MDM/Endpoint Engineer

KDINFOTECH INC
Redwood City, United States of America
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Intermediate
Compensation
$ 130K

Job location

Redwood City, United States of America

Tech stack

Microsoft Windows
Microsoft Active Directory
Android
iOS
Apple Mac Systems
User Authentication
Bash
Data Integrity
Mobile Application Software
Python
Public Key Infrastructure
Powershell
Software Deployment
Scripting (Bash/Python/Go/Ruby)
Workspace ONE
Microsoft InTune
Deployment Automation
Casper Suite
GXP

Job description

As an MDM/Endpoint Engineer at KDI, you will be responsible for supporting and securing the full device lifecycle across our client's organization. This includes but is not limited to mobile device management, endpoint provisioning, patch and update management, endpoint security hardening, and support for devices operating in a regulated, validated-systems environment., * Administer and maintain MDM platforms (Jamf Pro, Microsoft Intune, Workspace ONE, or similar) across macOS, Windows, iOS, and Android fleets

  • Design and maintain zero-touch provisioning workflows (Apple Business Manager, Windows Autopilot) for new hire, lab, and shared-device enrollment
  • Build and enforce configuration profiles, compliance policies, and security baselines aligned with HIPAA, GxP, and other biohealth regulatory requirements
  • Manage patch, OS update, and application deployment cycles across the endpoint fleet
  • Monitor client and internal endpoint compliance and proactively resolve non-compliant or at-risk devices
  • Leverage automation and scripting to optimize enrollment, patching, reporting, and remediation workflows
  • Partner with Security and Compliance teams to support audits, risk assessments, and validation documentation for regulated devices and systems
  • Troubleshoot common endpoint hardware, OS, and MDM policy issues
  • Work with business process owners to write and implement device management policy, including access controls, data protection, and retention standards

Requirements

An ideal candidate is self-motivated and passionate about technology, and naturally curious. We are looking for someone who enjoys taking an outside-the-box approach to unique problems and who understands the added rigor that comes with managing endpoints in an environment where data integrity, privacy, and compliance are non-negotiable., * 3+ yrs. administering an MDM platform (Jamf Pro, Intune, Workspace ONE, or similar)

  • Experience managing both macOS and Windows endpoint fleets within a single environment
  • Windows administration/GPO management experience
  • Experience with Apple Business Manager / Windows Autopilot zero-touch provisioning
  • Working knowledge of Active Directory / Entra ID and endpoint identity and authentication
  • Scripting experience (Bash, Zsh, PowerShell, or Python) for automation and remediation
  • Familiarity with compliance frameworks relevant to biohealth/life sciences (HIPAA, GxP, etc…)
  • Excellent written and verbal communication skills
  • Ability to write and maintain technical documentation

Desired Skills

  • Experience supporting endpoints in a validated/regulated systems environment
  • Familiarity with mobile application management (MAM) and conditional access policies
  • Experience with endpoint security/EDR tooling and its integration with MDM platforms
  • Working knowledge of certificate-based authentication and PKI for device trust
  • Working knowledge of infrastructure-as-code or automation frameworks for endpoint provisioning

Benefits & conditions

Pulled from the full job description

  • Parental leave
  • 401(k)
  • Health insurance
  • Retirement plan
  • 401(k) matching
  • Paid time off
  • Vision insurance, * 401(k)
  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Life insurance
  • Paid time off
  • Parental leave
  • Retirement plan
  • Vision insurance

Apply for this position