for Business, Autopatch, update rings, deferrals, and expedited updates while optimizing bandwidth for remote sites.
- Package and deploy cloud applications (Intune Win32, Microsoft Store, Enterprise App Catalog, M365 Apps) and legacy formats (MSI, MSIX, App-V) with reliable detection and dependencies.
- Maintain, rationalize, and migrate Group Policy (GPO) architecture and ADMX central stores to Intune policy equivalents.
- Build production-grade, idempotent, signed PowerShell scripts for automated provisioning, remediation, detection, and drift control.
- Implement security hardening baselines including BitLocker, ASR rules, AppLocker/WDAC, Credential Guard, exploit protection, and local admin management (LAPS)., The ideal candidate is a seasoned, hands-on endpoint build engineer-not merely a console administrator-who takes full accountability for the desktop estate. They possess deep expertise in both traditional on-premises management (ConfigMgr, GPO) and modern cloud management (Intune, Autopilot, WUfB), driven by a strong automation-first mindset using production-grade PowerShell., * Own and author Windows OS deployment designs, task sequences, WinPE, driver packages, and Autopilot provisioning.
- Engineer and maintain Configuration Manager and Microsoft Intune estates, managing co-management workloads and cloud transitions.
- Design and manage cloud patching strategies utilizing Windows Update for Business, update rings, and expedited updates.
- Develop production-grade, signed PowerShell scripts for automated device provisioning, drift control, and proactive remediations.
- Maintain endpoint security baselines, including BitLocker, Attack Surface Reduction (ASR) rules, AppLocker/WDAC, and LAPS.
- Rationalize legacy Group Policy (GPO) architecture and convert workloads to modern cloud policies.
Requirements
Reason for opening: Modernization and engineering ownership of the Windows desktop estate-driving end-to-end endpoint performance, security hardening, and transitioning workloads from on-premises ConfigMgr to cloud-native Microsoft Intune.
Key deliverables: Architecting bare-metal and zero-touch deployment task sequences, migrating GPO/ConfigMgr workloads to Intune with parity validation, creating robust PowerShell remediation scripts, and optimizing patch management for remote users.
Interview process stages: Multi-stage engineering interview focusing on hands-on task sequence authoring, PowerShell code quality/error handling, and real-world troubleshooting scenarios (logs, WMI, registry, driver/patch issues).
NON-NEGOTIABLES
Education: * Education: No specific degree explicitly required by client.
7+ years in Windows endpoint/desktop engineering owning build and configuration estates in complex environments.
Deep hands-on ConfigMgr (SCCM) site administration, OSD task sequence authoring, driver customization, and USMT.
Hands-on Intune engineering (Autopilot pre-provisioning, compliance, settings catalog, Win32 app delivery).
Production-grade PowerShell automation (must include logging, error handling, idempotency, and code signing).
Deep understanding of Windows client internals (Registry, WMI, Event Logs, setup logs, performance, profile behaviors) and supporting backend infrastructure (AD, Entra ID, DNS, DHCP, PKI, WSUS, LAPS).
NICE-TO-HAVES
Experience migrating ConfigMgr workloads to cloud management with full parity validation and on-premises retirement.
Advanced automation experience using Microsoft Graph API, CI/CD for application packaging, or infrastructure as code.
Microsoft certifications: MD-102 (Endpoint Administrator), SC-200, SC-100, or equivalent credentials.
DISQUALIFIERS
Candidates who are purely āconsole administratorsā or Tier 1/2 desktop support technicians lacking hands-on build/engineering experience.
Inability to write structured, production-grade PowerShell scripts (only relies on GUI tools or basic command lines).
Lack of experience with bare-metal OS deployment, WinPE engineering, or task sequence debugging from raw logs., * Windows Endpoint / Desktop Engineering (7+ years)
- Microsoft Configuration Manager / SCCM Engineering (5+ years)
- Windows OS Deployment, Imaging, & Task Sequences (5+ years)
- Microsoft Intune & Autopilot Engineering (3+ years)
- Windows Update for Business (WUfB) & Cloud Patching (3+ years)
- Advanced PowerShell Scripting & Automation (5+ years)
- Group Policy (GPO) Architecture & ADMX Management (5+ years)
- Application Packaging (MSI, Win32, MSIX) & App Delivery (5+ years)
ADDITIONAL DESIRED SKILLS
- Modernization experience migrating ConfigMgr workloads to Microsoft Intune
- Zero-touch / Low-touch Autopilot pre-provisioning architecture
- Windows Feature Update / OS migration programs at scale
- Graph API, WMI-driven reporting, or Policy-as-Code automation
- Experience in global, highly regulated, or enterprise environments (including VDI or shared devices)
- Relevant Microsoft certifications (MD-102, MCSE, SC-200, or SC-100)
About the company
InterSources Inc, a Certified Diverse Supplier, was founded in 2007 and offers innovative solutions to help clients with Digital Transformations across various domains and industries. Our history spans over 19 years and today we are an Award-Winning Global Software Consultancy solving complex problems with technology. We recognize that our employees and our clients are our strengths as the diverse talents and opportunities they bring to the table enable us to grow as a global platform and they are causally linked with our success. We provide strategic and technical advice, and we have expertise in areas covering Artificial Intelligence, Cloud Migration, Custom Software Development, Data Analytics Infrastructure & Cloud Solutions, Cyber Security Services, etc. We make reasonable accommodations for clients and employees and we do not discriminate based on any protected attribute including race, religion, color, national origin, gender sexual orientation, gender identity, age, or marital status. We also are a Google Cloud partner company. We align strategy with execution and provide secure service solutions by developing and using the latest technologies that thrive our resources to deliver industry-leading capabilities to our clients and customers, making it convenient for our clients to do business with InterSources Inc. Our teams also drive growth by refining technology-driven client experiences that put the users first, providing an unparalleled experience. This results in strengthening the core technologies of clients, enabling them to scale with flexibility, create seamless digital experiences and build lifelong relationships.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Loading talks and stories from around this roleā¦