Haystack
← Back to Jobs
Technology
CD

Sr. Endpoint Platform Engineer

Cloud Destinations LLCIndianapolis, IN🇺🇸United StatesPosted Sep 18, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Indianapolis, IN, United States
Posted
21 hours ago
SplunkAzureGitHub ActionsPowerShellPythonRESTZero Trust

Job Description

Position Overview:

The Senior Endpoint Platform Engineer will design, implement, and operate secure, scalable enterprise endpoint management platforms. This role combines deep endpoint engineering expertise with operational judgment, governance awareness, automation, observability, and data-driven decision making. The engineer will independently lead initiatives, navigate ambiguity, balance security requirements with operational realities, and build sustainable platform capabilities that can be adopted across teams and business units.

Hybrid onsite 3x a week

Responsibilities:

• Design, implement, and operate enterprise endpoint management services using Microsoft Intune and Microsoft Configuration Manager (MECM/SCCM).

• Develop and maintain Windows endpoint standards, including Windows Autopilot, Endpoint Analytics, compliance policies, configuration profiles, and Windows Update for Business.

• Engineer scalable processes for Win32 application packaging and deployment, as well as driver, BIOS, and firmware management.

• Design identity and administration models using Microsoft Entra ID, Identity Governance, Privileged Identity Management (PIM), Access Packages, role-based access control (RBAC), delegated administration, Scope Tags, and least-privilege principles.

• Build reusable automation and configuration-as-code solutions using PowerShell, Python, Microsoft Graph, REST APIs, GitHub Actions, JSON, and YAML.

• Apply Infrastructure as Code, automated testing, and documentation-as-code practices to endpoint platform engineering and operations.

• Define telemetry strategies and instrumentation that support service observability, operational health measurement, and data-driven decision making.

• Develop dashboards, reports, monitoring, and alerts using Azure Monitor, Log Analytics, Kusto Query Language (KQL), Splunk Enterprise, and Splunk Search Processing Language (SPL).

• Lead complex troubleshooting and root cause analysis for endpoint platform, application deployment, compliance, identity, and operational issues.

• Implement and maintain vulnerability management, security baselines, hardening standards, Zero Trust principles, change controls, and auditable operating practices.

• Assess tradeoffs, blast radius, resiliency, and risk when designing or changing endpoint services.

• Document architecture decisions, technical rationale, support procedures, and long-term ownership models.

• Partner across engineering, governance, security, operations, and leadership teams to align platform outcomes with business objectives.

• Communicate complex technical topics clearly to technical and non-technical stakeholders, including executive audiences.

• Enable other teams through standards, automation, reusable capabilities, and knowledge transfer rather than creating operational dependencies.

• Demonstrate ownership from solution design through implementation and operational support.

Qualifications:

Required Qualifications

• Senior-level experience designing, implementing, and operating enterprise endpoint management platforms at scale.

• Deep hands-on experience with Microsoft Intune, MECM/SCCM, Windows endpoint management, Windows Autopilot, Endpoint Analytics, compliance and configuration management, Win32 application deployment, Windows Update for Business, and hardware lifecycle management.

• Experience designing enterprise identity governance and delegated administration models using Microsoft Entra ID, PIM, Access Packages, RBAC, Scope Tags, and least-privilege practices.

• Advanced automation and scripting experience with PowerShell and working experience with Python, Microsoft Graph, REST APIs, GitHub Actions, JSON, and YAML.

• Experience applying Infrastructure as Code, Configuration as Code, automated testing, and documentation-as-code concepts.

• Experience designing telemetry, dashboards, reporting, monitoring, and alerting using Azure Monitor, Log Analytics, KQL, Splunk Enterprise, or SPL.

• Strong knowledge of vulnerability management, security baselines, endpoint hardening, Zero Trust, change control, auditability, and risk-based prioritization.

• Demonstrated ability to work independently, navigate ambiguity, challenge assumptions with evidence, and balance business, operational, and security requirements.

• Strong analytical, troubleshooting, documentation, and communication skills.

• Proven ability to build maintainable, supportable, and scalable platforms rather than one-time solutions.

Preferred Qualifications

• Experience leading large-scale endpoint migrations or MECM-to-Intune transformations.

• Experience supporting shared-service or multi-business-unit environments.

• Experience developing governance models, operating models, and enterprise platform standards.

• Experience establishing service observability and operational reporting for endpoint platforms.

• Experience engaging cross-functional stakeholders and influencing technical and executive audiences.

Tools and Technologies:

• Microsoft Intune

• Microsoft Configuration Manager (MECM/SCCM)

• Windows endpoint management

• Windows Autopilot

• Endpoint Analytics

• Windows Update for Business

• Microsoft Entra ID

• Identity Governance

• Privileged Identity Management (PIM)

• Access Packages

• RBAC and Scope Tags

• PowerShell

• Python

• Microsoft Graph

• REST APIs

• GitHub Actions

• JSON and YAML

• Infrastructure as Code

• Configuration as Code

• Azure Monitor

• Log Analytics

• Kusto Query Language (KQL)

• Splunk Enterprise

• Splunk Search Processing Language (SPL)

• Vulnerability management and security baselines

• Zero Trust

Similar jobs