Remote job
Lead Endpoint Engineering Architect
Job details
About this role
Role overview
The Lead Endpoint Engineering Architect owns the architecture and build-out of a modern endpoint management platform covering roughly 1,000 Windows devices across corporate, lab, and field locations. This is a hands-on technical position—not a people-management role—centered on engineering a reliable platform using Microsoft Intune, Autopilot, and Entra ID, then handing day-to-day operations to the existing support team through clear runbooks and documentation. The role partners closely with IT Security, Quality, and business stakeholders, but the core of the work is configuration design, application packaging, PowerShell scripting, deployment testing, and problem solving.
Responsibilities
- Own end-to-end design and implementation of the Intune and Autopilot environment, including enrollment profiles, configuration profile architecture, compliance policies, Conditional Access, and Windows update ring strategy. - Build Autopilot provisioning workflows that allow factory-sealed laptops to ship to any employee and arrive fully configured without technician intervention, including selecting deployment modes for different device scenarios. - Create a layered Intune configuration profile structure: security baselines that apply to everything, role-specific profiles for different groups, and targeted exception policies. - Design and own application deployment using Intune's Win32 packaging model with proper dependency chains, detection rules that verify successful installs, and a consistent test-before-deploy process. - Build Proactive Remediations that detect and auto-fix common endpoint issues such as dropped network drives, configuration drift, and application health problems before users contact the help desk. - Establish laptop performance baselines and remediation workflows using Proactive Remediations, Endpoint Analytics, and Windows performance counters to enforce consistent startup time, memory, and CPU standards across hardware models. - Design, build, and maintain SharePoint Online sites, libraries, and lists supporting departmental workflows, including permissions, lifecycle governance, and troubleshooting. - Partner with IT Security on compliance policies and Conditional Access rules that deliver continuous, auditable proof of endpoint security posture. - Author architecture diagrams, runbooks, application packaging standards, and troubleshooting guides; train deskside and help desk staff on Intune operations. - Evaluate endpoint management tools and OEM driver management solutions for the hardware fleet as needs arise.
Requirements
- Deep hands-on experience with Microsoft Intune, Autopilot, Entra ID, and Windows Update for Business ring management. - Strong PowerShell scripting ability and proven Win32 application packaging expertise. - Working knowledge of Conditional Access, compliance reporting, and endpoint security baselines. - Demonstrated ability to produce clear technical documentation, runbooks, and troubleshooting guides. - Strong analytical, conceptual, and problem-solving skills with the ability to handle multiple priorities under urgency and meet deadlines. - Ability to operate effectively in a remote or professional office environment with standard office equipment.
Benefits and work setup
- Remote-eligible professional work environment. - Annual base salary range of $195,000–$210,000 USD, with individual pay decisions based on primary work location, role complexity, and relevant experience. - Equal-opportunity employer committed to a diverse and inclusive workplace, with reasonable accommodations available for applicants and employees.