Architect - Enterprise Modern Workplace (remote)

Posted 18 Days Ago
Be an Early Applicant
Hiring Remotely in Denver, CO, USA
In-Office or Remote
110K-164K Annually
Senior level
Aerospace • Travel
The Role
Lead the architecture and administration of endpoint, identity, and Microsoft 365 ecosystems. Provide technical leadership for Intune, Entra ID/Active Directory, endpoint security (Defender), ManageEngine, Zscaler, and Exchange Online. Implement security controls, automate via PowerShell, manage device lifecycle, patching, app deployment, and collaborate with cybersecurity, infrastructure, service desk, and business stakeholders. Support hybrid cloud/on-prem environments with 25% travel.
Summary Generated by Built In

Working at Frontier Airlines 

At Frontier, our mission is to Make Every Flight Count. That mission guides how we support our customers, our people and the operation every day. 

As a Frontier employee, your work connects to more than a single role. Whether you’re supporting flights, helping customers, maintaining aircraft, leading teams or working behind the scenes, you help create a travel experience that is safe, reliable and built around value. 

Our work is guided by our core values: customer first, safety always, operational excellence and one team. These values shape how we make decisions, support each other and deliver for the people who count on us. 

Support for work, life and travel 

Frontier offers benefits, programs and travel privileges designed to support eligible employees at work and beyond. Availability may vary by role, employment status, eligibility, location, schedule, applicable policies and current plan details. 

Depending on role and eligibility, available benefits and programs may include: 

  • Medical, dental and vision coverage 
  • 401(k) retirement savings options 
  • Paid holidays, vacation time and sick time 
  • Travel privileges on Frontier Airlines and participating partner airlines, based on current program rules and availability 
  • Buddy passes, based on eligibility and program rules 
  • Travel-related discounts and employee discounts on select products, services and vendors 
  • A hybrid schedule for eligible headquarters roles based in Denver, Colorado 
  • Business casual dress options for eligible corporate and support roles 
  • Employee support programs and resources, including the HOPE League, Frontier Airlines’ nonprofit organization 

About Frontier Airlines 

Frontier Airlines is a Denver-based airline serving destinations across the United States and select international markets. Our people support every part of the travel journey, from airport operations and flight crews to aircraft maintenance, customer support, corporate teams and more. 

We’re focused on delivering meaningful value by making travel more accessible, practical and easy to personalize for our customers. Across the airline, our teams help support a safe, reliable and efficient operation while continuing to strengthen the experience for the people who choose Frontier. 

What Will You Be Doing?

The Lead Enterprise Modern Workplace Engineer is responsible for the architecture, engineering, security, administration, and continuous improvement of the enterprise endpoint, identity, and Microsoft 365 ecosystems. This role provides technical leadership for endpoint management, identity services, collaboration platforms, and cybersecurity initiatives that support a secure, resilient, and compliant hybrid (Cloud & On-prem) technology environment.

The position serves as the subject matter expert for endpoint device management, Microsoft 365 administration, Entra ID (Azure AD), identity governance, authentication technologies, device security, and endpoint security architecture. Additionally, the role is responsible for identifying, recommending, and implementing cybersecurity best practices that strengthen the organization’s overall security posture and reduce operational risk.

The Lead Engineer partners closely with Cybersecurity, Infrastructure, Service Desk, Cloud Engineering, and business stakeholders to ensure enterprise technologies align with security standards, regulatory requirements, and business objectives.

This role is responsible for administering Active Directory, Microsoft Entra ID, Microsoft Intune, ManageEngine Endpoint Central, Zscaler ZIA/ZPA, Microsoft 365, and Exchange Online. The successful candidate will support user identity lifecycle processes, endpoint enrollment and compliance, device patching, application deployment, secure internet and private application access, mail administration, and Microsoft 365 services.

This position requires strong troubleshooting skills, security awareness, documentation discipline, and the ability to collaborate effectively with infrastructure, cybersecurity, networking, and service desk teams.

Essential Functions

  • Identity Administration: Manage and support Active Directory and Microsoft Entra ID objects, including users, groups, service accounts, organizational units, attributes, and identity lifecycle processes.
  • Secure Access: Administer and support Conditional Access, Multi-Factor Authentication (MFA), and related identity security controls aligned to zero trust and company security standards.
  • Endpoint Management: Configure, deploy, and maintain endpoint management capabilities using Microsoft Intune and related MDM/MAM platforms.
  • Device Enrollment and Compliance: Manage endpoint enrollment, provisioning, compliance policies, configuration profiles, and device lifecycle processes for Windows, mobile, and other supported platforms.
  • Endpoint Security: Experience configuring and supporting Defender for Endpoint.
  • Endpoint Patching: Manage device patching, software updates, and remediation activities using ManageEngine Endpoint Central and Microsoft endpoint management tools.
  • Application Deployment: Package, deploy, update, and troubleshoot applications across managed endpoints using Intune, ManageEngine Endpoint Central, and other approved tools.
  • Zscaler Administration: Support Zscaler ZIA/ZPA access policies, client connector deployment, secure internet access, and private application access troubleshooting.
  • Microsoft 365 Administration: Administer Microsoft 365 services, including licensing, collaboration services, service health monitoring, and user support.
  • Exchange Online Administration: Support mailbox administration, mail flow, distribution groups, shared mailboxes, permissions, and troubleshooting of Exchange Online issues.
  • Troubleshooting and Support: Provide advanced technical support for identity, endpoint, secure access, mail, and Microsoft 365 service issues while minimizing business disruption.
  • Security Management: Implement and maintain endpoint and identity security controls to protect users, devices, applications, and data from threats and vulnerabilities.
  • Automation and Scripting: Use PowerShell and other approved automation methods to improve administration, reporting, remediation, and operational efficiency.
  • Documentation: Maintain comprehensive documentation of identity, endpoint, access, Microsoft 365, Exchange Online, and operational procedures.
  • Collaboration: Work closely with infrastructure, cybersecurity, networking, service desk, and business teams to align platform administration with organizational goals.
  • Training and Knowledge Sharing: Provide guidance and support to IT teams and end users on endpoint, identity, secure access, and Microsoft 365 best practices.
  • Travel requirements: 25% in support of projects.
  • Other duties as assigned.

Other Functions

  • Maintain accurate records for endpoint configurations, identity objects, access policies, mail administration, and Microsoft 365 service changes
  • Adhere to documented Change Management processes to protect the integrity of the production environment
  • Manage ticket loads and ensure response time SLAs are met for identity, endpoint, access, Microsoft 365, and Exchange Online support requests
  • Develop and maintain procedures that support consistent, secure, and process-driven resolution of operational issues

Qualifications

  • Education: Bachelor’s degree in Computer Science, Information Technology, or related field or equivalent combination of education and experience required.
  • Technical Experience: At least 7 years of experience in enterprise endpoint management, identity administration, Microsoft 365 administration, or related infrastructure operations.
  • Hybrid Identity Experience: Hands-on experience supporting hybrid identity environments using Active Directory and Microsoft Entra ID.
  • Endpoint Management Experience: Experience configuring and supporting Microsoft Intune, endpoint compliance, device enrollment, application deployment, and patch management.
  • Endpoint Tooling: Experience with ManageEngine Endpoint Central or similar endpoint patching and device management platforms strongly preferred.
  • Secure Access Platforms: Experience supporting Zscaler ZIA/ZPA, client connectors, secure internet access, and private application access preferred.
  • Microsoft 365 and Exchange Online: Experience administering Microsoft 365 services and Exchange Online, including mailbox management, mail flow, permissions, and collaboration services.
  • Automation: PowerShell scripting experience for administration, reporting, troubleshooting, and process automation strongly preferred.
  • Certifications: Relevant certifications such as Microsoft Certified: Endpoint Administrator Associate, Microsoft 365 Certified Administrator, Microsoft Certified: Identity and Access Administrator Associate, JAMF Certified Admin, or similar are a plus.
  • Problem-Solving: Excellent troubleshooting and problem-solving skills.
  • Communication: Strong verbal and written communication skills.
  • Team Player: Ability to work effectively in a team-oriented environment and collaborate with infrastructure, cybersecurity, networking, and service desk teams. 

Knowledge, Skills and Abilities

  • Identity Platforms: Strong understanding of Active Directory and Microsoft Entra ID administration, including users, groups, service accounts, synchronization concepts, and hybrid identity operations.
  • Conditional Access and MFA: Knowledge of Conditional Access, Multi-Factor Authentication, identity protection, and secure access best practices.
  • Endpoint Management: Advanced skills in configuring and managing Microsoft Intune, endpoint enrollment, compliance policies, configuration profiles, and application policies.
  • Endpoint Patching: Proficiency with ManageEngine Endpoint Central or similar tools for patch deployment, software updates, endpoint inventory, and remediation.
  • Operating Systems: Knowledge of desktop and mobile operating systems such as Windows, iOS, Android, and macOS.
  • Zscaler: Knowledge of Zscaler ZIA/ZPA, client connector behavior, secure internet access, private application access, and policy troubleshooting.
  • Microsoft 365: Ability to administer Microsoft 365 services, licensing, collaboration features, service health, and user support processes.
  • Exchange Online: Knowledge of mailbox administration, mail flow, shared mailboxes, distribution groups, permissions, and Exchange Online troubleshooting.
  • Security Best Practices: Familiarity with zero trust principles, endpoint security, identity security, and secure configuration standards.
  • Networking: Basic knowledge of networking principles and how they relate to endpoint connectivity, cloud services, VPN-less access, and secure web access.
  • Compliance Standards: Understanding of compliance standards and regulations related to endpoint, identity, and access management.
  • PowerShell: Ability to use PowerShell for administration, automation, reporting, troubleshooting, and operational support.
  • Troubleshooting: Strong troubleshooting skills to diagnose and resolve identity, endpoint, secure access, Microsoft 365, and Exchange Online issues.
  • Policy Development: Ability to develop, implement, and maintain endpoint, identity, access, and application policies.
  • Software Deployment: Proficiency in deploying software, updates, and patches through Intune, ManageEngine Endpoint Central, or similar platforms.
  • Documentation: Excellent documentation skills to maintain detailed records of configurations, policies, procedures, and support processes.
  • Communication: Strong verbal and written communication skills for effective collaboration and user support.
  • Training: Ability to train and support end users and IT teams on endpoint, identity, secure access, and Microsoft 365 best practices.
  • Analytical Thinking: Ability to analyze complex technical issues and develop effective solutions.
  • Attention to Detail: High attention to detail to ensure accurate configuration and compliance with policies.
  • Adaptability: Ability to adapt to new technologies and changing environments.
  • Team Collaboration: Strong ability to work collaboratively with infrastructure, cybersecurity, networking, service desk, and other departments.
  • Time Management: Effective time management skills to prioritize tasks and meet deadlines.
  • Customer Service: Ability to provide excellent customer service and support to end users.

Equipment Operated

Standard office equipment, including PC, copier, fax machine, printer

Work Environment

  • This role can be based at our headquarters in Denver, CO or anywhere in the United States via a remote work arrangement (periodic travel to Denver from a Frontier-serviced city required)
  • If remote, you must be able to follow our remote work policies, including ability and comfort level working from home with access to a high-speed internet connection
  • If headquarters-based, typical office environment, adequately heated and cooled

Physical Effort

Generally, not required.

Supervision Received

General Supervision:  The incumbent performs a variety of routine work within established policies and procedures and receives detailed instructions on new projects and assignments.

Salary Range: $110,114 - $163,873 - Please note: this role will close on or before 8/24/26.

Positions Supervised

None

Workplace Policies

Disclaimer: The above statements are intended only to describe the general nature and level of work required of the referenced position; they are not intended to be an exhaustive list of all responsibilities, duties, and skills required of individuals in this position.  Please be advised that duties and expectations of this position may be subject to change.

Frontier Airlines, Inc. is an equal opportunity employer and, as such, is committed to providing equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, national origin, age, marital status, veteran status, sexual orientation, gender identity or expression, disability status, pregnancy, genetic information, citizenship status or any other basis protected by federal, state, or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

Frontier Airlines is a Zero Tolerance Drug-Free Workplace. All prospective DOT safety-sensitive employees are subject to pre-employment testing for the following drugs and their metabolites: Marijuana, Cocaine, Amphetamines, Opioids and Phencyclidine (PCP). Further, any DOT safety-sensitive job applicant who is found to have tested positive on any required drug or alcohol test at a former employer will be considered ineligible for employment with Frontier.

Colorado Residents: In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Skills Required

  • Bachelor's degree in Computer Science, Information Technology, or related field (or equivalent experience)
  • At least 7 years experience in enterprise endpoint management, identity administration, Microsoft 365 administration, or related infrastructure operations
  • Hands-on experience supporting hybrid identity environments using Active Directory and Microsoft Entra ID (Azure AD)
  • Experience configuring and supporting Microsoft Intune (endpoint enrollment, compliance, configuration profiles, application deployment)
  • Experience configuring and supporting Defender for Endpoint and endpoint security controls
  • Experience administering Microsoft 365 services and Exchange Online (mailbox admin, mail flow, permissions, collaboration services)
  • Experience with endpoint patching, software updates, and remediation using ManageEngine Endpoint Central or similar
  • Experience supporting Zscaler ZIA/ZPA, client connector deployment, and private application access
  • PowerShell scripting for administration, automation, reporting, remediation and troubleshooting
  • Relevant certifications (Microsoft Endpoint Administrator, Microsoft 365 Administrator, Identity and Access Administrator, JAMF Certified Admin, or similar)
  • Knowledge of desktop and mobile operating systems (Windows, iOS, Android, macOS)
  • Experience implementing Conditional Access, Multi-Factor Authentication, identity protection, and zero trust principles
  • Strong troubleshooting and problem-solving skills for identity, endpoint, secure access, and Microsoft 365 issues
  • Strong verbal and written communication skills and ability to collaborate with infrastructure, cybersecurity, networking, and service desk teams
  • Documentation discipline and ability to maintain procedures, change records, and configuration documentation
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Denver, CO
4,789 Employees
Year Founded: 1994

What We Do

Frontier Airlines (NASDAQ: ULCC) is committed to “Low Fares Done Right.” Headquartered in Denver, Colorado, the company operates 120 A320 family aircraft and has the largest A320neo family fleet in the U.S. The use of these aircraft, Frontier’s seating configuration, weight-saving tactics and baggage process have all contributed to Frontier’s continued ability to be the most fuel-efficient of all major U.S. carriers when measured by available seat miles (ASMs) per fuel gallon consumed. With more than 230 new Airbus planes on order, Frontier will continue to grow to deliver on the mission of providing affordable travel across America.

Similar Jobs

Cleo Logo Cleo

Senior Project Manager

Cloud • eCommerce • Information Technology • Professional Services • Software
Remote or Hybrid
United States
500 Employees
110K-130K Annually

Rocket Logo Rocket

Executive Loan Officer (Denver, CO)

Fintech • Real Estate • Sales • Financial Services
Remote
Colorado, USA
14200 Employees
17-17 Hourly

MetLife Logo MetLife

Consultant

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
55K-70K Annually
Easy Apply
Remote or Hybrid
3 Locations
4405 Employees
111K-168K Annually

Similar Companies Hiring

PRIMA Thumbnail
Travel • Software • Marketing Tech • Hospitality • eCommerce
US
15 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account