Lead Endpoint Engineer
JFC Global
Lead Endpoint Engineer Location: Lancaster, PA (Hybrid, typically 2 to 3 days onsite) Type: Direct Hire Summary We are seeking a Lead Endpoint Engineer to own the design, deployment, security posture, and lifecycle management of end user devices across a...
Job description
What you will do
Modern endpoint management (Intune / Autopilot / Windows lifecycle)
Own and improve Microsoft Intune configuration profiles, compliance policies, security baselines, and application deployment strategy.
Lead Autopilot enrollment and provisioning workflows (including shared device and specialized user group models).
Design and manage Windows update strategy (update rings, feature updates, quality updates, rollout controls, and remediation).
Drive endpoint standardization and hygiene across device populations (policy consistency, profile cleanup, scoping, documentation).
Endpoint security and vulnerability remediation
Own day to day endpoint security posture and remediation work tied to security findings and defined timelines.
Administer and tune endpoint security tools and policies (including Defender for Endpoint and Carbon Black App Control style allowlisting/approval workflows).
Maintain encryption and platform trust posture (BitLocker, Secure Boot related considerations, tamper protection, and policy enforcement).
Identity and access alignment (Entra ID / Conditional Access / SSO)
Support and improve endpoint-related identity integrations with Entra ID (Azure AD), Conditional Access alignment, and device-based access controls.
Assist with MFA initiatives and identity audits in partnership with security/infrastructure teams.
Thin clients and specialized manufacturing site devices
Support thin client management (including Dell/WYSE management tooling) and standards across manufacturing sites.
Help troubleshoot urgent incidents impacting operations, with focus on fast recovery and prevention through better engineering.
Change management and project leadership
Author and own changes through a formal change process (CAB), from design through implementation and validation.
Lead concurrent projects independently, drive timelines, and coordinate across teams.
Build and maintain runbooks, standards, and technical documentation (tools referenced include Jira Service Management).
What we are looking for
Strong hands on endpoint engineering background (not just service desk escalation).
Proven experience owning Intune at scale, including: configuration profiles, compliance, app deployment, Autopilot, and rollout strategy.
Solid endpoint security experience (Defender for Endpoint and similar tooling, remediation workflows, policy enforcement).
Experience supporting hybrid enterprise identity environments (AD + Entra ID concepts, device identity, access controls).
Comfort operating in a multi-site environment where onsite coordination and operational urgency matter.
Ability to lead, prioritize, and execute with minimal day to day task assignment.
Nice to have
Thin client management experience (WYSE / Dell WMS).
Manufacturing or production environment exposure (24/7 mindset, low downtime tolerance).
Experience leading large programs like OS upgrades, carrier migrations, or acquisition integrations.
Apply now for immediate consideration!
Direct W2 only
EOE
INDIT
Pay: Up to $120,000.00 per year
Work Location: Hybrid remote in Lancaster, PA 17608