{"schemaVersion":"jobsearcher.job.v1","id":"bf2dfd2fec77fe109889c8e0","url":"https://jobsearcher.com/jobs/bf2dfd2fec77fe109889c8e0","canonicalUrl":"https://jobsearcher.com/jobs/bf2dfd2fec77fe109889c8e0","title":"MDM-Endpoint Engineer","description":"A Day in the Life of our MDM/Endpoint Engineer\r\nAs an MDM/Endpoint Engineer at KDI, you will be responsible for supporting and securing the full device lifecycle across our client's organization. This includes but is not limited to mobile device management, endpoint provisioning, patch and update management, endpoint security hardening, and support for devices operating in a regulated, validated-systems environment.\r\nWho Should Apply\r\nAn ideal candidate is self-motivated and passionate about technology, and naturally curious. We are looking for someone who enjoys taking an outside-the-box approach to unique problems and who understands the added rigor that comes with managing endpoints in an environment where data integrity, privacy, and compliance are non-negotiable.\r\nResponsibilities\r\nEndpoint Fleet Management\r\nMulti-OS device administration: Manage and support the endpoint fleet across macOS (Jamf Pro), Windows (FleetDM/PDQ), Linux, and Chrome devices, including enrollment, configuration profiles, and lifecycle management.\r\nApple Business Manager: Maintain ABM hygiene, including enrollment tokens, prestage/zero-touch enrollment, and removal of retired or e-wasted devices to prevent unauthorized re-enrollment.\r\nShared and lab devices: Support shared-use and lab instrument endpoints alongside standard user devices, coordinating maintenance windows with lab and facilities teams to minimize disruption.\r\nPatching & Vulnerability Remediation\r\nOS upgrade cycles: Drive macOS upgrade adoption (e.g., Tahoe) through Jamf nudges and forced-update strategies for non-compliant devices.\r\nWindows patching: Coordinate Windows 10/11 patching and ESU licensing, tracking machines by support status and closing gaps identified through fleet reporting.\r\nQuarterly maintenance windows: Plan and execute rolling patch cycles for hard-to-schedule lab instruments and shared devices.\r\nSecurity Tooling & Identity\r\nEDR and identity coordination: Monitor CrowdStrike agent health and Okta device trust/SSO status across the fleet; escalat gaps to InfoSec and remediate agent or enrollment failures.\r\nAccess hygiene: Administer and configure Okta/Active Directory for security and access management. Troubleshooting endpoint authentication using biometrics, hardware tokens, and certificates.\r\nAsset Inventory & Service Management\r\nCMDB accuracy: Maintain accurate device and user records in Fresh Service, including primary device assignment, location, and lifecycle status, per documented SOPs.\r\nPhysical and remote audits: Execute recurring inventory audits (FTE, contractor, and lab device phases) combining in-person checks with automated compliance validation.\r\nTicket-based tracking: Log and track compliance exceptions (backup failures, check-in gaps, stale devices) as tickets rather than informal notes, to prevent lost follow-up.\r\nBackup, Recovery & Onboarding/Offboarding\r\nBackup health: Monitor Druva (or equivalent) backup coverage and remediate gaps, including executive and VIP devices, contractors, and Linux endpoints.\r\nZero-touch onboarding: Maintain prestage enrollment and automated provisioning to minimize Helpdesk involvement in new-hire device setup.\r\nOffboarding reliability: Support consistent, auditable offboarding, including device lock, data preservation, and asset recovery, for contractors and employees alike.\r\nAutomation & Documentation\r\nScripting: Write and maintain scripts (Bash, Python, or PowerShell) and Jamf extension attributes/smart groups to automate compliance checks and reduce manual fleet management.\r\nSOPs and knowledge sharing: Document standard operating procedures for fleet management, patching, and audits so processes are repeatable across sites and shifts.\r\nCross-team coordination: Partner with Helpdesk, InfoSec, Facilities, and site leads across Bay Area, San Diego, and Cambridge to align on device installs, vendor visits, and support escalations.\r\nMinimum Qualifications\r\nBachelor's degree in Computer Science, Information Technology, or equivalent hands-on experience. Experience in early-stage companies or life sciences/research environments is a plus.\r\n3+ years of hands-on endpoint or systems administration experience across macOS, Windows, and/or Linux in a professional environment.\r\nHands-on experience administering an MDM platform at scale (Jamf Pro required; exposure to FleetDM, PDQ, or Intune).\r\nWorking knowledge of Okta for SSO and device trust.\r\nFamiliarity with an EDR/endpoint security tool such as CrowdStrike, and comfort collaborating with a security team on remediation.\r\nScripting proficiency in Bash, Python, or PowerShell for automating repetitive fleet tasks.\r\nExperience with an ITSM/ticketing platform (Fresh Service, ServiceNow, or similar) and asset/CMDB tracking.\r\nStrong communication skills and comfort working directly with end users, lab staff, and cross-functional stakeholders in a hybrid, multi-site organization.\r\nPreferred Qualifications\r\nExperience managing Chrome/ChromeOS devices in an enterprise setting (Google Admin console).\r\nFamiliarity with Apple Business Manager and zero-touch/prestage enrollment workflows.\r\nExposure to backup and disaster recovery tooling (Druva or similar) for endpoint fleets.\r\nExperience supporting a life sciences, biotech, or other regulated research environment.\r\nFamiliarity with Zero Trust concepts and phishing-resistant authentication (e.g., WebAuthn/FIDO2).\r\nITIL Foundation certification or equivalent service management experience.\r\nApple Certified Support Professional certification or equivalent\r\nApple Business Manager: Maintain ABM hygiene, including enrollment tokens, prestage/zero-touch enrollment, and removal of retired or e-wasted devices to prevent unauthorized re-enrollment.\r\nShared and lab devices: Support shared-use and lab instrument endpoints alongside standard user devices, coordinating maintenance windows with lab and facilities teams to minimize disruption.\r\nJ-18808-Ljbffr","company":"Kdinfotech","rawCompany":"kdinfotech","city":"Belmont","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-08-08T01:59:31.431Z","occupations":[{"code":"15-1244.00","title":"Network and Computer Systems Administrators","slug":"network-and-computer-systems-administrators"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1231.00","title":"Computer Network Support Specialists","slug":"computer-network-support-specialists"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541513","title":"Computer Facilities Management Services","slug":"computer-facilities-management-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"MDM-Endpoint Engineer","description":"A Day in the Life of our MDM/Endpoint Engineer\r\nAs an MDM/Endpoint Engineer at KDI, you will be responsible for supporting and securing the full device lifecycle across our client's organization. This includes but is not limited to mobile device management, endpoint provisioning, patch and update management, endpoint security hardening, and support for devices operating in a regulated, validated-systems environment.\r\nWho Should Apply\r\nAn ideal candidate is self-motivated and passionate about technology, and naturally curious. We are looking for someone who enjoys taking an outside-the-box approach to unique problems and who understands the added rigor that comes with managing endpoints in an environment where data integrity, privacy, and compliance are non-negotiable.\r\nResponsibilities\r\nEndpoint Fleet Management\r\nMulti-OS device administration: Manage and support the endpoint fleet across macOS (Jamf Pro), Windows (FleetDM/PDQ), Linux, and Chrome devices, including enrollment, configuration profiles, and lifecycle management.\r\nApple Business Manager: Maintain ABM hygiene, including enrollment tokens, prestage/zero-touch enrollment, and removal of retired or e-wasted devices to prevent unauthorized re-enrollment.\r\nShared and lab devices: Support shared-use and lab instrument endpoints alongside standard user devices, coordinating maintenance windows with lab and facilities teams to minimize disruption.\r\nPatching & Vulnerability Remediation\r\nOS upgrade cycles: Drive macOS upgrade adoption (e.g., Tahoe) through Jamf nudges and forced-update strategies for non-compliant devices.\r\nWindows patching: Coordinate Windows 10/11 patching and ESU licensing, tracking machines by support status and closing gaps identified through fleet reporting.\r\nQuarterly maintenance windows: Plan and execute rolling patch cycles for hard-to-schedule lab instruments and shared devices.\r\nSecurity Tooling & Identity\r\nEDR and identity coordination: Monitor CrowdStrike agent health and Okta device trust/SSO status across the fleet; escalat gaps to InfoSec and remediate agent or enrollment failures.\r\nAccess hygiene: Administer and configure Okta/Active Directory for security and access management. Troubleshooting endpoint authentication using biometrics, hardware tokens, and certificates.\r\nAsset Inventory & Service Management\r\nCMDB accuracy: Maintain accurate device and user records in Fresh Service, including primary device assignment, location, and lifecycle status, per documented SOPs.\r\nPhysical and remote audits: Execute recurring inventory audits (FTE, contractor, and lab device phases) combining in-person checks with automated compliance validation.\r\nTicket-based tracking: Log and track compliance exceptions (backup failures, check-in gaps, stale devices) as tickets rather than informal notes, to prevent lost follow-up.\r\nBackup, Recovery & Onboarding/Offboarding\r\nBackup health: Monitor Druva (or equivalent) backup coverage and remediate gaps, including executive and VIP devices, contractors, and Linux endpoints.\r\nZero-touch onboarding: Maintain prestage enrollment and automated provisioning to minimize Helpdesk involvement in new-hire device setup.\r\nOffboarding reliability: Support consistent, auditable offboarding, including device lock, data preservation, and asset recovery, for contractors and employees alike.\r\nAutomation & Documentation\r\nScripting: Write and maintain scripts (Bash, Python, or PowerShell) and Jamf extension attributes/smart groups to automate compliance checks and reduce manual fleet management.\r\nSOPs and knowledge sharing: Document standard operating procedures for fleet management, patching, and audits so processes are repeatable across sites and shifts.\r\nCross-team coordination: Partner with Helpdesk, InfoSec, Facilities, and site leads across Bay Area, San Diego, and Cambridge to align on device installs, vendor visits, and support escalations.\r\nMinimum Qualifications\r\nBachelor's degree in Computer Science, Information Technology, or equivalent hands-on experience. Experience in early-stage companies or life sciences/research environments is a plus.\r\n3+ years of hands-on endpoint or systems administration experience across macOS, Windows, and/or Linux in a professional environment.\r\nHands-on experience administering an MDM platform at scale (Jamf Pro required; exposure to FleetDM, PDQ, or Intune).\r\nWorking knowledge of Okta for SSO and device trust.\r\nFamiliarity with an EDR/endpoint security tool such as CrowdStrike, and comfort collaborating with a security team on remediation.\r\nScripting proficiency in Bash, Python, or PowerShell for automating repetitive fleet tasks.\r\nExperience with an ITSM/ticketing platform (Fresh Service, ServiceNow, or similar) and asset/CMDB tracking.\r\nStrong communication skills and comfort working directly with end users, lab staff, and cross-functional stakeholders in a hybrid, multi-site organization.\r\nPreferred Qualifications\r\nExperience managing Chrome/ChromeOS devices in an enterprise setting (Google Admin console).\r\nFamiliarity with Apple Business Manager and zero-touch/prestage enrollment workflows.\r\nExposure to backup and disaster recovery tooling (Druva or similar) for endpoint fleets.\r\nExperience supporting a life sciences, biotech, or other regulated research environment.\r\nFamiliarity with Zero Trust concepts and phishing-resistant authentication (e.g., WebAuthn/FIDO2).\r\nITIL Foundation certification or equivalent service management experience.\r\nApple Certified Support Professional certification or equivalent\r\nApple Business Manager: Maintain ABM hygiene, including enrollment tokens, prestage/zero-touch enrollment, and removal of retired or e-wasted devices to prevent unauthorized re-enrollment.\r\nShared and lab devices: Support shared-use and lab instrument endpoints alongside standard user devices, coordinating maintenance windows with lab and facilities teams to minimize disruption.\r\nJ-18808-Ljbffr","datePosted":"2026-08-08T01:59:31.431Z","dateModified":"2026-08-08T01:59:31.431Z","hiringOrganization":{"@type":"Organization","name":"Kdinfotech","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Belmont","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"bf2dfd2fec77fe109889c8e0"},"url":"https://jobsearcher.com/jobs/bf2dfd2fec77fe109889c8e0"}}