Modern Endpoint Engineer - IT

Frank Rimerman and Co LLP

  • San Jose, California
  • 1 day ago
  • $115,000–$130,000 Per Year
  • Full-time

Highlights

Strong hands-on experience with Microsoft Configuration Manager (SCCM/MECM) and Microsoft Intune, including application and software deployment, collections, client management, task sequences, operating system deployment, patching, compliance, reporting, and troubleshooting. The ideal candidate has strong hands-on experience with Microsoft Configuration Manager (SCCM/MECM) and Microsoft Intune, along with Windows Autopilot, application deployment, patch management, endpoint security, mobile device management, reporting, and automation.

Numbers & Facts

LocationSan Jose, California
Job TypeFull-time
Salary$115,000–$130,000 Per Year

Description

Overview:

We are looking for a hands on Modern Endpoint Engineer to help shape and support a secure, modern, and reliable endpoint environment within our Information Technology services. In this role, you will take ownership of endpoint administration, engineering, security, automation, and continuous improvement across Windows and mobile devices.

 

Based in our San Jose office, this hybrid role will partner closely with our Infrastructure, Security, Solutions Delivery, and Service Desk teams to deliver a smooth technology experience for employees while maintaining strong security and compliance standards. This role is ideal for someone who enjoys solving technical challenges, improving processes, and working with modern Microsoft endpoint technologies.

 

The ideal candidate has strong hands-on experience with Microsoft Configuration Manager (SCCM/MECM) and Microsoft Intune, along with Windows Autopilot, application deployment, patch management, endpoint security, mobile device management, reporting, and automation. The role will be responsible for supporting and optimizing the existing SCCM environment while helping advance the firm's transition toward modern endpoint management with Intune and Autopilot.

 

IND123

Responsibilities:

Manage and Improve the Endpoint Environment

  • Administer, maintain, and troubleshoot Microsoft Configuration Manager (SCCM/MECM) and Microsoft Intune, including collections, client health, policies, inventory, software distribution, compliance, and reporting.
  • Manage Windows endpoint configuration and lifecycle activities, including imaging, task sequences, drivers, operating system deployment, patching, upgrades, and application delivery.
  • Develop modern provisioning workflows with Windows Autopilot and support the evolving integration and coexistence of Intune and Configuration Manager.
  • Monitor endpoint health, compliance, and performance; resolve issues methodically while minimizing disruption and improving the employee experience.

Deploy and Maintain Business Applications

  • Package, test, deploy, update, document, and retire business applications through Configuration Manager and Intune.
  • Establish repeatable deployment standards that improve reliability and reduce support effort.
  • Investigate and resolve application installation and deployment issues, including detection rules, distribution failures, and client-side problems, in partnership with support teams and vendors.

Automate, Report, and Document

  • Build PowerShell scripts and use Microsoft Graph or other APIs to automate endpoint administration and reduce manual effort.
  • Create reports and dashboards that provide visibility into endpoint health, compliance, performance, and trends.
  • Maintain clear documentation for processes, procedures, and automation workflows while identifying opportunities to simplify and standardize operations.

Support Endpoint Security and Compliance

  • Configure and maintain endpoint security baselines, policies, controls, and compliance settings aligned with organizational standards.
  • Administer Microsoft Defender for Endpoint and partner with Information Security on vulnerability remediation, investigations, and security initiatives.
  • Provide accurate endpoint data, documentation, and evidence for audit and compliance needs while balancing security requirements with a user-conscious experience.

Administer Mobile Device Management

  • Administer mobile device management through Microsoft Intune, including enrollment, configuration profiles, applications, compliance, and security settings.
  • Support the transition from Lookout to Intune and troubleshoot enrollment or management issues to maintain a consistent user experience.
  • Maintain mobile device management standards, procedures, and documentation.

Drive Continuous Improvement

  • Recommend and implement improvements that strengthen endpoint reliability, security, performance, efficiency, and the employee technology experience.
  • Stay current on modern endpoint management technologies and participate in proofs of concept and evaluations that shape future capabilities.
  • Continuously refine endpoint standards, processes, and best practices as organizational needs evolve.

Collaborate and Support

  • Provide Tier II/III support for complex endpoint issues and escalations.
  • Collaborate with Infrastructure, Security, Solutions Delivery, Service Desk, vendors, and service providers on endpoint initiatives and issue resolution.
  • Serve as a technical resource and mentor by sharing guidance, best practices, knowledge base articles, documentation, and training materials.
Qualifications:

Education and Certifications

  • Bachelor’s degree in Information Technology, Computer Science, or a related field preferred; equivalent professional experience, technical training, or relevant certifications may be considered.
  • Microsoft certifications in Intune, Endpoint Administration, Azure, or Microsoft 365 are a plus.

Experience and Technical Skills

  • 3–5 years of experience supporting or administering enterprise endpoint environments.
  • Strong hands-on experience with Microsoft Configuration Manager (SCCM/MECM) and Microsoft Intune, including application and software deployment, collections, client management, task sequences, operating system deployment, patching, compliance, reporting, and troubleshooting.
  • Experience managing the Windows 10/11 endpoint lifecycle, including provisioning, configuration, maintenance, application packaging, operating system upgrades, Windows Autopilot, and modern device deployment practices.
  • Working knowledge of Microsoft 365, Microsoft Entra ID, Active Directory, Group Policy, and Windows configuration management.
  • Ability to create or maintain PowerShell scripts for endpoint administration; familiarity with Microsoft Graph or API-based automation is a plus.
  • Experience with Microsoft Defender for Endpoint or comparable security tools, including endpoint compliance, vulnerability management, and security best practices.
  • Experience administering mobile devices through Microsoft Intune or another enterprise MDM platform.
  • Understanding of endpoint lifecycle management and modern workplace technologies; experience creating endpoint reports, monitoring views, or compliance dashboards is a plus.

Professional Strengths

  • Strong analytical and troubleshooting skills, with a methodical approach and close attention to detail.
  • Clear verbal, written, and documentation skills, including the ability to explain technical topics to varied audiences.
  • Strong organization, time management, and follow-through, with the ability to balance multiple priorities.
  • Customer-focused and responsive, with the ability to work independently and collaborate effectively across teams.
  • Curious, adaptable, and committed to continuous learning as endpoint technologies evolve.

Work Environment

  • Participate in an on-call rotation and provide occasional evening, weekend, or after-hours support for deployments, upgrades, maintenance, or urgent business needs.
  • Travel to office locations as needed to support endpoint initiatives, deployments, and troubleshooting.

The hourly range for this position is based upon a salary of $115,000- $130,000. This pay range reflects the San Francisco Bay Area. Compensation will be adjusted for each candidate based on their geographic location and experience.

 

------------------------------

Applicants must be authorized to work in the United States. This position is not eligible for sponsorship and we do not sponsor applicants for work visas. It is our policy and intent to provide equal opportunity to all persons without regard to race, color, religion, sex, pregnancy, marital status, sexual orientation, age, national origin, disability, or medical condition as defined in state and federal laws. Pursuant to the San Francisco Fair Chance Ordinance,

Similar Jobs

See more jobs