Senior Microsoft Endpoint Management Engineer

All Lines Technology

  • Pittsburgh, PA
  • 22 days ago

    Highlights

    Preferred Certifications Strongly Preferred MD-102: Endpoint Administrator AssociateMS-102: Microsoft 365 Administrator Expert Additional SC-300: Identity and Access AdministratorAZ-104: Azure Administrator Associate Ideal Candidate The ideal candidate has extensive experience managing both MECM and Intune environments and understands how to bridge traditional endpoint management with modern cloud-based management. The Senior Microsoft Endpoint Management Engineer is responsible for designing, implementing, maintaining, and supporting enterprise endpoint management solutions using both Microsoft Endpoint Configuration Manager (MECM/SCCM) and Microsoft Intune.

    Numbers & Facts

    LocationPittsburgh, PA

    Description

    The Senior Microsoft Endpoint Management Engineer is responsible for designing, implementing, maintaining, and supporting enterprise endpoint management solutions using both Microsoft Endpoint Configuration Manager (MECM/SCCM) and Microsoft Intune.This role serves as a subject matter expert for traditional and modern endpoint management, including operating system deployment, application lifecycle management, device compliance, security controls, endpoint analytics, and cloud-based device management.The ideal candidate possesses deep expertise in both MECM and Intune and can help organizations modernize endpoint management through co-management, Microsoft Entra ID integration, Windows Autopilot, and cloud-native management strategies.Key ResponsibilitiesMicrosoft Endpoint Configuration Manager (MECM / SCCM)
    • Design, implement, administer, and maintain MECM infrastructure, including site systems, boundaries, boundary groups, distribution points, and client settings.
    • Monitor MECM health, performance, and availability; perform upgrades, hotfix installations, and environment maintenance.
    • Design and maintain Windows 10/11 operating system deployment task sequences for bare-metal, refresh, and in-place upgrade scenarios.
    • Manage boot images, driver repositories, deployment media, and PXE/task sequence troubleshooting.
    • Package, test, deploy, and maintain enterprise applications using MSI, EXE, PowerShell, scripts, and establish detection methods, dependencies, supersedence, and deployment requirements.
    • Manage Windows and third-party patching solutions, including deployment rings, maintenance windows, compliance monitoring, and remediation.
    Microsoft Intune / Cloud Endpoint Management
    • Design, implement, and administer Microsoft Intune environments for Windows, macOS, iOS, and Android device management.
    • Configure device enrollment, Microsoft Entra ID join, hybrid join, compliance policies, configuration profiles, device restrictions, and endpoint security policies.
    • Design and implement Windows Autopilot scenarios, including user-driven, pre-provisioned, and self-deploying deployments.
    • Configure Enrollment Status Page behavior, Autopilot profile assignments, and troubleshoot enrollment and provisioning issues.
    • Package and deploy Win32, Microsoft Store, Microsoft 365 Apps, and line-of-business applications; manage application lifecycle and update processes.
    • Configure and maintain security baselines, BitLocker management, Endpoint Privilege Management, Microsoft Defender integration, and Conditional Access integration.
    Co-Management & Endpoint Modernization
    • Design and implement MECM/Intune co-management solutions and migrate workloads between MECM and Intune.
    • Develop endpoint modernization roadmaps that guide customers from traditional device management to cloud-native management.
    • Assess customer endpoint environments and recommend best-practice architectures for modern management, compliance, and security.
    • Lead technical workshops, design sessions, implementation efforts, and customer-facing endpoint management projects.
    Automation, Documentation & Reporting
    • Develop PowerShell scripts for endpoint automation, administration, reporting, and remediation.
    • Integrate endpoint management workflows with Microsoft Graph API where applicable.
    • Create and maintain technical documentation, SOPs, runbooks, architecture diagrams, and implementation guides.
    • Develop reports using MECM, Intune, Power BI, SQL, and Microsoft reporting tools to track deployment success, compliance, and endpoint metrics.
    • Provide Tier 3 escalation support and mentor junior engineers or support staff.
    Required Qualifications
    • 5+ years of hands-on experience administering MECM/SCCM in enterprise environments.
    • 5+ years of hands-on experience administering Microsoft Intune.
    • Strong experience with Windows 10 and Windows 11 deployment, management, and troubleshooting.
    • Experience with operating system deployment, application packaging/deployment, patch management, endpoint security, and device compliance.
    • Strong understanding of Microsoft Entra ID, Active Directory, Group Policy, DNS, DHCP, and PKI/certificates.
    • Advanced PowerShell scripting and automation experience.
    • Experience implementing MECM and Intune co-management.
    • Strong troubleshooting, communication, documentation, and customer-facing consulting skills.
    Preferred Qualifications
    • Experience with Microsoft Defender for Endpoint, Defender XDR, Microsoft Cloud PKI, Endpoint Privilege Management, and Microsoft security baselines.
    • Experience with Microsoft Graph API, Power BI reporting, tenant-to-tenant migrations, endpoint modernization projects, and third-party patching solutions.
    • Experience supporting SMB, education, healthcare, government, or enterprise organizations.
    • Ability to lead discovery sessions, translate technical needs into project scopes, and present recommendations to customers and internal stakeholders.
    Preferred CertificationsStrongly PreferredMD-102: Endpoint Administrator AssociateMS-102: Microsoft 365 Administrator ExpertAdditional SC-300: Identity and Access AdministratorAZ-104: Azure Administrator AssociateIdeal Candidate The ideal candidate has extensive experience managing both MECM and Intune environments and understands how to bridge traditional endpoint management with modern cloud-based management. They can independently lead customer implementations, support large-scale device deployments, automate administrative processes, and provide strategic guidance around endpoint modernization and endpoint security.This is a senior technical position requiring strong consulting skills, customer engagement experience, and the ability to lead endpoint management projects from design through implementation and support.

    Powered by JazzHR

    Similar Jobs