Endpoint Engineer

Posted 11 Days Ago
Be an Early Applicant
2 Locations
In-Office or Remote
Senior level
Hardware • Other • Software • Appliances • Industrial • Manufacturing
The Role
Designs, secures, automates, and manages enterprise Windows and Apple endpoints using Intune, SCCM/MECM, Autopilot, and Jamf Pro. Leads SCCM-to-cloud modernization, zero-touch provisioning, endpoint security, application packaging, compliance, remediation, and lifecycle automation. Provides Level 3 support, resolves complex endpoint issues, establishes engineering standards, documents architecture and procedures, collaborates with technology teams, and mentors junior engineers.
Summary Generated by Built In
Endpoint Engineer Role Overview

The Endpoint Engineer is responsible for the design, engineering, security, automation, and lifecycle management of enterprise Windows and Apple endpoints. This role serves as a technical subject matter expert for Microsoft Intune, SCCM/MECM, Windows Autopilot, Jamf Pro, endpoint provisioning, security configuration, and Endpoint Privilege Management (EPM).

The engineer will lead initiatives to modernize endpoint management, transition legacy management capabilities toward cloud-native solutions, improve endpoint security, automate provisioning and remediation, and establish scalable endpoint engineering standards across the enterprise.

Key Responsibilities
  • Design, engineer, and maintain enterprise endpoint management solutions using Microsoft Intune, SCCM/MECM, Jamf Pro, and Windows Autopilot.
  • Serve as a technical SME for Windows and macOS endpoint architecture, management, provisioning, security, and troubleshooting.
  • Lead the modernization and migration of traditional SCCM workloads toward Intune and cloud-native endpoint management.
  • Design and maintain Intune configuration profiles, compliance policies, security baselines, device restrictions, and remediation solutions.
  • Architect and optimize Windows Autopilot and Apple Automated Device Enrollment to provide standardized zero-touch provisioning.
  • Engineer SCCM/Intune co-management solutions and determine appropriate workload migration strategies.
  • Administer and engineer Jamf Pro for enterprise macOS management, including configuration, application deployment, FileVault, security policies, scripting, and automated provisioning.
  • Design endpoint security standards using technologies including Microsoft Defender for Endpoint, BitLocker, FileVault, Attack Surface Reduction, Windows Firewall, device control, application control, and security baselines.
  • Design and implement Microsoft Intune Endpoint Privilege Management (EPM) to reduce permanent local administrator access and enforce least-privilege principles.
  • Develop and maintain application packaging and deployment solutions across Intune, SCCM, and Jamf.
  • Develop automation using PowerShell, Microsoft Graph API, Graph PowerShell SDK, REST APIs, and shell scripting.
  • Automate device provisioning, application deployment, configuration validation, compliance reporting, security remediation, inventory, and endpoint lifecycle activities.
  • Integrate endpoint compliance and security controls with Microsoft Entra ID and Conditional Access.
  • Establish engineering standards for endpoint provisioning, configuration, security, patching, application deployment, and lifecycle management.
  • Provide Level 3 engineering support and root-cause analysis for complex Windows, macOS, enrollment, provisioning, application, and security issues.
  • Partner with Cybersecurity, IAM, Infrastructure, Service Desk, and other technology teams to align endpoint architecture with enterprise security and operational requirements.
  • Create technical standards, architecture documentation, SOPs, implementation plans, and operational procedures.
  • Mentor junior engineers and support teams while providing technical leadership for endpoint initiatives.
Required Qualifications
  • 6+ years of experience in endpoint engineering, desktop engineering, endpoint security, or enterprise device management.
  • Advanced experience with Microsoft Intune and SCCM/MECM.
  • Strong experience with Windows Autopilot and modern Windows provisioning.
  • Experience administering and engineering Jamf Pro and enterprise macOS environments.
  • Strong knowledge of Windows 10/11, macOS, Entra ID, device identity, and Conditional Access.
  • Strong PowerShell scripting and automation experience.
  • Experience with application packaging, deployment, patching, and remediation.
  • Strong understanding of endpoint security, least privilege, device compliance, and configuration management.
  • Experience designing and implementing enterprise-scale endpoint solutions.
  • Demonstrated ability to troubleshoot complex endpoint and provisioning issues.
Preferred Qualifications

Experience with Intune Endpoint Privilege Management, Microsoft Defender for Endpoint, Microsoft Graph API, Windows Hello for Business, Apple Business Manager, enterprise PKI/certificate-based authentication, CIS/Microsoft security benchmarks, vulnerability management, and large-scale SCCM-to-Intune modernization initiatives is highly desirable.

Skills Required

  • 6+ years of experience in endpoint engineering, desktop engineering, endpoint security, or enterprise device management
  • Advanced experience with Microsoft Intune and SCCM/MECM
  • Strong experience with Windows Autopilot and modern Windows provisioning
  • Experience administering and engineering Jamf Pro and enterprise macOS environments
  • Strong knowledge of Windows 10/11, macOS, Entra ID, device identity, and Conditional Access
  • Strong PowerShell scripting and automation experience
  • Experience with application packaging, deployment, patching, and remediation
  • Strong understanding of endpoint security, least privilege, device compliance, and configuration management
  • Experience designing and implementing enterprise-scale endpoint solutions
  • Demonstrated ability to troubleshoot complex endpoint and provisioning issues
  • Experience with Intune Endpoint Privilege Management, Microsoft Defender for Endpoint, Microsoft Graph API, Windows Hello for Business, Apple Business Manager, enterprise PKI or certificate-based authentication, security benchmarks, vulnerability management, or SCCM-to-Intune modernization

Fortive Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Fortive and has not been reviewed or approved by Fortive.

  • Parental & Family Support Parental leave is fully paid for 12 weeks for all parents, with fertility coverage via Progyny and generous adoption/surrogacy support. Backup child and adult care plus inclusive eligibility extend support across diverse family structures.
  • Healthcare Strength Multiple PPO and HSA medical options include telemedicine and second-opinion services, alongside robust mental-health access through Spring Health with no‑cost therapy sessions. The breadth of medical and behavioral health resources is highlighted as a strength.
  • Retirement Support The 401(k) provides a competitive employer match each pay period, with an additional company retirement contribution after one year of service. Financial wellness tools and an employee stock purchase plan further bolster long‑term savings.

Fortive Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Everett, WA
13,486 Employees
Year Founded: 2016

What We Do

Fortive’s essential technology makes the world stronger, safer, and smarter. We accelerate transformation across a broad range of applications including environmental, health and safety compliance, industrial condition monitoring, next-generation product design, and healthcare safety solutions. We are a global industrial technology innovator with a startup spirit. Our forward-looking companies lead the way in software-powered workflow solutions, data-driven intelligence, AI-powered automation, and other disruptive technologies. We’re a force for progress, working alongside our customers and partners to solve challenges on a global scale, from workplace safety in the most demanding conditions to groundbreaking sustainability solutions. We are a diverse team 18,000 strong, united by a dynamic, inclusive culture and energized by limitless learning and growth. We use the proven Fortive Business System (FBS) to accelerate our positive impact. At Fortive, we believe in you. We believe in your potential—your ability to learn, grow, and make a difference. At Fortive, we believe in us. We believe in the power of people working together to solve problems no one could solve alone. At Fortive, we believe in growth. We’re honest about what’s working and what isn’t, and we never stop improving and innovating. Fortive: For you, for us, for growth.

Similar Jobs

SonicWall Logo SonicWall

Staff Engineer

Security • Cybersecurity
In-Office or Remote
Pune, Maharashtra, IND
1832 Employees

Zimperium Logo Zimperium

Support Engineer

Machine Learning • Mobile • Security
Remote
India
237 Employees
In-Office or Remote
2 Locations
10000 Employees
Remote
India
35 Employees

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account