Systems Engineer IV
About the role
The Senior Mobile Endpoint Systems Engineer leads the strategy, design, deployment, and ongoing management of enterprise mobile and endpoint solutions across Windows, macOS, iOS, and Android platforms. This role is the primary subject matter expert for Mobile Device Management (MDM), Mobile Application Management (MAM), and zero-touch device enrollment programs.
Responsibilities
Design, deploy, and manage enterprise MDM/MAM platforms (Microsoft Intune, Kandji/SOTI) with a primary focus on mobile fleet management across iOS, Android, Windows, and macOS.
Architect and administer zero-touch enrollment programs including Apple Business Manager (ABM/DEP), Android Enterprise (Zero-Touch) and Windows Autopilot.
Implement, and enforce BYOD, COPE, and COBO device policies aligned with corporate security standards and regulatory requirements.
Create and manage mobile app protection policies, app configuration profiles, and conditional access policies via Microsoft Intune and Entra ID.
Collaborate with the security team to enforce zero-trust endpoint principles, including device compliance, identity-based access, and continuous monitoring.
Manage endpoint security controls, patch management, software deployment, and compliance policy frameworks across all device types.
Diagnose and resolve complex technical issues across the endpoint stack (hardware, OS, application, MDM policy) including escalated tier 3 incidents.
Create and maintain comprehensive documentation for mobile/endpoint architecture, enrollment procedures, policy configurations, and operational runbooks.
Provide leadership, coaching, and mentoring to junior engineers and support staff; act as a technical escalation point across the endpoint practice.
Evaluate emerging mobile and endpoint technologies, vendors, and industry trends; provide recommendations to leadership.
Qualifications
Bachelor's degree in Computer Science, Information Technology, or equivalent professional experience.
5+ years in endpoint engineering or device management roles, with at least 2 years focused on mobile endpoint management (Android at scale).
Deep proficiency with MDM/MAM platforms: Microsoft Intune (required), Kandji, and/or SOTI.
Hands-on experience with Apple Business Manager (ABM), Android Enterprise and Windows Autopilot enrollment programs.
Strong understanding of Conditional Access, Entra ID (Azure AD) device compliance, and app protection policies.
Proficiency in scripting and automation: PowerShell (required), Bash, and/or Python for endpoint lifecycle automation.
Solid understanding of BYOD, COPE, and COBO program design, legal/privacy considerations, and policy enforcement.
Familiarity with endpoint security frameworks (CIS Benchmarks, NIST, DISA STIGs) and patch management best practices.
Excellent problem-solving, analytical, and written/verbal communication skills.