Systems Engineer - Endpoint Automation & Management
Pioneer Technology
The Systems Engineer is responsible for engineering, standardizing, automating, and maintaining Windows endpoint environments across our managed customer base. This role owns the platforms and processes used to monitor, configure, patch, secure, and...
Job description
This is not primarily a traditional help desk or desktop support position. The focus is to reduce manual work and recurring issues by creating reliable standards, reusable automation, measurable controls, and repeatable deployment processes. The engineer will also serve as an escalation resource when endpoint issues expose gaps in our tooling, standards, or automation.
Core Responsibilities:
RMM Platform Ownership
• Own the administration, health, and continuous improvement of the company’s RMM platform across customer environments.
• Design and maintain standardized policies for monitoring, alerting, patching, agent health, software deployment, and automated remediation.
• Audit newly onboarded and existing environments against established standards and develop practical remediation plans.
• Identify recurring technician work and convert it into reliable RMM automation wherever practical.
• Maintain dashboards and reporting that provide visibility into endpoint health, patch compliance, failed jobs, and unmanaged or non-reporting devices.
PowerShell Automation and Software Deployment
• Design, test, and maintain production-ready PowerShell scripts for software deployment, configuration, auditing, remediation, and reporting across large numbers of endpoints.
• Build reusable deployment packages that support unattended installation, detection logic, version control, rollback or recovery planning, logging, and clear exit codes.
• Use pilot groups and phased rollouts to validate changes before broad deployment across customer environments.
• Develop scripts that safely handle different Windows versions, hardware platforms, customer configurations, and systems that may be intermittently connected.
• Maintain a controlled script library with documentation, change history, testing requirements, error handling, and support ownership.
Endpoint Management and Standardization
• Establish and maintain company standards for workstations, including operating system configuration, required applications, security settings, browsers, utilities, and support tools.
• Reduce unnecessary configuration differences between customers while allowing for legitimate business and application requirements.
• Develop repeatable workstation deployment, replacement, and lifecycle processes that minimize manual technician effort.
• Evaluate whether software and configuration changes should be delivered through RMM, Microsoft Intune, Windows Autopilot, WinGet, Microsoft Store, or another approved platform.
Microsoft Intune and Entra ID
• Support Microsoft Entra joined and hybrid joined Windows environments and help customers move toward modern cloud-managed endpoint practices.
• Develop and maintain Windows Autopilot standards, enrollment profiles, Enrollment Status Pages, device groups, and repeatable deployment processes.
• Troubleshoot enrollment, synchronization, compliance, application deployment, identity, and policy issues.
• Evaluate new Microsoft endpoint management capabilities and recommend how they should be incorporated into company standards.
Patching, Security, and Endpoint Health
• Own the workstation patch management strategy across managed customers, including deployment rings, schedules, reboot policies, maintenance windows, compliance reporting, and failed-update remediation.
• Manage Windows feature update and end-of-support upgrade strategies using controlled, phased rollouts.
• Coordinate with the security team to ensure endpoint protection, EDR, encryption, firewall, and other required agents are installed, healthy, and reporting.
• Maintain BitLocker deployment and recovery key standards and assist with Microsoft security baselines and recommended Windows security settings.
• Identify unsupported operating systems, outdated applications, unhealthy agents, and improperly configured endpoints before they become operational or security emergencies.
Customer Onboarding and Engineering Escalation
• Assess endpoint configurations, management tools, patching, security agents, local administration practices, and software during new customer onboarding.
• Deploy and validate RMM, security, monitoring, and management agents, then bring endpoints into company standards through a phased remediation plan.
• Assist with workstation migrations involving Active Directory, Entra ID, Microsoft Intune, profiles, applications, and endpoint management platforms.
• Serve as an escalation resource for complex Windows, RMM, Intune, Entra ID, software deployment, patching, authentication, profile, policy, and endpoint security issues.
• Identify root causes and use escalations as input for better standards, documentation, monitoring, or automation rather than repeatedly treating symptoms.
Documentation and Continuous Improvement
• Maintain clear documentation for RMM policies, Intune configurations, scripts, deployment packages, patching standards, security configurations, and workstation build requirements.
• Create technical procedures and checklists that support engineers and technicians can follow consistently.
• Review ticket trends and operational data to identify problems that can be prevented through engineering or automation.
• Communicate changes to standards and tooling so the support team understands the intended process and expected outcome.
• Work collaboratively with support, systems, network, cloud, and security teams when endpoint issues cross technical boundaries.
Qualifications and Experience
• Experience administering and troubleshooting Windows 10 and Windows 11 in business environments.
• Experience with SCCM or an RMM platform, including monitoring, automation, patching, software deployment, agent health, or reporting.
• Working knowledge of PowerShell for software deployment, configuration, auditing, or remediation.
• Familiarity with Microsoft Intune, Entra ID, Microsoft 365, and modern Windows device management.
• Understanding of Windows application packaging, unattended installations, patch management, Active Directory, Group Policy, BitLocker, and endpoint security concepts.
• Strong troubleshooting, documentation, and communication skills.
• MSP experience, Windows Autopilot, Microsoft Graph or REST APIs, source control, and experience managing endpoints across multiple customer environments are helpful but not required.
Company DescriptionPioneer Technology is a nationwide Managed Services Provider with a strong focus on healthcare and
enterprise customers. We deliver secure, scalable IT solutions across cloud, networking, systems, and
security. Our mission is to help organizations modernize their technology environments while protecting
them against evolving cyber threats.