Endpoint Jobs
SerpAPI Google Jobs

Endpoint Management Engineer

Encore Technologies

Description Position Summary The Endpoint Management Engineer is responsible for the design, deployment, security, and ongoing operation of the endpoint management platforms Encore Technologies uses to manage client device estates. This is a...

Role overview

Job description

The role owns the full endpoint lifecycle zero-touch provisioning, application packaging and delivery, patch and vulnerability remediation, security baseline enforcement, telemetry and reporting, and secure device retirement. The engineer is expected to work automation-first, using PowerShell, Microsoft Graph, and native platform scripting to eliminate manual effort, and to lead modernization efforts such as co-management, Configuration Manager to Intune migration, and RMM platform consolidation during client transitions.

This position serves as the senior technical escalation point for endpoint issues raised by the Service Desk, ITOCC, and On-Site Support teams, and partners with Security Operations, client stakeholders, and Encore delivery leadership to translate business and compliance requirements into scalable, well-documented endpoint standards.

Responsibilities:

· Platform Administration – Design, deploy, configure, and maintain endpoint management platforms including Microsoft Intune, Microsoft Configuration Manager (MECM), NinjaOne, and HCL BigFix across single-tenant and multi-tenant client environments.

· Zero-Touch Provisioning – Build and maintain modern provisioning workflows using Windows Autopilot, Apple Business Manager and Automated Device Enrollment, and Android Enterprise, reducing image-based build effort and shortening device delivery timelines.

· Application Packaging and Delivery – Package, test, publish, and version control enterprise applications (Win32, MSIX, MSI, Winget, Homebrew, PKG) with defined detection rules, dependencies, supersedence, and rollback paths.

· Patch and Vulnerability Remediation – Own operating system and third-party patch cycles across all managed platforms, coordinate maintenance windows using ring-based deployment, and remediate findings surfaced by vulnerability management tooling within contracted SLAs.

· Security Baseline Enforcement – Implement and maintain ‘hardening’ baselines and compliance policies (CIS Benchmarks, Microsoft Security Baselines, NIST) including disk encryption, attack surface reduction, application control, local administrator management, endpoint detection and agent health.

· Identity and Access Integration – Configure device compliance, Conditional Access policies, certificate and Wi-Fi/VPN profile delivery in partnership with the identity team, ensuring endpoint posture is a trusted signal in access decisions.

· Automation and Scripting – Develop and maintain PowerShell, Bash, Microsoft Graph API automations, Intune remediation scripts, tool specific scripting (Ex. BigFix custom scripting) to automate deployments, configuration drift correction, and reporting.

· Endpoint Health and Digital Employee Experience – Monitor agent health, policy compliance, and device performance telemetry; use DEX data to proactively identify and resolve endpoint issues before they generate tickets.

· Platform Migration and Modernization – Lead endpoint workstreams during client transitions and modernization projects, including co-management enablement, Configuration Manager to Intune workload migration, tenant-to-tenant moves, and RMM platform consolidation.

· Multi-Tenant Governance – Configure and maintain role-based access control, scope tags, organizational units, policy naming standards, and change control across client tenants to protect data separation and enforce least privilege.

· Technical Escalation – Serve as tier-3 escalation for endpoint incidents and problems raised by the Service Desk, ITOCC, and field teams; perform root cause analysis and drive permanent corrective action.

· ITSM and Change Management – Integrate endpoint platforms with ITSM tooling for asset, incident, and request automation, and submit endpoint changes through the established change management process with tested back-out plans.

· Reporting and Client Reviews – Produce compliance, patch, and lifecycle reporting for internal leadership and client business reviews, translating platform telemetry into clear risk and health narratives.

· Documentation and Enablement – Maintain run books, standard operating procedures, and configuration-as-documented records for every managed platform, and transfer knowledge to Service Desk and field teams through training and knowledge base content.

· Technology Evaluation – Track vendor roadmaps and emerging endpoint capabilities, evaluate new tooling against Encore service standards, and recommend improvements that reduce cost, risk, or manual effort.

Qualifications:

· Bachelor’s degree in Computer Science, Information Technology, or a related field, or equivalent work experience.

· Minimum of 5 years of hands-on endpoint management experience in enterprise or managed services environments.

· Demonstrated production experience with at least two enterprise endpoint management platforms, such as Microsoft Intune, Microsoft Configuration Manager, NinjaOne, HCL BigFix, Tanium, Jamf, or Workspace ONE.

· Working knowledge of modern Windows management, including Autopilot, co-management, Windows Update for Business, and Windows Update rings.

· Experience managing non-Windows endpoints, including macOS and iOS/Android mobile device and application management.

· Strong scripting and automation skills in PowerShell, with working knowledge of Microsoft Graph API; Bash or Python experience is a plus.

· Solid understanding of Microsoft Entra ID, Active Directory, Group Policy, certificate services, and Conditional Access.

· Practical experience with endpoint security tooling and hardening standards, including Microsoft Defender for Endpoint, disk encryption, privilege management, and CIS or NIST baselines.

· Application packaging and software distribution experience across multiple formats and platforms.

· Familiarity with ITSM practices and platforms, including incident, problem, and change management workflows.

· Excellent analytical and troubleshooting skills, with the ability to isolate complex issues across identity, network, application, and device layers.

· Effective written and verbal communication skills, with the ability to work across cross-functional teams and explain technical concepts to non-technical stakeholders.

· Preferred certifications: Microsoft 365 Certified: Endpoint Administrator Associate (MD-102), Microsoft Certified: Identity and Access Administrator Associate, CompTIA Security+, Apple Certified Support Professional, ITIL 4 Foundation, or platform-specific NinjaOne or BigFix certifications.

· Prior experience in a managed service provider or multi-client environment is strongly preferred.

Physical Requirements:

· Prolonged periods sitting at a desk and working on the computer.

· Occasional lifting, pushing, and pulling up to 15 lbs.

· Hybrid position: in-office and remote workdays.

· Occasional travel to client sites within the greater Cincinnati and Northern Kentucky region.

· Participation in a scheduled on-call rotation and periodic after-hours maintenance windows.