Lead Endpoint Engineer

Jfc Global
Lancaster, United States of America
7 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 120K

Job location

Lancaster, United States of America

Tech stack

Microsoft Windows
JIRA
BitLocker Drive Encryption
HP Thin Clients
Azure
Software Deployment
Software Vulnerability Management
EndPointSecurity
Microsoft InTune
Deployment Automation
CIS Benchmarks
U-Boot

Job description

We are seeking a Lead Endpoint Engineer to own the design, deployment, security posture, and lifecycle management of end user devices across a multi-site manufacturing environment. This is an engineering and project execution role, not a ticket-only or break/fix role. You will lead endpoint initiatives end to end, partner closely with security and infrastructure teams, and drive standards through change management.This role is a backfill for a lead who was running major endpoint programs at scale (for example: large Windows 11 upgrades, mobile device and BYOD MDM design, Autopilot rollout, carrier migrations across 1,000+ devices, and security tooling ownership). We need someone who can step into that kind of ownership and keep the roadmap moving., * Own and improve Microsoft Intune configuration profiles, compliance policies, security baselines, and application deployment strategy.

  • Lead Autopilot enrollment and provisioning workflows (including shared device and specialized user group models).
  • Design and manage Windows update strategy (update rings, feature updates, quality updates, rollout controls, and remediation).
  • Drive endpoint standardization and hygiene across device populations (policy consistency, profile cleanup, scoping, documentation).

Endpoint security and vulnerability remediation

  • Own day to day endpoint security posture and remediation work tied to security findings and defined timelines.
  • Administer and tune endpoint security tools and policies (including Defender for Endpoint and Carbon Black App Control style allowlisting/approval workflows).
  • Maintain encryption and platform trust posture (BitLocker, Secure Boot related considerations, tamper protection, and policy enforcement).

Identity and access alignment (Entra ID / Conditional Access / SSO)

  • Support and improve endpoint-related identity integrations with Entra ID (Azure AD), Conditional Access alignment, and device-based access controls.
  • Assist with MFA initiatives and identity audits in partnership with security/infrastructure teams.

Thin clients and specialized manufacturing site devices

  • Support thin client management (including Dell/WYSE management tooling) and standards across manufacturing sites.
  • Help troubleshoot urgent incidents impacting operations, with focus on fast recovery and prevention through better engineering.

Change management and project leadership

  • Author and own changes through a formal change process (CAB), from design through implementation and validation.
  • Lead concurrent projects independently, drive timelines, and coordinate across teams.
  • Build and maintain runbooks, standards, and technical documentation (tools referenced include Jira Service Management).

Requirements

  • Strong hands on endpoint engineering background (not just service desk escalation).
  • Proven experience owning Intune at scale, including: configuration profiles, compliance, app deployment, Autopilot, and rollout strategy.
  • Solid endpoint security experience (Defender for Endpoint and similar tooling, remediation workflows, policy enforcement).
  • Experience supporting hybrid enterprise identity environments (AD + Entra ID concepts, device identity, access controls).
  • Comfort operating in a multi-site environment where onsite coordination and operational urgency matter.
  • Ability to lead, prioritize, and execute with minimal day to day task assignment.

Nice to have

  • Thin client management experience (WYSE / Dell WMS).
  • Manufacturing or production environment exposure (24/7 mindset, low downtime tolerance).
  • Experience leading large programs like OS upgrades, carrier migrations, or acquisition integrations.

Benefits & conditions

Pay: Up to $120,000.00 per year

Apply for this position