{"schemaVersion":"jobsearcher.job.v1","id":"67bc24d219d83dbde9fa12c7","url":"https://jobsearcher.com/jobs/67bc24d219d83dbde9fa12c7","canonicalUrl":"https://jobsearcher.com/jobs/67bc24d219d83dbde9fa12c7","title":"Endpoint Systems Engineer","description":"As an Endpoint Systems Engineer, you will be responsible for designing, implementing, maintaining, and securing the enterprise workstation and mobile endpoint estate, including Windows, macOS, and iOS devices managed through Microsoft Intune. This role owns operating system and third-party application patching, OS lifecycle management, software packaging and deployment, Group Policy (GPO) and Intune policy administration, configuration baselines, and endpoint security tooling across on-premises, cloud-managed, and remote endpoints in a regulated financial services environment.\nResponsibilities\nDesign, implement, maintain, and secure enterprise workstation and mobile endpoint environments, including Windows, macOS, and iOS devices managed through Microsoft Intune.\nAdminister, maintain, and optimize Tanium as the primary endpoint management and patching platform, including module configuration, sensor/package authoring, content distribution, and operational reporting.\nDevelop and execute enterprise patching strategies for Windows and macOS OS and third-party applications, including Patch Tuesday cycles, out-of-band releases, and zero-day remediation.\nCoordinate patch testing, pilot rings, phased deployments, validation, and rollback procedures across on-site and remote/VPN workstations.\nPackage, test, and deploy enterprise applications for Windows, macOS, and iOS using Tanium Deploy and Microsoft Intune, maintaining a curated software catalog.\nManage endpoint provisioning and enrollment workflows for Windows Autopilot, macOS Automated Device Enrollment, and iOS ADE, including driver libraries and zero-touch provisioning.\nOwn the lifecycle management of Group Policy Objects and Microsoft Intune policies, including configuration profiles, compliance policies, security baselines, and endpoint protection policies.\nDesign, test, deploy, troubleshoot, and tune policies in line with CIS-based standards and business needs.\nDevelop automation scripts for provisioning, deployment, patch orchestration, health checks, and reporting using PowerShell, Python, Bash, and Tanium sensors/packages.\nOversee workstation lifecycle activities such as provisioning, upgrades, decommissioning, and asset reconciliation.\nPartner with cybersecurity to analyze vulnerability scans and prioritize remediation efforts.\nProvide Tier 3 support for complex endpoint and software deployment issues, conducting root cause analysis and implementing solutions.\nParticipate in platform upgrades and migrations, including system rollouts and major OS version transitions.\nMaintain technical documentation, runbooks, standards, procedures, and change records.\nCollaborate with cross-functional teams to ensure secure, resilient, and high-performing endpoint services.\nRequirements\n4 to 6 years of enterprise endpoint engineering experience, including administrator experience with Tanium and Microsoft Intune.\nStrong knowledge of Group Policy (GPO), Intune policy administration, and third-party application patching.\nExperience with scripting languages such as PowerShell, Python, and Bash.\nExperience troubleshooting Tier 3 support issues related to endpoints and deployment.\nExperience with SCCM/MECM, Kaseya VSA, or similar platforms is a plus.\nA 4-year degree in Information Systems, Computer Science, Computer Engineering, or a related field is preferred.\nEquivalent certifications or experience will be considered.\nExperience working in regulated industries such as financial services, healthcare, or government is strongly preferred.\nSystem One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.\nSystem One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.\n\n#J-18808-Ljbffr","company":"System One","rawCompany":"system one","city":"Florida","state":"NY","isRemote":false,"isActive":false,"createdAt":"2026-08-01T03:12:11.176Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1244.00","title":"Network and Computer Systems Administrators","slug":"network-and-computer-systems-administrators"},{"code":"15-1211.00","title":"Computer Systems Analysts","slug":"computer-systems-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Endpoint Systems Engineer","description":"As an Endpoint Systems Engineer, you will be responsible for designing, implementing, maintaining, and securing the enterprise workstation and mobile endpoint estate, including Windows, macOS, and iOS devices managed through Microsoft Intune. This role owns operating system and third-party application patching, OS lifecycle management, software packaging and deployment, Group Policy (GPO) and Intune policy administration, configuration baselines, and endpoint security tooling across on-premises, cloud-managed, and remote endpoints in a regulated financial services environment.\nResponsibilities\nDesign, implement, maintain, and secure enterprise workstation and mobile endpoint environments, including Windows, macOS, and iOS devices managed through Microsoft Intune.\nAdminister, maintain, and optimize Tanium as the primary endpoint management and patching platform, including module configuration, sensor/package authoring, content distribution, and operational reporting.\nDevelop and execute enterprise patching strategies for Windows and macOS OS and third-party applications, including Patch Tuesday cycles, out-of-band releases, and zero-day remediation.\nCoordinate patch testing, pilot rings, phased deployments, validation, and rollback procedures across on-site and remote/VPN workstations.\nPackage, test, and deploy enterprise applications for Windows, macOS, and iOS using Tanium Deploy and Microsoft Intune, maintaining a curated software catalog.\nManage endpoint provisioning and enrollment workflows for Windows Autopilot, macOS Automated Device Enrollment, and iOS ADE, including driver libraries and zero-touch provisioning.\nOwn the lifecycle management of Group Policy Objects and Microsoft Intune policies, including configuration profiles, compliance policies, security baselines, and endpoint protection policies.\nDesign, test, deploy, troubleshoot, and tune policies in line with CIS-based standards and business needs.\nDevelop automation scripts for provisioning, deployment, patch orchestration, health checks, and reporting using PowerShell, Python, Bash, and Tanium sensors/packages.\nOversee workstation lifecycle activities such as provisioning, upgrades, decommissioning, and asset reconciliation.\nPartner with cybersecurity to analyze vulnerability scans and prioritize remediation efforts.\nProvide Tier 3 support for complex endpoint and software deployment issues, conducting root cause analysis and implementing solutions.\nParticipate in platform upgrades and migrations, including system rollouts and major OS version transitions.\nMaintain technical documentation, runbooks, standards, procedures, and change records.\nCollaborate with cross-functional teams to ensure secure, resilient, and high-performing endpoint services.\nRequirements\n4 to 6 years of enterprise endpoint engineering experience, including administrator experience with Tanium and Microsoft Intune.\nStrong knowledge of Group Policy (GPO), Intune policy administration, and third-party application patching.\nExperience with scripting languages such as PowerShell, Python, and Bash.\nExperience troubleshooting Tier 3 support issues related to endpoints and deployment.\nExperience with SCCM/MECM, Kaseya VSA, or similar platforms is a plus.\nA 4-year degree in Information Systems, Computer Science, Computer Engineering, or a related field is preferred.\nEquivalent certifications or experience will be considered.\nExperience working in regulated industries such as financial services, healthcare, or government is strongly preferred.\nSystem One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.\nSystem One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.\n\n#J-18808-Ljbffr","datePosted":"2026-08-01T03:12:11.176Z","dateModified":"2026-08-01T03:12:11.176Z","hiringOrganization":{"@type":"Organization","name":"System One","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Florida","addressRegion":"NY","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"67bc24d219d83dbde9fa12c7"},"url":"https://jobsearcher.com/jobs/67bc24d219d83dbde9fa12c7"}}