Endpoint Engineer, Technology & Security
Oaktree is a leader among global investment managers specializing in alternative investments, with more than $220 billion in assets under management. The firm emphasizes an opportunistic, value-oriented, and risk-controlled approach to investments in credit, equity, and real estate. With more than 1,400 employees and offices in over 25 cities worldwide, Oaktree is committed to cultivating a collaborative, curious, and inclusive environment that honors diversity of thought. The firm provides training and career development opportunities and supports local communities through philanthropic initiatives.
Responsibilities
- Endpoint Management & Engineering
- Own and continuously improve the modern endpoint management platform, including Microsoft Intune, Windows Autopilot, Microsoft Entra ID, and related technologies.
- Manage the full Windows endpoint lifecycle: provisioning, enrollment, configuration, compliance, application deployment, patching, OS upgrades, troubleshooting, and retirement.
- Lead the transition from SCCM/MECM and Group Policy–based management to modern, cloud-native endpoint management, including decommissioning legacy infrastructure.
- Leverage AI-assisted tools and automation to improve endpoint engineering, monitoring, troubleshooting, reporting, and operational consistency.
- Microsoft Intune & Modern Management
- Design, implement, and optimize Intune configuration profiles, compliance and security policies, application deployments, update rings, remediation scripts, and enrollment profiles.
- Support Microsoft Entra joined, hybrid-joined, co-managed, and cloud-native device management scenarios.
- Develop standardized processes for device provisioning, refresh, rebuilds, feature updates, and hardware lifecycle management.
- Endpoint Security & Compliance
- Implement and maintain endpoint security controls, including BitLocker, Microsoft Defender, Windows LAPS, Windows Hello for Business, firewall policies, attack surface reduction rules, and security baselines.
- Configure and monitor compliance policies to ensure devices meet organizational security requirements.
- Application & Operating System Management
- Package, deploy, test, and support applications using Intune, Win32 app deployment, Microsoft Store, PowerShell, and enterprise software distribution tools.
- Plan and execute Windows feature updates and OS migrations, including readiness assessments, pilot deployments, issue remediation, reporting, and production rollouts.
- Develop scripts, detection rules, remediation packages, and automation to improve operational efficiency.
- Operational Support
- Act as the escalation point for complex endpoint issues involving Windows, Intune, Autopilot, SCCM, application deployment, compliance, authentication, and device management.
- Diagnose and resolve issues using endpoint logs, Intune reporting, Autopilot diagnostics, PowerShell, Event Viewer, SCCM client logs, and Entra device records.
- Participate in incident response, change management, root cause analysis, and continuous service improvement.
- Documentation & Collaboration
- Maintain documentation for endpoint architecture, standards, policies, deployment processes, application packaging, and support procedures.
- Partner with Security, Identity, Infrastructure, Networking, Procurement, and Service Desk teams to deliver endpoint initiatives.
- Support audits, compliance efforts, risk assessments, and endpoint modernization projects.
Qualifications
Required Qualifications
- 5+ years of relevant experience.
- Strong troubleshooting skills across Windows OS, device enrollment, endpoint policy, application deployment, network connectivity, certificates, user profiles, and endpoint security controls.
- Ability to write clear technical documentation and communicate effectively with technical and non-technical stakeholders.
- Bachelor’s degree required.
Preferred Qualifications
- Microsoft certifications such as Microsoft 365 Certified: Endpoint Administrator Associate, Azure Administrator Associate, or related Microsoft security and identity certifications.
- Experience migrating from SCCM/GPO-based environments to Microsoft Intune and modern endpoint management.
- Experience with Microsoft Entra Conditional Access, device compliance, Zero Trust, and Microsoft Defender for Endpoint.
- Experience managing Apple Business Manager, macOS, iOS/iPadOS, and Android devices through Intune.
- Experience with enterprise application packaging and deployment, including Win32, MSI/MSIX, detection rules, dependencies, and deployment rings.
- Experience supporting Windows Hello for Business, Cloud Kerberos Trust, Universal Print, VPN, virtual desktop/Citrix environments, and line-of-business applications.
- Experience using AI-assisted tools (e.g., Microsoft Copilot or Security Copilot) to improve endpoint automation, troubleshooting, reporting, and documentation.
Personal Attributes
- Strong endpoint engineering mindset with the ability to design for scale, reliability, security, and operational simplicity.
- Ability to modernize legacy endpoint practices while maintaining business continuity.
- Strong analytical and troubleshooting skills.
- Security-first mindset with practical understanding of user experience and operational supportability.
- Ability to work independently while collaborating across multiple technical teams.
- Strong documentation discipline and process orientation.
Pay
Base Salary: $125,000 - $160,000. In addition to a competitive base salary, you will be eligible to receive discretionary bonus incentives and a comprehensive benefits package.