Jobs · Information Technology · New York

Senior Windows Engineer, Endpoint Engineering

Ares Management · New York, NY · 4 days ago
HybridInformation TechnologyFull-time

Job Description

The Senior Windows/SCCM/Intune Engineer is responsible for the architecture, engineering, automation, security, and lifecycle management of the firm's global Windows endpoint environment. This role serves as a senior technical leader within End User Engineering, driving enterprise device management strategies across Microsoft Configuration Manager (SCCM/MECM), Microsoft Intune, Microsoft Entra ID, and Windows 11 platforms.

Primary Functions & Responsibilities

  • Design, implement, and support enterprise Windows endpoint management solutions.

  • Manage and optimize Microsoft Configuration Manager (SCCM/MECM) infrastructure.

  • Lead migration initiatives from traditional SCCM management toward cloud-native management using Microsoft Intune.

  • Engineer and maintain Microsoft Intune policies for device compliance, configuration, security baselines, endpoint protection, and application deployment.

  • Develop and maintain device provisioning strategies utilizing: Windows Autopilot, Microsoft Intune, Hybrid Azure AD Join, Entra ID Join.

  • Establish endpoint configuration standards across global environments.

  • Drive hardware refresh and operating system modernization initiatives.

  • Maintain endpoint inventory, reporting, and lifecycle management processes.

Operating System Engineering

  • Lead Windows 11 deployment, maintenance, and upgrade programs.

  • Develop and maintain enterprise OS deployment task sequences and Autopilot provisioning packages.

  • Engineer standardized endpoint configuration profiles and provisioning methodologies.

  • Manage feature updates, quality updates, and servicing channels.

  • Perform application compatibility testing and remediation.

  • Develop rollback and contingency plans for large-scale deployment initiatives.

Application Packaging & Deployment

  • Package, test, deploy, and maintain enterprise software solutions.

  • Develop deployment methodologies utilizing: Intune Win32 Applications, SCCM Applications, PowerShell, Winget.

  • Create detection methods, superseding strategies, and deployment automation workflows.

  • Manage application lifecycle processes from onboarding through retirement.

Automation & Scripting

  • Develop automation solutions using: PowerShell, PowerShell App Deployment Toolkit (PSADT), Graph API, Azure Automation, Azure Functions.

  • Create self-healing and proactive remediation scripts.

  • Develop reporting, monitoring, and compliance automation solutions.

  • Reduce operational overhead through infrastructure-as-code methodologies.

Endpoint Security & Compliance

  • Partner with Information Security teams to implement endpoint security controls.

  • Engineer and maintain: Intune Patch Management / Autopatch, SCCM/WSUS software updates, Attack Surface Reduction Rules, Device Control Policies, BitLocker Encryption, Security Baselines, Group Policy Management, Conditional Access integrations.

  • Ensure compliance with regulatory and corporate security requirements.

  • Evaluate vulnerabilities and coordinate remediation activities.

  • Support audit readiness and security reviews.

Microsoft Cloud Technologies

  • Support and integrate: Microsoft Intune, Microsoft Entra ID, Microsoft Defender, Microsoft 365 Apps, Windows Update for Business, Microsoft Graph.

  • Develop modern management strategies aligned with Microsoft's cloud-first approach.

  • Manage co-management capabilities between SCCM and Intune.

  • Optimize device management through cloud-based services and automation.

Digital Employee Experience (DEX)

  • Utilize Digital Experience Monitoring tools such as: Nexthink, Microsoft Endpoint Analytics, Lakeside SysTrack, ControlUp, Anlyze endpoint health and performance trends.

  • Develop initiatives to improve: Device performance, Boot times, Reliability, Application experience, Employee productivity.

  • Create executive-level reporting and operational dashboards.

Qualifications

  • Education: Bachelor’s degree in Computer Science, Information Systems, Engineering, or related technical field. Advanced degree strongly preferred.

  • Required Experience:

    • 7+ years of enterprise endpoint engineering experience.

    • 5+ years managing Microsoft Configuration Manager (SCCM/MECM).

    • 3+ years managing Microsoft Intune in a large enterprise environment.

    • Experience supporting environments with 5,000+ endpoints preferred.

    • Experience in financial services, healthcare, legal, or highly regulated industries preferred.

  • Preferred Certifications:

    • Microsoft Certified: Endpoint Administrator Associate

    • Microsoft Certified: Azure Administrator Associate

    • Microsoft Certified: Enterprise Administrator Expert

    • Microsoft Certified: Security Operations Analyst Associate

    • ITIL Foundations

    • MCM, MCSE, or equivalent legacy Microsoft certifications

  • Technical Skills:

    • Expert Knowledge: Windows 11 administration, Microsoft Configuration Manager (SCCM/MECM), Microsoft Intune, Windows Autopilot, PowerShell scripting, Microsoft Entra ID, Group Policy Management, Endpoint security technologies, Software packaging and deployment.

    • Advanced Knowledge: Co-Management, Windows Update for Business, Microsoft Defender for Endpoint, BitLocker, Conditional Access, Azure Automation, Microsoft Graph API, Active Directory, DNS/DHCP fundamentals, PKI/Certificate Services.

  • Preferred Skills:

    • Microsoft 365, Defender XDR, ServiceNow, Azure Virtual Desktop, Windows 365, Azure Infrastructure, Enterprise mobility management, Zero Trust architectures.

  • General Requirements:

    • Strong written and verbal communication skills.

    • Experience working in global enterprise environments, preferably in financial services or other highly regulated environments.

    • Willingness to travel (approximately 10-25%).

Compensation

The anticipated rate for this position is listed below. Total compensation may also include a discretionary performance-based bonus. $125,000 - $140,000

The firm also offers robust Benefits offerings. Ares U.S. Core Benefits include Comprehensive Medical/Rx, Dental and Vision plans; 401(k) program with company match; Flexible Savings Accounts (FSA); Healthcare Savings Accounts (HSA) with company contribution; Basic and Voluntary Life Insurance; Long-Term Disability (LTD) and Short-Term Disability (STD) insurance; Employee Assistance Program (EAP), and Commuter Benefits plan for parking and transit. Ares offers a number of additional benefits including access to a world-class medical advisory team, a mental health app that includes coaching, therapy and psychiatry, a mindfulness and wellbeing app, financial wellness benefit that includes access to a financial advisor, new parent leave, reproductive and adoption assistance, emergency backup care, matching gift program, education sponsorship program, and much more.

Similar jobs