> Markdown version of [/jobs/ext/3619058-senior-windows-endpoint-engineer](https://www.wearedevelopers.com/jobs/ext/3619058-senior-windows-endpoint-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Windows Endpoint Engineer - **Company:** Intersources Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $26,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Application Packaging, Microsoft App-V, BitLocker Drive Encryption, Cloud Computing, Cloud Engineering, Configuration Management, Software Quality, Continuous Integration, Dynamic Host Configuration Protocol, Software Debugging, Domain Name System (DNS), Event Logging, Firmware, System Center Configuration Manager, Windows API, Public Key Infrastructure, Windows PowerShell, Windows Desktop, Policy as Code, Data Logging, Backend, Microsoft InTune, Deployment Automation, Bare Metal, Patch Management, Build Process, Graphql, CIS Benchmarks, Wsus, Windows Client - **Published:** October 8, 2026 - **Apply:** https://www2.jobdiva.com/portal/?a=62jdnw10t7d77ytz0lbaey9qxonk3b05a9tqw96rb7z6hlfo7xj79l9g6mp6aj2o&compid=0/jobs/33211669#/jobs/33211669 ## About the Role Reason for opening: Modernization and engineering ownership of the Windows desktop estate-driving end-to-end endpoint performance, security hardening, and transitioning workloads from on-premises ConfigMgr to cloud-native Microsoft Intune. Key deliverables: Architecting bare-metal and zero-touch deployment task sequences, migrating GPO/ConfigMgr workloads to Intune with parity validation, creating robust PowerShell remediation scripts, and optimizing patch management for remote users. Interview process stages: Multi-stage engineering interview focusing on hands-on task sequence authoring, PowerShell code quality/error handling, and real-world troubleshooting scenarios (logs, WMI, registry, driver/patch issues). NON-NEGOTIABLES Education: * Education: No specific degree explicitly required by client. 7+ years in Windows endpoint/desktop engineering owning build and configuration estates in complex environments. Deep hands-on ConfigMgr (SCCM) site administration, OSD task sequence authoring, driver customization, and USMT. Hands-on Intune engineering (Autopilot pre-provisioning, compliance, settings catalog, Win32 app delivery). Production-grade PowerShell automation (must include logging, error handling, idempotency, and code signing). Deep understanding of Windows client internals (Registry, WMI, Event Logs, setup logs, performance, profile behaviors) and supporting backend infrastructure (AD, Entra ID, DNS, DHCP, PKI, WSUS, LAPS). NICE-TO-HAVES Experience migrating ConfigMgr workloads to cloud management with full parity validation and on-premises retirement. Advanced automation experience using Microsoft Graph API, CI/CD for application packaging, or infrastructure as code. Microsoft certifications: MD-102 (Endpoint Administrator), SC-200, SC-100, or equivalent credentials. DISQUALIFIERS Candidates who are purely "console administrators" or Tier 1/2 desktop support technicians lacking hands-on build/engineering experience. Inability to write structured, production-grade PowerShell scripts (only relies on GUI tools or basic command lines). Lack of experience with bare-metal OS deployment, WinPE engineering, or task sequence debugging from raw logs., * Windows Endpoint / Desktop Engineering (7+ years) * Microsoft Configuration Manager / SCCM Engineering (5+ years) * Windows OS Deployment, Imaging, & Task Sequences (5+ years) * Microsoft Intune & Autopilot Engineering (3+ years) * Windows Update for Business (WUfB) & Cloud Patching (3+ years) * Advanced PowerShell Scripting & Automation (5+ years) * Group Policy (GPO) Architecture & ADMX Management (5+ years) * Application Packaging (MSI, Win32, MSIX) & App Delivery (5+ years) ADDITIONAL DESIRED SKILLS * Modernization experience migrating ConfigMgr workloads to Microsoft Intune * Zero-touch / Low-touch Autopilot pre-provisioning architecture * Windows Feature Update / OS migration programs at scale * Graph API, WMI-driven reporting, or Policy-as-Code automation * Experience in global, highly regulated, or enterprise environments (including VDI or shared devices) * Relevant Microsoft certifications (MD-102, MCSE, SC-200, or SC-100) ## Description The Senior Windows Endpoint Engineer owns the Windows client end-to-end, from bare-metal builds to the everyday user experience. This hands-on build engineering role is accountable for image and task sequence architecture in Microsoft Configuration Manager (SCCM), Group Policy, and Microsoft Intune cloud management, ensuring endpoints provision predictably, stay secure, and maintain optimal performance across their lifecycle., * Design, engineer, and troubleshoot Windows OS deployment across imaging, WinPE, task sequences, drivers, USMT, BitLocker, and firmware integration. * Manage Configuration Manager (ConfigMgr/SCCM) site health, roles, PXE, boot images, boundaries, client settings, collections, software updates, and co-management workloads. * Architect and implement Microsoft Intune capabilities, including Autopilot provisioning, settings catalogs, compliance policies, security baselines, and proactive remediations. * Own Windows cloud patch management using Windows Update for Business, Autopatch, update rings, deferrals, and expedited updates while optimizing bandwidth for remote sites. * Package and deploy cloud applications (Intune Win32, Microsoft Store, Enterprise App Catalog, M365 Apps) and legacy formats (MSI, MSIX, App-V) with reliable detection and dependencies. * Maintain, rationalize, and migrate Group Policy (GPO) architecture and ADMX central stores to Intune policy equivalents. * Build production-grade, idempotent, signed PowerShell scripts for automated provisioning, remediation, detection, and drift control. * Implement security hardening baselines including BitLocker, ASR rules, AppLocker/WDAC, Credential Guard, exploit protection, and local admin management (LAPS)., The ideal candidate is a seasoned, hands-on endpoint build engineer-not merely a console administrator-who takes full accountability for the desktop estate. They possess deep expertise in both traditional on-premises management (ConfigMgr, GPO) and modern cloud management (Intune, Autopilot, WUfB), driven by a strong automation-first mindset using production-grade PowerShell., * Own and author Windows OS deployment designs, task sequences, WinPE, driver packages, and Autopilot provisioning. * Engineer and maintain Configuration Manager and Microsoft Intune estates, managing co-management workloads and cloud transitions. * Design and manage cloud patching strategies utilizing Windows Update for Business, update rings, and expedited updates. * Develop production-grade, signed PowerShell scripts for automated device provisioning, drift control, and proactive remediations. * Maintain endpoint security baselines, including BitLocker, Attack Surface Reduction (ASR) rules, AppLocker/WDAC, and LAPS. * Rationalize legacy Group Policy (GPO) architecture and convert workloads to modern cloud policies.