Sr. Endpoint Engineer
ARCHIVED
We can't find an active application page for this role right now. It may reopen or be listed elsewhere. Use Next Steps to search for an active apply link and similar live jobs.
Job Description
Description:MSM Technology is seeking a Senior Endpoint Engineer to support the Department of Homeland Security in a fully cloud-based Microsoft Azure environment. The selected candidate will join a team of Windows cloud engineers and cybersecurity specialists responsible for modern endpoint management, automation, and security hardening across enterprise systems.This role focuses heavily on Microsoft Intune administration, Windows Autopilot deployment, endpoint compliance, enterprise patching, and automation through PowerShell scripting. The engineer will work across endpoint management and server operations teams to support secure device provisioning, application deployment, patch management, and vulnerability remediation.The ideal candidate will have strong experience in software packaging and deployment, endpoint compliance, security baseline implementation, and troubleshooting enterprise Windows environments. This individual will also play a key role in mentoring junior engineers and collaborating with security teams to ensure systems align with DHS security requirements.Qualifications, skills, and all relevant experience needed for this role can be found in the full description below.Administer and engineer Microsoft Intune environments including device compliance policies, conditional access, application deployment, and patch management.Create, configure, and deploy Intune policies, device configurations, and endpoint security settingsManage and maintain Windows 11 workstation baseline configurationsSupport provisioning and troubleshooting of devices using Windows Autopilot and Autopilot pre-provisioningUtilize Windows Update for Business (WUfB) to maintain enterprise patch compliancePackage, test, and deploy enterprise applications using PSAppDeployToolkit (PSADT) or similar toolsDevelop and implement endpoint security baselines in collaboration with engineering and cybersecurity teamsSupport endpoint hardening using Windows Defender Application Control (WDAC)Monitor and maintain endpoint compliance, vulnerability remediation, and patch managementCreate reporting on device compliance, patch status, software inventory, and deployment metricsDevelop PowerShell scripts and automation workflows to streamline endpoint management tasksTroubleshoot complex endpoint and system issues, providing both short-term mitigation and long-term remediationSupport Tier 2 escalation requests and collaborate with Tier 3 engineering teams to resolve incidentsProvide guidance and mentorship to junior systems and endpoint engineersParticipate in client meetings to ensure technical requirements and operational needs are metCollaborate with security, infrastructure, and cloud engineering teams to implement new technologies and improvementsParticipate in special engineering initiatives, technology testing, and cloud modernization xaygatp projectsRequirements:Education / Experience:Bachelor’s degree + 10 years relevant experience, ORAssociate degree + 12 years relevant experience, OR16 years of relevant experienceTools and Technologies:Experience managing cloud-based endpoint environmentsExperience supporting Azure Virtual Desktop (AVD) environmentsExperience with Nerdio or similar AVD management platformsFamiliarity with PSAppDeployToolkit (PSADT)Experience implementing Windows Defender Application Control (WDAC)Experience with endpoint vulnerability managementPreferred Technical Skills:Strong experience with Microsoft Intune administration and engineeringExperience supporting software packaging, patch management, and application deployment