Lead Endpoint Engineer
Role details
Job location
Tech stack
Job description
We are seeking a Lead Endpoint Engineer to own the design, deployment, security posture, and lifecycle management of end user devices across a multi-site manufacturing environment. This is an engineering and project execution role, not a ticket-only or break/fix role. You will lead endpoint initiatives end to end, partner closely with security and infrastructure teams, and drive standards through change management.This role is a backfill for a lead who was running major endpoint programs at scale (for example: large Windows 11 upgrades, mobile device and BYOD MDM design, Autopilot rollout, carrier migrations across 1,000+ devices, and security tooling ownership). We need someone who can step into that kind of ownership and keep the roadmap moving., * Own and improve Microsoft Intune configuration profiles, compliance policies, security baselines, and application deployment strategy.
- Lead Autopilot enrollment and provisioning workflows (including shared device and specialized user group models).
- Design and manage Windows update strategy (update rings, feature updates, quality updates, rollout controls, and remediation).
- Drive endpoint standardization and hygiene across device populations (policy consistency, profile cleanup, scoping, documentation).
Endpoint security and vulnerability remediation
- Own day to day endpoint security posture and remediation work tied to security findings and defined timelines.
- Administer and tune endpoint security tools and policies (including Defender for Endpoint and Carbon Black App Control style allowlisting/approval workflows).
- Maintain encryption and platform trust posture (BitLocker, Secure Boot related considerations, tamper protection, and policy enforcement).
Identity and access alignment (Entra ID / Conditional Access / SSO)
- Support and improve endpoint-related identity integrations with Entra ID (Azure AD), Conditional Access alignment, and device-based access controls.
- Assist with MFA initiatives and identity audits in partnership with security/infrastructure teams.
Thin clients and specialized manufacturing site devices
- Support thin client management (including Dell/WYSE management tooling) and standards across manufacturing sites.
- Help troubleshoot urgent incidents impacting operations, with focus on fast recovery and prevention through better engineering.
Change management and project leadership
- Author and own changes through a formal change process (CAB), from design through implementation and validation.
- Lead concurrent projects independently, drive timelines, and coordinate across teams.
- Build and maintain runbooks, standards, and technical documentation (tools referenced include Jira Service Management).
Requirements
- Strong hands on endpoint engineering background (not just service desk escalation).
- Proven experience owning Intune at scale, including: configuration profiles, compliance, app deployment, Autopilot, and rollout strategy.
- Solid endpoint security experience (Defender for Endpoint and similar tooling, remediation workflows, policy enforcement).
- Experience supporting hybrid enterprise identity environments (AD + Entra ID concepts, device identity, access controls).
- Comfort operating in a multi-site environment where onsite coordination and operational urgency matter.
- Ability to lead, prioritize, and execute with minimal day to day task assignment.
Nice to have
- Thin client management experience (WYSE / Dell WMS).
- Manufacturing or production environment exposure (24/7 mindset, low downtime tolerance).
- Experience leading large programs like OS upgrades, carrier migrations, or acquisition integrations.
Benefits & conditions
Pay: Up to $120,000.00 per year