Quick Overview
Job Description
Position Overview:
The Senior Endpoint Platform Engineer will design, implement, and operate secure, scalable enterprise endpoint management platforms. This role combines deep endpoint engineering expertise with operational judgment, governance awareness, automation, observability, and data-driven decision making. The engineer will independently lead initiatives, navigate ambiguity, balance security requirements with operational realities, and build sustainable platform capabilities that can be adopted across teams and business units.
Hybrid onsite 3x a week
Responsibilities:
• Design, implement, and operate enterprise endpoint management services using Microsoft Intune and Microsoft Configuration Manager (MECM/SCCM).
• Develop and maintain Windows endpoint standards, including Windows Autopilot, Endpoint Analytics, compliance policies, configuration profiles, and Windows Update for Business.
• Engineer scalable processes for Win32 application packaging and deployment, as well as driver, BIOS, and firmware management.
• Design identity and administration models using Microsoft Entra ID, Identity Governance, Privileged Identity Management (PIM), Access Packages, role-based access control (RBAC), delegated administration, Scope Tags, and least-privilege principles.
• Build reusable automation and configuration-as-code solutions using PowerShell, Python, Microsoft Graph, REST APIs, GitHub Actions, JSON, and YAML.
• Apply Infrastructure as Code, automated testing, and documentation-as-code practices to endpoint platform engineering and operations.
• Define telemetry strategies and instrumentation that support service observability, operational health measurement, and data-driven decision making.
• Develop dashboards, reports, monitoring, and alerts using Azure Monitor, Log Analytics, Kusto Query Language (KQL), Splunk Enterprise, and Splunk Search Processing Language (SPL).
• Lead complex troubleshooting and root cause analysis for endpoint platform, application deployment, compliance, identity, and operational issues.
• Implement and maintain vulnerability management, security baselines, hardening standards, Zero Trust principles, change controls, and auditable operating practices.
• Assess tradeoffs, blast radius, resiliency, and risk when designing or changing endpoint services.
• Document architecture decisions, technical rationale, support procedures, and long-term ownership models.
• Partner across engineering, governance, security, operations, and leadership teams to align platform outcomes with business objectives.
• Communicate complex technical topics clearly to technical and non-technical stakeholders, including executive audiences.
• Enable other teams through standards, automation, reusable capabilities, and knowledge transfer rather than creating operational dependencies.
• Demonstrate ownership from solution design through implementation and operational support.
Qualifications:
Required Qualifications
• Senior-level experience designing, implementing, and operating enterprise endpoint management platforms at scale.
• Deep hands-on experience with Microsoft Intune, MECM/SCCM, Windows endpoint management, Windows Autopilot, Endpoint Analytics, compliance and configuration management, Win32 application deployment, Windows Update for Business, and hardware lifecycle management.
• Experience designing enterprise identity governance and delegated administration models using Microsoft Entra ID, PIM, Access Packages, RBAC, Scope Tags, and least-privilege practices.
• Advanced automation and scripting experience with PowerShell and working experience with Python, Microsoft Graph, REST APIs, GitHub Actions, JSON, and YAML.
• Experience applying Infrastructure as Code, Configuration as Code, automated testing, and documentation-as-code concepts.
• Experience designing telemetry, dashboards, reporting, monitoring, and alerting using Azure Monitor, Log Analytics, KQL, Splunk Enterprise, or SPL.
• Strong knowledge of vulnerability management, security baselines, endpoint hardening, Zero Trust, change control, auditability, and risk-based prioritization.
• Demonstrated ability to work independently, navigate ambiguity, challenge assumptions with evidence, and balance business, operational, and security requirements.
• Strong analytical, troubleshooting, documentation, and communication skills.
• Proven ability to build maintainable, supportable, and scalable platforms rather than one-time solutions.
Preferred Qualifications
• Experience leading large-scale endpoint migrations or MECM-to-Intune transformations.
• Experience supporting shared-service or multi-business-unit environments.
• Experience developing governance models, operating models, and enterprise platform standards.
• Experience establishing service observability and operational reporting for endpoint platforms.
• Experience engaging cross-functional stakeholders and influencing technical and executive audiences.
Tools and Technologies:
• Microsoft Intune
• Microsoft Configuration Manager (MECM/SCCM)
• Windows endpoint management
• Windows Autopilot
• Endpoint Analytics
• Windows Update for Business
• Microsoft Entra ID
• Identity Governance
• Privileged Identity Management (PIM)
• Access Packages
• RBAC and Scope Tags
• PowerShell
• Python
• Microsoft Graph
• REST APIs
• GitHub Actions
• JSON and YAML
• Infrastructure as Code
• Configuration as Code
• Azure Monitor
• Log Analytics
• Kusto Query Language (KQL)
• Splunk Enterprise
• Splunk Search Processing Language (SPL)
• Vulnerability management and security baselines
• Zero Trust
Similar jobs
- ST
Azure Platform Engineer
NewSun Technologies,Inc.
Johns Creek, GA🇺🇸$50 - $65/hrHybrid21 hours agoSQLEncryptionAzure+4Technology - BA
DevSecOps Engineer
NewBooz Allen Hamilton
McLean, VA🇺🇸$77.6k - $176k/yrOn-site21 hours agoEngineering - EG
AI Application Engineer .NET/Java + DevOps + Cloud
NewEnexus Global
Austin, TX🇺🇸Hybrid21 hours agoAWSC#.NET+5Technology - BS
DevOps Engineer || Hybrid - New York || 12+ Years Experience must
NewBright Sol
New York, NY🇺🇸Hybrid21 hours agoDockerAWSEncryption+9Technology - NG
Sr. Principal Network Engineer with Security Clearance
NewNorthrop Grumman
Orlando, FL🇺🇸$111.7k - $167.5k/yrHybrid21 hours agoEncryptionTCP/IPiOSTechnology - IU
SmartReach / LiveVox Platform Engineer
NewIBOTIX US Inc.
Baltimore, MD🇺🇸On-site21 hours agoSQLSSOSnowflakeTechnology