Senior Microsoft Endpoint Management Engineer
All Lines Technology
About the position The Senior Microsoft Endpoint Management Engineer is responsible for designing, implementing, maintaining, and supporting enterprise endpoint management solutions using both Microsoft Endpoint Configuration Manager (MECM/SCCM) and...
Job description
Responsibilities
Design, implement, administer, and maintain MECM infrastructure, including site systems, boundaries, boundary groups, distribution points, and client settings.Monitor MECM health, performance, and availability; perform upgrades, hotfix installations, and environment maintenance.Design and maintain Windows 10/11 operating system deployment task sequences for bare-metal, refresh, and in-place upgrade scenarios.Manage boot images, driver repositories, deployment media, and PXE/task sequence troubleshooting.Package, test, deploy, and maintain enterprise applications using MSI, EXE, PowerShell, scripts, and establish detection methods, dependencies, supersedence, and deployment requirements.Manage Windows and third-party patching solutions, including deployment rings, maintenance windows, compliance monitoring, and remediation.Design, implement, and administer Microsoft Intune environments for Windows, macOS, iOS, and Android device management.Configure device enrollment, Microsoft Entra ID join, hybrid join, compliance policies, configuration profiles, device restrictions, and endpoint security policies.Design and implement Windows Autopilot scenarios, including user-driven, pre-provisioned, and self-deploying deployments.Configure Enrollment Status Page behavior, Autopilot profile assignments, and troubleshoot enrollment and provisioning issues.Package and deploy Win32, Microsoft Store, Microsoft 365 Apps, and line-of-business applications; manage application lifecycle and update processes.Configure and maintain security baselines, BitLocker management, Endpoint Privilege Management, Microsoft Defender integration, and Conditional Access integration.Design and implement MECM/Intune co-management solutions and migrate workloads between MECM and Intune.Develop endpoint modernization roadmaps that guide customers from traditional device management to cloud-native management.Assess customer endpoint environments and recommend best-practice architectures for modern management, compliance, and security.Lead technical workshops, design sessions, implementation efforts, and customer-facing endpoint management projects.Develop PowerShell scripts for endpoint automation, administration, reporting, and remediation.Integrate endpoint management workflows with Microsoft Graph API where applicable.Create and maintain technical documentation, SOPs, runbooks, architecture diagrams, and implementation guides.Develop reports using MECM, Intune, Power BI, SQL, and Microsoft reporting tools to track deployment success, compliance, and endpoint metrics.Provide Tier 3 escalation support and mentor junior engineers or support staff.Requirements
5+ years of hands-on experience administering MECM/SCCM in enterprise environments.5+ years of hands-on experience administering Microsoft Intune.Strong experience with Windows 10 and Windows 11 deployment, management, and troubleshooting.Experience with operating system deployment, application packaging/deployment, patch management, endpoint security, and device compliance.Strong understanding of Microsoft Entra ID, Active Directory, Group Policy, DNS, DHCP, and PKI/certificates.Advanced PowerShell scripting and automation experience.Experience implementing MECM and Intune co-management.Strong troubleshooting, communication, documentation, and customer-facing consulting skills.Nice-to-haves
Experience with Microsoft Defender for Endpoint, Defender XDR, Microsoft Cloud PKI, Endpoint Privilege Management, and Microsoft security baselines.Experience with Microsoft Graph API, Power BI reporting, tenant-to-tenant migrations, endpoint modernization projects, and third-party patching solutions.Experience supporting SMB, education, healthcare, government, or enterprise organizations.Ability to lead discovery sessions, translate technical needs into project scopes, and present recommendations to customers and internal stakeholders.MD-102: Endpoint Administrator AssociateMS-102: Microsoft 365 Administrator ExpertSC-300: Identity and Access AdministratorAZ-104: Azure Administrator Associate