Senior Infrastructure and Systems Engineer

Reposted 11 Days Ago
Be an Early Applicant
Watertown, MA, USA
In-Office
115K-200K Annually
Senior level
Healthtech • Biotech • Pharmaceutical
The Role
The Endpoint Systems Engineer will provide advanced support for Windows endpoints, manage security compliance, and handle identity and access management within a hybrid environment, focusing on optimizing user experience and system reliability.
Summary Generated by Built In
Who we are:

Kymera is a clinical-stage biotechnology company pioneering the field of targeted protein degradation (TPD) to develop medicines that address critical health problems and have the potential to dramatically improve patients’ lives. Kymera is deploying TPD to address disease targets and pathways inaccessible with conventional therapeutics. Having advanced the first degrader into the clinic for immunological diseases, Kymera is focused on building an industry-leading pipeline of oral small molecule degraders to provide a new generation of convenient, highly effective therapies for patients with these conditions. Founded in 2016, Kymera has been recognized as one of Boston’s top workplaces for the past several years. For more information about our science, pipeline and people, please visit www.kymeratx.com or follow us on X (formerly Twitter) or LinkedIn. 


How we work:
  • PIONEER: We are courageous, resilient and rigorous in our mission to improve patients’ lives through our revolutionary degrader medicines.
  • COLLABORATE: We value trust + transparency from everyone. Our goals are shared, our decisions data-driven and our camaraderie genuine.
  • BELONG: We recognize our differences, inviting curiosity and inclusivity, so that our people are valued, seen, and heard.

Kymera Therapeutics is seeking a Senior Infrastructure & Systems Engineer to serve as a technical peer and force multiplier for the Senior Director of Infrastructure & Operations. This role provides technical leadership for the organization's endpoint computing platform and broader infrastructure within a hybrid Microsoft ecosystem, serving as the senior engineering resource responsible for designing, implementing, securing, and optimizing endpoint management technologies while acting as the highest level of technical escalation for complex infrastructure issues.

The successful candidate will drive the evolution of Kymera's modern workplace by leveraging Microsoft Intune, Microsoft 365, Entra ID, Windows client engineering, automation, and cloud technologies to deliver secure, scalable, and highly available endpoint services. This position partners closely with Infrastructure, Cybersecurity, Identity, and Enterprise Applications teams to modernize endpoint architecture, improve operational maturity, and implement engineering best practices across the organization.

The ideal candidate possesses a cloud-first engineering mindset while maintaining deep expertise across hybrid environments. They understand enterprise systems as interconnected platforms rather than isolated technologies and are comfortable designing solutions that improve security, automation, and user experience across the enterprise. The right candidate operates independently, takes strong ownership of their work, and is committed to reducing single points of failure through automation and documentation.


 

 

Core Responsibilities

Endpoint Engineering and Modern Device Management

  • Architect, implement, and maintain enterprise endpoint management solutions using Microsoft Intune and Company Portal
  • Design and maintain application deployment strategies utilizing Win32 packaging, Microsoft Store integration, Microsoft 365 Apps, and PowerShell automation
  • Develop and maintain configuration profiles, compliance policies, security baselines, remediation scripts, and update rings
  • Engineer and optimize Windows Autopilot deployments including Enrollment Status Page (ESP) configurations, provisioning workflows, Windows Hello for Business, and lifecycle management
  • Develop standards for endpoint configuration, provisioning, and device governance
  • Lead initiatives to modernize endpoint management through cloud-native technologies
  • Support macOS and iPadOS devices in an enterprise MDM context alongside Windows. A key opportunity within this role is to establish and mature Apple device management practices including MDM enrollment, compliance policies, and lifecycle management
  • Serve as L3 escalation point for the deskside support team, building on prior work rather than re-diagnosing from scratch

Windows Systems Engineering

  • Engineer and support Windows 11 enterprise platforms with a focus on performance, reliability, and security
  • Perform deep operating system analysis including boot performance, driver architecture, Windows servicing, registry, profile management, and application compatibility
  • Analyze Windows internals using Event Viewer, Performance Monitor, ProcMon, Reliability Monitor, ETW traces, and Windows diagnostic tools
  • Lead root cause analysis of recurring endpoint issues and implement permanent engineering solutions
  • Evaluate new Microsoft technologies and recommend improvements to the enterprise endpoint platform

Identity and Access Management

  • Advanced Active Directory and Entra ID administration in a hybrid environment including Azure AD Connect, conditional access, hybrid join states, and Privileged Identity Management
  • Okta and Microsoft Entra ID administration including SSO integrations, enterprise application registrations, user provisioning, MFA policy management, and agent health monitoring across a hybrid identity environment
  • Troubleshoot complex authentication, synchronization, token, Kerberos, and hybrid identity issues spanning on-premises Active Directory, Entra ID, and Okta
  • Support identity lifecycle processes for users, devices, and service accounts
  • Partner with Infrastructure and Security teams to strengthen identity governance and Zero Trust initiatives
 

 

Automation and Scripting

  • Advanced PowerShell scripting and Microsoft Graph API proficiency are core requirements. The environment relies heavily on custom automation across identity, endpoint management, and operational workflows. The candidate must be able to read, maintain, extend, and build complex scripts and Graph API integrations from scratch including Azure Automation runbooks and scheduled operational tasks.
  • Administer and maintain Power Automate flows integrated with SharePoint, Azure Automation, and identity systems
  • Troubleshoot flow failures, manage connections, and improve existing automation reliability
  • Build reusable automation solutions that improve operational efficiency and reduce manual effort
  • Create reporting dashboards and health monitoring scripts for endpoint compliance and operational metrics

Microsoft 365 and Collaboration

  • Advanced Exchange Online administration including mail flow rules, connectors, transport policies, message tracing, and the ability to diagnose and resolve complex email delivery issues
  • Advanced SharePoint Online administration including site lifecycle management, permissions, governance, and the ability to research and resolve complex issues independently
  • Microsoft Teams administration
  • Troubleshoot cross-service Microsoft 365 issues involving authentication, licensing, permissions, and collaboration services

Endpoint Security Engineering

  • Engineer endpoint security controls in partnership with the cybersecurity team including Microsoft Defender for Endpoint, Attack Surface Reduction, BitLocker, Windows Firewall, and endpoint hardening standards
  • Perform initial triage of endpoint and infrastructure security alerts before escalation
  • Support vulnerability management, compliance reporting, and endpoint security assessments
  • Participate in incident response activities involving endpoint compromise or identity-related threats

Hardware Lifecycle

  • Establish standards for enterprise hardware lifecycle management
  • Coordinate OEM warranty services, vendor escalations, and hardware replacement programs
  • Utilize enterprise diagnostic tools to distinguish hardware, firmware, and operating system issues
  • Evaluate new endpoint hardware platforms for enterprise deployment

Documentation and Technical Leadership

  • Author and maintain technical documentation, runbooks, engineering standards, and operational SOPs
  • Mentor junior engineers and deskside support staff while promoting engineering best practices
  • Lead root cause analysis efforts and post-incident reviews for critical endpoint issues
  • Drive continuous service improvement through automation, standardization, and operational maturity
 

 

Where You'll Contribute

In addition to core responsibilities, this role contributes across a broad infrastructure stack in collaboration with the wider infrastructure team. While endpoint management and identity remain the primary focus, the successful candidate will bring familiarity with the following areas and engage with them as part of day-to-day operations.

Azure Infrastructure

  • Participate in Azure environment administration including resource groups, virtual networks, and storage accounts
  • Manage and maintain Azure Automation runbooks supporting identity and operational workflows
  • Contribute to Azure infrastructure initiatives in collaboration with the broader infrastructure team

Networking

  • Assist with Cisco Meraki network administration including switch configuration, VLAN management, and wireless access point management
  • Troubleshoot DNS, DHCP, VPN, and Wi-Fi connectivity issues affecting endpoints and users
  • Support network infrastructure projects including hardware refresh and new site deployments
  • Familiarity with Palo Alto next-generation firewalls is a plus

Server and Virtualization

  • Participate in VMware ESXi environment administration including VM deployment, configuration, and health monitoring
  • Assist with Windows Server administration including domain controllers, utility servers, and application servers
  • Contribute to server patching, lifecycle management, and disaster recovery validation

Storage

  • Assist with NetApp ONTAP storage administration as needed including volume management and cluster health
  • Support cloud file storage migration and ongoing management
 

 

Skills You Must Bring

  • 5 to 7 years of hands-on experience specifically in an enterprise infrastructure or systems engineering role, not general IT support. This person needs to contribute immediately without significant onboarding or training.
  • Advanced Intune administration including Win32 app packaging, compliance policies, configuration profiles, remediation scripts, and Autopilot provisioning
  • Advanced Active Directory and Entra ID administration in a hybrid environment including Azure AD Connect, conditional access, hybrid join states, and Privileged Identity Management
  • Okta and Microsoft Entra ID administration including SSO integrations, enterprise application registrations, user provisioning, and MFA policy management
  • Advanced PowerShell scripting and Microsoft Graph API proficiency
  • Advanced Exchange Online administration including mail flow rules, connectors, transport policies, and message tracing
  • Advanced SharePoint Online administration including site lifecycle, permissions, and governance
  • Microsoft Teams administration
  • Experience supporting Apple devices including macOS and iPadOS in an enterprise environment
  • Deep understanding of Windows client architecture, troubleshooting, and enterprise lifecycle management
  • Strong knowledge of enterprise networking concepts including DNS, DHCP, VPN, and Wi-Fi
  • Strong troubleshooting instincts across identity, endpoints, and connectivity
  • Familiarity with enterprise ITSM platforms for ticket management and documentation
  • Ability to work independently across multiple concurrent workstreams
  • Strong written and verbal communication skills

Skills That Will Set You Apart

  • Azure administration including resource groups, virtual networks, storage accounts, and Azure Automation runbook management
  • Cisco Meraki network administration including switches, VLANs, and wireless access points
  • Palo Alto firewall familiarity
  • VMware ESXi and vSphere administration
  • NetApp ONTAP familiarity
  • Power Automate and Power Apps experience building and maintaining enterprise flows integrated with SharePoint and Azure Automation
  • Experience with hybrid Active Directory to Entra ID migration
  • Zoom platform administration including user management, licensing, meeting policies, and Zoom Rooms
  • Experience with Microsoft Defender for Endpoint and Microsoft Defender XDR
  • Experience with Windows Update for Business, Windows Autopatch, and enterprise servicing strategies
  • Backup and disaster recovery platform experience
  • Apple Business Manager and enterprise Apple MDM platform experience such as Jamf or Kandji
  • Exposure to regulated industry environments including biotech, pharma, or life sciences

Personal Attributes

  • Operates with a high degree of independence and ownership
  • Comfortable managing multiple concurrent workstreams without losing depth on any of them
  • Brings methodical, structured thinking to ambiguous technical problems
  • Understands enterprise systems as interconnected platforms rather than isolated technologies
  • Communicates clearly across technical and non-technical audiences
  • Committed to reducing single points of failure through documentation and automation
  • Ready to contribute immediately

Skills Required

  • 5+ years supporting Windows endpoints in an enterprise environment
  • Experience with Microsoft Intune app deployment, policy management, and device troubleshooting
  • Strong troubleshooting skills across OS, identity, and Microsoft 365 services
  • PowerShell scripting skills for automation and remediation workflows
  • Solid understanding of hybrid Entra ID / Azure AD identity concepts
  • Experience diagnosing hardware issues and coordinating warranty repairs
  • Familiarity with DNS, VPN, and Wi-Fi troubleshooting
  • Strong written and verbal communication skills

Kymera Therapeutics Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Kymera Therapeutics and has not been reviewed or approved by Kymera Therapeutics.

  • Fair & Transparent Compensation Pay is considered market‑competitive for core scientific and leadership roles, with clearly posted ranges visible for U.S. openings. Feedback suggests strong base pay aligns with comments about high salary and good pay.
  • Equity Value & Accessibility Employees are eligible to participate in broad‑based equity programs, including an equity incentive plan and an ESPP. Feedback suggests this ownership opportunity can meaningfully augment total compensation in a growth‑focused setting.
  • Leave & Time Off Breadth Company‑wide office shutdowns, standard PTO, and summer schedules are promoted to help people unplug. Feedback suggests these practices contribute to a well‑rounded time‑off offering.

Kymera Therapeutics Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Watertown, Massachusetts
208 Employees
Year Founded: 2016

What We Do

Kymera is a clinical-stage biotechnology company pioneering the field of targeted protein degradation (TPD) to develop medicines that address critical health problems and have the potential to dramatically improve patients’ lives. Kymera is deploying TPD to address disease targets and pathways inaccessible with conventional therapeutics. Having advanced the first degrader into the clinic for immunological diseases, Kymera is focused on delivering oral small molecule degraders to provide a new generation of convenient, highly effective therapies for patients with these conditions. Kymera is also progressing degrader oncology programs that target undrugged or poorly drugged proteins to create new ways to fight cancer. Founded in 2016, Kymera has been recognized as one of Boston’s top workplaces for the past several years

Similar Jobs

Pfizer Logo Pfizer

Sr. Manager PSL&D Business Operations Lead

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Hybrid
4 Locations
121990 Employees
116K-193K Annually
Remote or Hybrid
USA
589 Employees

Ahold Delhaize USA Logo Ahold Delhaize USA

Manager Business Enablement

AdTech • eCommerce • Food • Marketing Tech • Retail
Hybrid
Quincy, MA, USA
10000 Employees
121K-209K Annually

MetLife Logo MetLife

Care Coordinator Long Term Care - 9/28/26 - 19472

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
50K-58K Annually

Similar Companies Hiring

Sailor Health Thumbnail
Healthtech • Social Impact • Telehealth
New York City, NY
20 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account