Intune Architect
Agility Technologies Inc · Reston, VA · 1 wk ago
RemoteRemoteArt & CreativeFull-time
About the Role
Design and lead the end-to-end Microsoft Intune architecture for a large federal enterprise, establishing secure modern management patterns across Windows, iOS/iPadOS, and Android. Define security baselines and conditional access guardrails, engineer a Blackberry UEM → Intune migration and co-management strategy (SCCM/Configuration Manager), and stand up technical governance (standards, patterns, and guardrails) to keep the environment compliant, resilient, and cost-effective. The architect partners with Security, Identity, Networking, Client Engineering, and PMO to deliver a Zero Trust-aligned endpoint platform.
Responsibilities
- Intune & Modern Management (Expert): Autopilot provisioning, device compliance, configuration profiles, application lifecycle (Win32/MSIX/MAM), update rings, and RBAC/scopes.
- Security & Compliance: Conditional Access design, BitLocker governance, Microsoft Security Baselines, Defender for Endpoint integration, threat & vulnerability workflows.
- Entra ID & Identity: Azure AD/Entra ID tenant administration, user/group design, SSO (SAML/OIDC), device identities, certificate/PKI integration.
- Automation: PowerShell scripting; configuration as code mindset; build reusable modules and reporting.
- Mobile Management (MDM/MAM): MAM/app protection policies, conditional launch controls.
- Co-Management & Migration: Hands-on experience transitioning SCCM/Configuration Manager to cloud-based Intune; defining co-management workloads and phased cutovers.
- Delivery: Lead pilots, wave plans, and executive-level briefings; strong documentation and stakeholder management.
Requirements
- Minimum 8 years of experience in a relevant field.
- 7–10+ years in endpoint management; 3–5+ years architecting Intune at enterprise scale (10k+ devices or federal programs).
- Public Trust (or higher) clearance eligibility; prior federal client experience.
Preferred Skills
- Zero Trust architecture and NIST 800-53 control mapping for endpoints; familiarity with FedRAMP/ATO processes.
- Win32 packaging at scale (IntuneWin, detection rules, dependencies), app remediation, and Autopatch/Update rings optimization.
- Advanced CA design (session controls, sign-in risk, compliant network locations), Entra ID P2 features (Identity Protection, Access Reviews).
- Defender for Endpoint advanced hunting (KQL), attack surface reduction (ASR), tamper protection, and automated response playbooks.
- Enterprise certificate management (device certs, SCEP/PKCS), Wi-Fi/VPN profiles, and network prerequisites.
- Terraform/Bicep or pipeline-driven deployments for repeatable config; Git-based governance for profiles/policies.
- Incident response and DR runbooks for endpoint outages; executive communications and change management expertise.
Benefits
- 401(k) matching
- Dental insurance
- Health insurance
- Paid time off
- Parental leave
- Vision insurance
This is a remote position.