IT Senior Endpoint Engineer - Microsoft Endpoint Configuration Manager (MECM) & Intune
What You'll Do
As a hands-on technical specialist, you will serve as the enterprise owner for endpoint management across Windows devices. Your primary responsibility will be the design, configuration, operation, and troubleshooting of Microsoft Endpoint Configuration Manager (MECM) and Microsoft Intune, along with the Azure/Entra ID services that keep Intune resilient and secure.
You will drive patch/update compliance, application and Operating System (OS) deployments, client health, and co-management strategy Microsoft Endpoint Configuration Manager (MECM + Intune), while closely collaborating with Cybersecurity, Network, and Support teams to ensure reliability, security, and compliance of our endpoint fleet.
You are responsible for maintaining a thorough knowledge of applicable Federal, State, Department of Energy (DOE), Corporate and Plant rules, regulations, and Plant-wide operating policies and procedures.
Essential Job Duties
Microsoft Core Infrastructure (MCM) Platform Ownership & Optimization
- Own, administer, and continually optimize MCM core infrastructure (site server, Management Point (MP)/Distribution Point (DP) roles, Structured Query Language (SQL), Windows Server Update Services (WSUS)/Software Update Point (SUP), boundary groups, content distribution, and backup/disaster recovery (DR) readiness).
- Drive client-health improvement using telemetry, automation, and consistent collection hygiene.
- Enhance platform performance and scalability across multiple locations and networks.
OS Deployment (OSD) Engineering
- Lead design, maintenance, and modernization of OSD task sequences for Windows 11.
- Engineer efficient driver-lifecycle management, secure imaging standards, pre-provisioning (BitLocker), post-install hardening, and automation to reduce build time and increase reliability.
- Evaluate migration from traditional OSD to Autopilot-first strategies where appropriate.
Software Packaging & Deployment
- Establish packaging standards and best practices for Microsoft Installer (MSI)/Executable File (EXE)/Win32 deployments across MECM and Intune.
- Build, test, and deploy applications at scale; optimize distribution-point content placement and success-rate visibility.
- Expand capabilities using third-party patch/catalog solutions to increase coverage.
Patch & Update Compliance
- Lead monthly update cycles for Windows OS, Microsoft 365 Apps, and third-party applications.
- Rapidly remediate non-compliant devices through automation and targeted deployments.
- Ensure WSUS/SUP synchronization health and maintain a reliable update pipeline.
Intune & Modern Device Management
- Own Intune configuration strategy, including Autopilot, configuration profiles, compliance policies, and Windows Update for Business rings.
- Implement and maintain Endpoint Security Baselines (BitLocker, Defender, firewall, attack surface reduction, Credential Guard).
- Drive clarity and evolution of MECM/Intune workload split using co-management and Tenant Attach.
Identity & Security Integration
- Manage Entra ID (Azure AD) device identity, Conditional Access policies, role-based access control, and SCEP/NDES/PKI integrations.
- Ensure secure enrollment, compliance signaling, and alignment with cybersecurity requirements.
Automation, Monitoring & Troubleshooting
- Use PowerShell, Microsoft Graph Application Programming Interface (API), Kusto Query Language (KQL) (Log Analytics/Azure Monitor), and SQL Server Reporting Services (SSRS)/Power Business Intelligence (BI) reporting to automate operations and improve visibility.
- Troubleshoot complex endpoint failures (Windows Management Instrumentation (WMI), Background Intelligent Transfer Service (BITS), policy conflict, client registration, SUP sync, Cloud Management Gateway (CMG) connectivity) and deliver long-term fixes.
Documentation & Leadership
- Create and maintain enterprise runbooks, engineering standards, and troubleshooting guides.
- Lead technical workshops, mentor peers, and contribute to continuous improvement of endpoint management processes.
- Bachelor's degree in engineering/science/information technology discipline: Minimum 2 years of relevant experience.
- OR Master's degree in engineering/science/information technology discipline.
- OR applicants without a bachelor's degree may be considered based on a combination of at least 10 years of completed education and/or relevant experience.
- Department of Energy (DOE) Order 426.2A Requirements: Not applicable.
- Expert-level experience with MCM administration, OSD engineering, software distribution, client health, and update compliance.
- Strong experience with Intune, Autopilot, configuration profiles, compliance/policy management, and Windows security baselines.
- Deep PowerShell scripting capability, operational analytics knowledge (Log Analytics/KQL, SSRS, Power BI).
- Proven ability to diagnose and resolve complex Windows/MECM/Intune issues at scale.
- Experience with CMG, Tenant Attach, and defining MECM/Intune co-management workloads.
- Experience optimizing MECM SQL performance and WSUS/SUP maintenance.
- Experience with Secure Communications Interoperability (SCUP) or third-party patching solutions.
- Relevant Microsoft certifications (MD-102, SC-300, AZ-104, AZ-500) or equivalent hands-on proficiency.