Endpoint Engineer - Intune
Role details
Job location
Tech stack
Job description
Experteer Overview In this role you design, automate, and operate an enterprise device management platform supporting a global workforce. You will own hands-on engineering across Intune and SCCM in a co-management setup, with Hybrid Entra ID joined endpoints and a multi-platform estate. You write production-grade scripts and leverage Graph API for automation, while upholding strict compliance in a regulated pharma environment. You partner with security, networking, and site IT to advance modern management and secure, cloud-first policy delivery. Compensation / Benefits * Design, write, and maintain production-quality PowerShell for endpoint provisioning, configuration enforcement, and remediation * Write and maintain macOS shell scripts for configuration and delivery via Intune * Build and manage Intune Remediations to detect and self-heal configuration drift * Automate platform operations against Microsoft Graph API for device and policy tasks * Apply engineering discipline to automation assets: source control, logging, error handling, idempotency, controlled release * Convert manual/Service Desk tasks into automated or self-service capabilities * Engineer and maintain Intune compliance policies across platforms * Manage configuration profiles, settings catalogs, and templates for Windows, macOS, iOS/iPadOS, Android * Handle Windows Update for Business, update rings, and patch governance in Configuration Manager * Package, test, and deploy applications across platforms with correct detection, dependencies, and assignment logic * Implement and maintain security baselines (Microsoft, CIS, DISA STIG) with drift tracking * Administer the Configuration Manager hierarchy and OS deployments * Manage non-standard Windows endpoints with tailored collections and documented deviations * Configure identity and conditional access in Entra ID and on-prem AD, including workload transitions to Intune * Support macOS SSO with Entra ID and Enterprise SSO plug-in * Familiarize with Zero Trust tools (Zscaler) and endpoint security (Defender, BitLocker, FileVault) * Deploy certificate and Wi-Fi profiles across platforms * Define endpoint management KPIs and build dashboards using Intune, SCCM, SQL, Log Analytics, Graph data, and PowerBI * Leverage AI-assisted tooling to accelerate script development, log analysis, and reporting * Follow formal change management, support GxP endpoints, and maintain documentation * Participate in on-call rotation for critical endpoint incidents and maintenance Tasks * Bachelor's degree in relevant field or equivalent experience * Minimum 3 years with Microsoft Configuration Manager (SCCM/MECM) in enterprise * Minimum 3 years with Microsoft Intune including policies, baselines, and deployment * Proficiency writing and maintaining PowerShell for automation and reporting * Experience with Microsoft Graph API for automation or reporting * Experience with Intune and Configuration Manager co-management, workload transition, Hybrid Entra ID join * Hands-on experience managing at least two non-Windows platforms in Intune (macOS, iOS/iPadOS, Android) * Knowledge of Entra ID, Conditional Access, Active Directory, and PKI/certificates * Experience deploying/troubleshooting endpoint security and network access agents (e.g., Zscaler, CrowdStrike) * Experience with endpoint reporting/analytics and dashboards (Intune, Nexthink) * Familiarity with AI-assisted development tools for script/policy development * Experience with change management, incident management, and documentation standards * Strong analytical and troubleshooting skills across identity, network, policy, and endpoint domains Key requirements * Medical, dental & vision * 401(k) plan * Life保险(Voluntary) * Disability coverage * HSA * Time Off/Leave
Requirements
Zero Trust tools (Zscaler) and endpoint security (Defender, BitLocker, FileVault) * Deploy certificate and Wi-Fi profiles across platforms * Define endpoint management KPIs and build dashboards using Intune, SCCM, SQL, Log Analytics, Graph data, and PowerBI * Leverage AI-assisted tooling to accelerate script development, log analysis, and reporting * Follow formal change management, support GxP endpoints, and maintain documentation * Participate in on-call rotation for critical endpoint incidents and maintenance Tasks * Bachelor's degree in relevant field or equivalent experience * Minimum 3 years with Microsoft Configuration Manager (SCCM/MECM) in enterprise * Minimum 3 years with Microsoft Intune including policies, baselines, and deployment * Proficiency writing and maintaining PowerShell for automation and reporting * Experience with Microsoft Graph API for automation or reporting * Experience with Intune and Configuration Manager co-management, workload transition, Hybrid Entra ID join * Hands-on experience managing at least two non-Windows platforms in Intune (macOS, iOS/iPadOS, Android) * Knowledge of Entra ID, Conditional Access, Active Directory, and PKI/certificates * Experience deploying/troubleshooting endpoint security and network access agents (e.g., Zscaler, CrowdStrike) * Experience with endpoint reporting/analytics and dashboards (Intune, Nexthink) * Familiarity with AI-assisted development tools for script/policy development * Experience with change management, incident management, and documentation standards * Strong analytical and troubleshooting skills across identity, network, policy, and endpoint domains Key requirements * Medical, dental & vision * 401(k) plan * Life保险(Voluntary) * Disability coverage * HSA * Time Off/Leave