{"schemaVersion":"jobsearcher.job.v1","id":"63e29a6dce3761eee0cad2fe","url":"https://jobsearcher.com/jobs/63e29a6dce3761eee0cad2fe","canonicalUrl":"https://jobsearcher.com/jobs/63e29a6dce3761eee0cad2fe","title":"Intune Admin : Grant Thornton","description":"Interview : VideoVisa : USC, GCThis is onsite from day-1Description :Need Candidates mother's maiden namesend full linkedinMust send date of birthmust send 3 referencesPosition: Mac Endpoint Engineer (macOS + Intune)Overview:Onsite contract role (6+ months, possible extension) for a proactive engineer ready to shape macOS in a Microsoft-centric enterprise. Client is elevating macOS to first-class status and needs a hands-on Mac Endpoint Engineer to build and harden a modern Intune-managed macOS environment. You will deliver zero-touch enrollment, seamless Platform SSO (PSSO) first sign-in, large-scale macOS app packaging, configuration, compliance, automation, and a strong security posture with a goal of achieving 1:1 parity with Windows devices.Key ResponsibilitiesDesign/operate zero-touch enrollment with ABM + ADE (PreStage through post-enrollment fixes).Build a consistent first sign-in experience using PSSO + Intune.Improve enrollment flows, bootstrap content, and post-enrollment automations.Lead macOS app packaging for Intune (PKG/DMG + pre/post scripts, detection rules, dependencies, retries, uninstall logic).Create a scalable third-party app deployment model with staged rings, rollback plans, and change control.Collaborate with Packaging/QA on versioning, testing, and release notes.Manage Intune baseline configs & compliance policies; suggest UX/reliability improvements.Enforce CIS macOS benchmark controls (macOS 26+); own configuration/enforcement, partner with InfoSec.Integrate/support: Entra ID, Defender for Endpoint (DLP), CrowdStrike, CyberArk EPM, Qualys, GlobalProtect ZTNA.Automate via scripting (bash/zsh/Python; PowerShell for Graph) provisioning, remediations, health checks, reporting.Deliver actionable Intune dashboard metrics (enrollment success, sign-in time, compliance drift, packaging SLAs).Write KB articles/how-tos; transfer knowledge to Support; provide occasional Tier 3 guidance (no on-call).Partner with Identity, Security, Networking, and Support to prepare for go-live and scale across US users.Contribute to standards, guardrails, and SOPs for long-term stability.EnvironmentMDM: Microsoft Intune only (no Jamf/Kandji).Minimum: macOS 26 (Tahoe).Stack: Entra ID, Defender for Endpoint , CrowdStrike, CyberArk EPM, Qualys, GlobalProtect.Standards: CIS macOS benchmark (InfoSec sets policy; you implement/operate).Tools: ABM + ADE in place; Intune for compliance & reporting.Required Qualifications3 5+ years enterprise macOS MDM (Intune preferred).Strong Intune macOS packaging expertise (PKG/DMG, scripts, detection, rings, rollback).Hands-on ADE zero-touch + PSSO implementation.Scripting: bash/zsh/Python (PowerShell/Graph as needed).Experience enforcing CIS controls via Intune profiles/policies.Familiarity with Defender, CrowdStrike, CyberArk EPM, Qualys, and GlobalProtect.Excellent documentation & knowledge-transfer skills.PreferredSelf-healing remediations / drift correction.iOS/iPadOS in Intune (bonus).Entra ID Conditional Access for macOS.Current Apple management trends (PSSO, macOS security/privacy).Success Looks LikeReliable zero-touch from unbox to desktop.Fast, frictionless PSSO sign-in.Scalable packaging/patching with SLAs, rings, and rollback.Trusted CIS-aligned posture with clear Intune dashboards.","company":"ShiftCode Analytics","rawCompany":"shiftcode analytics","city":"Downers Grove","state":"IL","isRemote":false,"isActive":false,"createdAt":"2026-05-21T03:20:09.179Z","occupations":[{"code":"15-1244.00","title":"Network and Computer Systems Administrators","slug":"network-and-computer-systems-administrators"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1211.00","title":"Computer Systems Analysts","slug":"computer-systems-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Intune Admin : Grant Thornton","description":"Interview : VideoVisa : USC, GCThis is onsite from day-1Description :Need Candidates mother's maiden namesend full linkedinMust send date of birthmust send 3 referencesPosition: Mac Endpoint Engineer (macOS + Intune)Overview:Onsite contract role (6+ months, possible extension) for a proactive engineer ready to shape macOS in a Microsoft-centric enterprise. Client is elevating macOS to first-class status and needs a hands-on Mac Endpoint Engineer to build and harden a modern Intune-managed macOS environment. You will deliver zero-touch enrollment, seamless Platform SSO (PSSO) first sign-in, large-scale macOS app packaging, configuration, compliance, automation, and a strong security posture with a goal of achieving 1:1 parity with Windows devices.Key ResponsibilitiesDesign/operate zero-touch enrollment with ABM + ADE (PreStage through post-enrollment fixes).Build a consistent first sign-in experience using PSSO + Intune.Improve enrollment flows, bootstrap content, and post-enrollment automations.Lead macOS app packaging for Intune (PKG/DMG + pre/post scripts, detection rules, dependencies, retries, uninstall logic).Create a scalable third-party app deployment model with staged rings, rollback plans, and change control.Collaborate with Packaging/QA on versioning, testing, and release notes.Manage Intune baseline configs & compliance policies; suggest UX/reliability improvements.Enforce CIS macOS benchmark controls (macOS 26+); own configuration/enforcement, partner with InfoSec.Integrate/support: Entra ID, Defender for Endpoint (DLP), CrowdStrike, CyberArk EPM, Qualys, GlobalProtect ZTNA.Automate via scripting (bash/zsh/Python; PowerShell for Graph) provisioning, remediations, health checks, reporting.Deliver actionable Intune dashboard metrics (enrollment success, sign-in time, compliance drift, packaging SLAs).Write KB articles/how-tos; transfer knowledge to Support; provide occasional Tier 3 guidance (no on-call).Partner with Identity, Security, Networking, and Support to prepare for go-live and scale across US users.Contribute to standards, guardrails, and SOPs for long-term stability.EnvironmentMDM: Microsoft Intune only (no Jamf/Kandji).Minimum: macOS 26 (Tahoe).Stack: Entra ID, Defender for Endpoint , CrowdStrike, CyberArk EPM, Qualys, GlobalProtect.Standards: CIS macOS benchmark (InfoSec sets policy; you implement/operate).Tools: ABM + ADE in place; Intune for compliance & reporting.Required Qualifications3 5+ years enterprise macOS MDM (Intune preferred).Strong Intune macOS packaging expertise (PKG/DMG, scripts, detection, rings, rollback).Hands-on ADE zero-touch + PSSO implementation.Scripting: bash/zsh/Python (PowerShell/Graph as needed).Experience enforcing CIS controls via Intune profiles/policies.Familiarity with Defender, CrowdStrike, CyberArk EPM, Qualys, and GlobalProtect.Excellent documentation & knowledge-transfer skills.PreferredSelf-healing remediations / drift correction.iOS/iPadOS in Intune (bonus).Entra ID Conditional Access for macOS.Current Apple management trends (PSSO, macOS security/privacy).Success Looks LikeReliable zero-touch from unbox to desktop.Fast, frictionless PSSO sign-in.Scalable packaging/patching with SLAs, rings, and rollback.Trusted CIS-aligned posture with clear Intune dashboards.","datePosted":"2026-05-21T03:20:09.179Z","dateModified":"2026-05-21T03:20:09.179Z","hiringOrganization":{"@type":"Organization","name":"ShiftCode Analytics","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Downers Grove","addressRegion":"IL","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"63e29a6dce3761eee0cad2fe"},"url":"https://jobsearcher.com/jobs/63e29a6dce3761eee0cad2fe"}}