Role Positioning
This senior role is intentionally balanced across Microsoft Endpoint Configuration Manager (MECM/SCCM) and Microsoft Intune, with responsibilities split between traditional endpoint management and modern cloud-based endpoint management.
Functional Split
Level
Core Platforms
Ideal Certifications
50% MECM / SCCM
50% Microsoft Intune
Senior Engineer / Consultant
MECM, Intune, Entra ID, Windows Autopilot
MD-102 and MS-102
The Senior Microsoft Endpoint Management Engineer is responsible for designing, implementing, maintaining, and supporting enterprise endpoint management solutions using both Microsoft Endpoint Configuration Manager (MECM/SCCM) and Microsoft Intune.
This role serves as a subject matter expert for traditional and modern endpoint management, including operating system deployment, application lifecycle management, device compliance, security controls, endpoint analytics, and cloud-based device management.
The ideal candidate possesses deep expertise in both MECM and Intune and can help organizations modernize endpoint management through co-management, Microsoft Entra ID integration, Windows Autopilot, and cloud-native management strategies.
- Design, implement, administer, and maintain MECM infrastructure, including site systems, boundaries, boundary groups, distribution points, and client settings.
- Monitor MECM health, performance, and availability; perform upgrades, hotfix installations, and environment maintenance.
- Design and maintain Windows 10/11 operating system deployment task sequences for bare-metal, refresh, and in-place upgrade scenarios.
- Manage boot images, driver repositories, deployment media, and PXE/task sequence troubleshooting.
- Package, test, deploy, and maintain enterprise applications using MSI, EXE, PowerShell, scripts, and establish detection methods, dependencies, supersedence, and deployment requirements.
- Manage Windows and third-party patching solutions, including deployment rings, maintenance windows, compliance monitoring, and remediation.
- Design, implement, and administer Microsoft Intune environments for Windows, macOS, iOS, and Android device management.
- Configure device enrollment, Microsoft Entra ID join, hybrid join, compliance policies, configuration profiles, device restrictions, and endpoint security policies.
- Design and implement Windows Autopilot scenarios, including user-driven, pre-provisioned, and self-deploying deployments.
- Configure Enrollment Status Page behavior, Autopilot profile assignments, and troubleshoot enrollment and provisioning issues.
- Package and deploy Win32, Microsoft Store, Microsoft 365 Apps, and line-of-business applications; manage application lifecycle and update processes.
- Configure and maintain security baselines, BitLocker management, Endpoint Privilege Management, Microsoft Defender integration, and Conditional Access integration.
- Design and implement MECM/Intune co-management solutions and migrate workloads between MECM and Intune.
- Develop endpoint modernization roadmaps that guide customers from traditional device management to cloud-native management.
- Assess customer endpoint environments and recommend best-practice architectures for modern management, compliance, and security.
- Lead technical workshops, design sessions, implementation efforts, and customer-facing endpoint management projects.
- Develop PowerShell scripts for endpoint automation, administration, reporting, and remediation.
- Integrate endpoint management workflows with Microsoft Graph API where applicable.
- Create and maintain technical documentation, SOPs, runbooks, architecture diagrams, and implementation guides.
- Develop reports using MECM, Intune, Power BI, SQL, and Microsoft reporting tools to track deployment success, compliance, and endpoint metrics.
- Provide Tier 3 escalation support and mentor junior engineers or support staff.
Qualifications
- 5+ years of hands-on experience administering MECM/SCCM in enterprise environments.
- 5+ years of hands-on experience administering Microsoft Intune.
- Strong experience with Windows 10 and Windows 11 deployment, management, and troubleshooting.
- Experience with operating system deployment, application packaging/deployment, patch management, endpoint security, and device compliance.
- Medical, dental, and vision insurance plans.
- Company-paid life insurance and long-term disability coverage.
- Optional supplemental benefits.
- Paid time off (PTO) starting in your first year of employment.
- Seven (7) paid holidays annually.
- 401(k) plan with safe harbor match, including both traditional and Roth options.
- Business casual office environment.
- Employee referral program with bonus opportunities.
-Direct Applicants Only - No Third-Party Recruiters-
Skills Required
- 5+ years hands-on experience administering MECM/SCCM in enterprise environments
- 5+ years hands-on experience administering Microsoft Intune
- Strong experience with Windows 10 and Windows 11 deployment, management, and troubleshooting
- Experience with operating system deployment, application packaging/deployment, patch management, endpoint security, and device compliance
- Experience designing and maintaining MECM infrastructure (site systems, boundary groups, distribution points)
- PowerShell scripting for automation, administration, reporting, and remediation
- Experience integrating endpoint management with Microsoft Graph API and reporting tools (Power BI, SQL)
- Familiarity with Windows Autopilot, Microsoft Entra ID join/hybrid join, and co-management strategies
- MD-102 and MS-102 certifications
What We Do
Fire Fighter Sales & Service Co. is a leading provider of comprehensive fire protection solutions, specializing in the design, installation, maintenance, and inspection of fire safety systems. Serving industrial and commercial organizations across the Pittsburgh tri-state area, they offer a wide array of products and services, including fire alarms, sprinklers, and suppression systems, as well as professional training and consultation to ensure life safety and property protection.







