Senior Endpoint Client Engineer
AirZap
Senior Endpoint Client Engineer: This position is responsible for the design, implementation, administration, and third-level operational support of enterprise endpoint computing platforms and services. The role focuses on Microsoft Intune, Microsoft...
Job description
Key Responsibilities
Serve as a senior technical engineer for enterprise endpoint management platforms, ensuring availability, security, performance, and operational reliability. Design, implement, and maintain endpoint management solutions for Windows, iOS, and Android devices. Perform lifecycle management activities including operating system upgrades, software packaging and deployment, patching, hardware refreshes, and endpoint provisioning. Administer enterprise mobile device management (MDM) and mobile application management (MAM) platforms. Manage endpoint compliance policies, security baselines, configuration profiles, and enforcement controls. Implement and support modern device management capabilities, including Windows Autopilot and zero-touch provisioning. Develop and maintain automated endpoint deployment, configuration, remediation, and reporting processes utilizing PowerShell and other automation technologies. Coordinate endpoint-related maintenance and change activities with business units, application owners, security teams, and infrastructure teams. Monitor endpoint platform health, compliance metrics, and security posture; proactively identify and remediate operational and security risks. Participate in incident response, root cause analysis, troubleshooting, and remediation of endpoint-related issues. Develop, maintain, and follow operational runbooks, standards, and standard operating procedures. Provide technical guidance and operational support for endpoint security, device management, vulnerability management, and end-user computing initiatives. Participate in after-hours maintenance activities and troubleshooting events. Experience working in an agile environment.
Core Technologies
Microsoft Intune Endpoint ManagementMicrosoft Configuration Manager (MECM/SCCM)Windows Autopilot and Modern Device ProvisioningMicrosoft Entra ID Device ManagementConditional Access and Device ComplianceWindows 11 Enterprise AdministrationApple iOS/iPadOS Device ManagementApple Business ManagerEndpoint Security and Vulnerability ManagementEndpoint Software Packaging and DeploymentEndpoint Configuration and Compliance ManagementMobile Device Management (MDM) and Mobile Application Management (MAM)Endpoint Analytics and Device Health MonitoringPowerShell Automation and Endpoint Orchestration
Qualifications
Bachelor’s degree in computer science, Information Technology, or a related field, or equivalent practical experience. Minimum of 7+ years of experience in endpoint engineering, systems administration, or enterprise endpoint operations in a corporate or enterprise IT environment. In-depth knowledge and hands-on experience administering Microsoft Intune in enterprise environments, including device enrollment, compliance policies, application deployment, endpoint security management, and reporting. Demonstrated experience implementing and supporting Windows Autopilot provisioning and modern endpoint management strategies. Strong hands-on experience administering Microsoft Configuration Manager (MECM/SCCM) for software deployment, operating system deployment, patch management, and endpoint administration. Strong understanding of Microsoft Entra ID device registration, hybrid identity environments, Conditional Access policies, and compliance enforcement. Experience administering Apple Business Manager and enterprise Apple device enrollment programs. Strong experience managing Windows 11 enterprise environments, endpoint security configurations, and device lifecycle management. Knowledge of Zero Trust security principles as applied to endpoint management and device security. Experience creating scripts and automation solutions using PowerShell or similar technologies. Thorough understanding of endpoint compliance, vulnerability management, patch management, and security best practices. Proven ability to troubleshoot complex endpoint issues spanning operating systems, applications, identity services, security controls, and device management platforms. Experience working within change management, incident management, and agile environments. Strong written and verbal communication skills with the ability to collaborate across technical and non-technical teams. Travel to Ashburn, VA, Washington, DC, or other regional offices as required.
Estimated Length
6 months with possible extension.