Microsoft Engineer
InTune Endpoint EngineerThis is a 6+ month W2 ONLY contractFully onsite in Torrance.Rate range is 80-100/hr (but please let me know what you typically seek if this is below your range)MUST BE A U.S. Person status as defined by ITAR (22 CFR 120.15), due to access to export-controlled technical data. (US Citizen or Green Card)Strong hands-on experience with Microsoft Intune and Microsoft Entra ID (Azure AD).Deep knowledge of Windows endpoint management, including Autopilot, enrollment, compliance, configuration profiles, and application deployment.Experience with certificate-based authentication, PKI integration, SCEP, and RADIUS.We are seeking an experienced InTune Endpoint Engineer to lead the design, implementation, and validation of modern device management and security capabilities across Windows and other major endpoint platforms.This role will focus on Microsoft Intune, Microsoft Entra ID, Windows Autopilot, certificate-based authentication, device hardening, and cross-platform endpoint governance, while also supporting integrations for Apple, Android, and third-party PKI/RADIUS solutions.The ideal candidate is a hands-on technical specialist who can translate business and security requirements into scalable endpoint architectures, implement solutions in production, and support pilot-to-rollout execution with strong documentation and stakeholder coordination.Key ResponsibilitiesIntune QuickstartLead discovery and design workshops to confirm tenant configuration, device platforms, enrollment models, and target-state policy architecture.Produce a configuration design document for review and approval prior to build.Configure Microsoft Intune tenant settingsDesign and implement Entra ID dynamic device and user group architecture to support policy, application, and Conditional Access targeting.Configure Windows Autopilot for cloud provisioningConfigure Windows enrollment for Microsoft Entra ID joined devices, including Company Portal deployment and user-driven enrollment.Package and deploy a representative set of applications using reusable deployment patterns.Manage pilot deployment to agreed pilot device groups, including validation, remediation, and sign-off before production rollout.EZ PKI and EZ RADIUS IntegrationLead integration design for certificate authority topology, certificate templates, and SCEP-based certificate issuance for Intune-managed devices.Configure Intune certificate integration with EZ PKI, including connector or API integration as required.Create and deploy trusted root and intermediate certificate profiles for all managed platforms.Design and configure device and user certificate profilesIntegrate EZ RADIUS with Intune-managed devices to enable certificate-based EAP-TLS authentication for Wi-Fi and VPN.Define authorization policies based on Entra ID group membership and Intune device compliance state.Create and deploy Wi-Fi and VPN profiles per platform, referencing deployed certificate profiles.Validate RADIUS policies, certificate-to-identity mapping, and end-to-end authentication across device platforms.Validate certificate lifecycle behavior, including issuance, renewal, and revocation upon device retirement or wipe.Addigy and Apple Device Management IntegrationManage Apple Business Manager configuration and hygieneIntegrate Addigy with Microsoft Intune using the current Device Compliance integration model so Addigy-managed Mac compliance state is available to Entra ID Conditional Access.Design and configure enrollment methodsManage application deployment across macOS, iPadOS, and iOS, including managed app distribution and Apps and Books licensing.Configure device restrictions for iPhone, iPad, and MacDefine Apple platform compliance policies and integrate them with Conditional Access.Perform validation and testing across Apple platforms and enrollment types.Android Enterprise BYODConfigure Managed Google Play account enrollment and bind it to the Intune tenant.Configure Android Enterprise Personally-Owned Work Profile (POWP) enrollment profiles.Deploy corporate applications into the work profile, including required and available app assignments.Configure work/personal container separation controls, including data transfer restrictions between work and personal profiles.Define Android Enterprise compliance policies and integrate them with Conditional Access.Perform enrollment and functional testing on representative Android devices.DLP and Device HardeningConfigure Microsoft Intune App Protection Policies for iOS, Android, and WindowsConfigure Windows Update for BusinessImplement baseline security configuration for WindowsImplement baseline security configuration for macOS, iOS, iPadOS, and Android, including passcode, encryption, and platform-appropriate restrictions.Configure baseline Intune policy for Entra ID joined devicesSupport Conditional Access policy design and validation to ensure device compliance and app protection signals are enforced correctly.Work with client on policy authoring and enablement.Configure reporting and compliance dashboards to provide ongoing operational visibility to the support team.Required QualificationsStrong hands-on experience with Microsoft Intune and Microsoft Entra ID.Deep knowledge of Windows endpoint management, including Autopilot, enrollment, compliance, configuration profiles, and application deployment.Experience with certificate-based authentication, PKI integration, SCEP, and RADIUS.Experience integrating endpoint compliance with Conditional Access.Working knowledge of Android Enterprise and Managed Google Play.Experience with device hardening, DLP, and security baseline implementation across multiple platforms.Ability to document technical designs, lead workshops, and support pilot-to-production deployments.Strong troubleshooting, communication, and stakeholder collaboration skills.Preferred QualificationsWorking knowledge of JAMF or Addigy, Apple Business Manager, and Apple device management.Microsoft certifications such as:Microsoft 365 Certified: Endpoint Administrator AssociateMicrosoft Certified: Identity and Access Administrator AssociateExperience with third-party PKI and RADIUS solutions.Experience supporting regulated or security-sensitive environments.Familiarity with cross-platform endpoint governance at enterprise scale.The estimated pay range for this position is USD $80.00/hr. - USD $100.00/hr. Exact compensation and offers of employment are dependent on job-related knowledge, skills, experience, licenses or certifications, and location. We also offer comprehensive benefits. The Talent Acquisition Partner can share more details about compensation or benefits for the role during the interview process.