Jobs · Information Technology · California

Endpoint Engineer, Technology & Security

Oaktree · Los Angeles, CA · 3 wk ago
HybridInformation Technology$125k–$160k/yrFull-time

Oaktree is a leader among global investment managers specializing in alternative investments, with more than $220 billion in assets under management. The firm emphasizes an opportunistic, value-oriented, and risk-controlled approach to investments in credit, equity, and real estate. With more than 1,400 employees and offices in over 25 cities worldwide, Oaktree is committed to cultivating a collaborative, curious, and inclusive environment that honors diversity of thought. The firm provides training and career development opportunities and supports local communities through philanthropic initiatives.

Responsibilities

  • Endpoint Management & Engineering
    • Own and continuously improve the modern endpoint management platform, including Microsoft Intune, Windows Autopilot, Microsoft Entra ID, and related technologies.
    • Manage the full Windows endpoint lifecycle: provisioning, enrollment, configuration, compliance, application deployment, patching, OS upgrades, troubleshooting, and retirement.
    • Lead the transition from SCCM/MECM and Group Policy–based management to modern, cloud-native endpoint management, including decommissioning legacy infrastructure.
    • Leverage AI-assisted tools and automation to improve endpoint engineering, monitoring, troubleshooting, reporting, and operational consistency.
  • Microsoft Intune & Modern Management
    • Design, implement, and optimize Intune configuration profiles, compliance and security policies, application deployments, update rings, remediation scripts, and enrollment profiles.
    • Support Microsoft Entra joined, hybrid-joined, co-managed, and cloud-native device management scenarios.
    • Develop standardized processes for device provisioning, refresh, rebuilds, feature updates, and hardware lifecycle management.
  • Endpoint Security & Compliance
    • Implement and maintain endpoint security controls, including BitLocker, Microsoft Defender, Windows LAPS, Windows Hello for Business, firewall policies, attack surface reduction rules, and security baselines.
    • Configure and monitor compliance policies to ensure devices meet organizational security requirements.
  • Application & Operating System Management
    • Package, deploy, test, and support applications using Intune, Win32 app deployment, Microsoft Store, PowerShell, and enterprise software distribution tools.
    • Plan and execute Windows feature updates and OS migrations, including readiness assessments, pilot deployments, issue remediation, reporting, and production rollouts.
    • Develop scripts, detection rules, remediation packages, and automation to improve operational efficiency.
  • Operational Support
    • Act as the escalation point for complex endpoint issues involving Windows, Intune, Autopilot, SCCM, application deployment, compliance, authentication, and device management.
    • Diagnose and resolve issues using endpoint logs, Intune reporting, Autopilot diagnostics, PowerShell, Event Viewer, SCCM client logs, and Entra device records.
    • Participate in incident response, change management, root cause analysis, and continuous service improvement.
  • Documentation & Collaboration
    • Maintain documentation for endpoint architecture, standards, policies, deployment processes, application packaging, and support procedures.
    • Partner with Security, Identity, Infrastructure, Networking, Procurement, and Service Desk teams to deliver endpoint initiatives.
    • Support audits, compliance efforts, risk assessments, and endpoint modernization projects.

Qualifications

Required Qualifications

  • 5+ years of relevant experience.
  • Strong troubleshooting skills across Windows OS, device enrollment, endpoint policy, application deployment, network connectivity, certificates, user profiles, and endpoint security controls.
  • Ability to write clear technical documentation and communicate effectively with technical and non-technical stakeholders.
  • Bachelor’s degree required.

Preferred Qualifications

  • Microsoft certifications such as Microsoft 365 Certified: Endpoint Administrator Associate, Azure Administrator Associate, or related Microsoft security and identity certifications.
  • Experience migrating from SCCM/GPO-based environments to Microsoft Intune and modern endpoint management.
  • Experience with Microsoft Entra Conditional Access, device compliance, Zero Trust, and Microsoft Defender for Endpoint.
  • Experience managing Apple Business Manager, macOS, iOS/iPadOS, and Android devices through Intune.
  • Experience with enterprise application packaging and deployment, including Win32, MSI/MSIX, detection rules, dependencies, and deployment rings.
  • Experience supporting Windows Hello for Business, Cloud Kerberos Trust, Universal Print, VPN, virtual desktop/Citrix environments, and line-of-business applications.
  • Experience using AI-assisted tools (e.g., Microsoft Copilot or Security Copilot) to improve endpoint automation, troubleshooting, reporting, and documentation.

Personal Attributes

  • Strong endpoint engineering mindset with the ability to design for scale, reliability, security, and operational simplicity.
  • Ability to modernize legacy endpoint practices while maintaining business continuity.
  • Strong analytical and troubleshooting skills.
  • Security-first mindset with practical understanding of user experience and operational supportability.
  • Ability to work independently while collaborating across multiple technical teams.
  • Strong documentation discipline and process orientation.

Pay

Base Salary: $125,000 - $160,000. In addition to a competitive base salary, you will be eligible to receive discretionary bonus incentives and a comprehensive benefits package.

Similar jobs