Sr. Endpoint Engineer - MS Intune,Endpoint Engineering

Reposted Yesterday
Be an Early Applicant
Hyderabad, Telangana, IND
In-Office
Senior level
eCommerce • Logistics
The Role
Lead design and modernization of the enterprise endpoint ecosystem (Windows, Mac, mobile). Own endpoint strategy and governance, drive Intune/Autopilot adoption, automate provisioning/patching, integrate Defender/Conditional Access, implement Zero Trust endpoint controls, build Graph API and PowerShell automations, and collaborate with Security, Identity, Cloud, and End User Computing teams to improve security, compliance, and user experience.
Summary Generated by Built In

About Blue Yonder, Inc. 

Blue Yonder is the proven leader in artificial intelligence and machine learning (AI/ML)-driven supply chain and retail solutions for 4,000 of the world’s leading, manufacturing and logistics companies. Blue Yonder’s world-class client brands include 75 of the top 100 retailers, 77 of the top 100 consumer goods companies, and 8 of the top 10 global 3PLs. Running Blue Yonder, you can plan to deliver. 

Title: Staff System Engineer 1

Blue Yonder is seeking a highly experienced Senior Endpoint Engineering SME to lead the design, engineering, modernization, and security of the enterprise endpoint ecosystem. This role owns the endpoint strategy and is responsible for delivering transformational initiatives across Windows MacBook, and mobile devices.  Experienced candidates will assess endpoint security opportunities, assist with device lifecycle management, and identify modern workplace technologies to enhance end user experience.

The ideal candidate brings deep expertise with the following technologies:  Microsoft Intune, Microsoft Entra ID, Windows Autopilot, Endpoint Security, Microsoft Defender, Zero Trust architecture, MDM, Desktop as a Service (DaaS), and enterprise endpoint engineering. Candidate will serve as the primary technical lead, collaborating closely with Infrastructure, Security, Identity, Networking, Cloud, and End User Computing teams.

Key Responsibilities:

Enterprise Device Management
  • Lead enterprise endpoint management modernization initiatives, including ManageEngine Endpoint Central cloud migration, Microsoft Intune adoption, and the transition away from legacy endpoint management platforms.
  • Design and implement automated endpoint patching, software deployment, and application lifecycle management processes to improve security, compliance, and operational efficiency.
  • Establish and maintain endpoint governance through device inventory management, compliance reporting, asset visibility, and endpoint health monitoring across the global environment

Endpoint Modernization

  • Lead enterprise endpoint modernization programs, including Windows Autopilot deployment, Entra ID Join adoption, and the migration from traditional Group Policy management to cloud-native Intune/MDM policies.
  • Design and implement modern endpoint access and identity solutions, including certificate lifecycle management and the replacement of legacy Hybrid Join VPN architectures with secure, cloud-first access technologies.
  • Establish and maintain Windows endpoint standards, including Windows 11 lifecycle management, security baselines, configuration governance, and endpoint compliance across the enterprise.

Secure workforce Experience

  • Architect and deliver modern identity and access management solutions, including DUO MFA migration to Microsoft Authenticator.  Intune Conditional Access integration to enhance security and user experience. Password-less authentication via biometrics such as Windows Hello for Business.
  • Enhance secure endpoint access by modernizing guest network services, optimizing Global Protect endpoint protection and connectivity, and implementing device posture-based access controls aligned with Zero Trust principles

Endpoint Trust and Governance

  • Architect and implement endpoint trust and governance frameworks, including privileged access management, admin rights automation, and endpoint hardening initiatives aligned with Zero Trust principles.
  • Drive endpoint compliance and mobile security strategies through software lifecycle governance, mobile device segmentation, and enhanced security controls for corporate-owned and Blue Yonder devices.

Endpoint Strategy and Architecture

  • Establish endpoint security, compliance, and governance standards through Microsoft Defender strategy, device posture controls, Zero Trust principles, and ongoing review of endpoint usage and security policies.
  • Develop and execute the endpoint technology roadmap by driving hardware lifecycle automation, VDI architecture modernization, and future workplace technology strategies that enhance user experience, operational efficiency, and scalability.
  • Own DaaS Architecture & Design including solution design and capacity planning

Security and Compliance

  • Lead endpoint security engineering initiatives, including Microsoft Defender/XDR deployment, endpoint hardening, vulnerability management, Zero Trust controls, and Conditional Access integration to strengthen the organization's security posture.
  • Establish and maintain enterprise endpoint security and compliance standards through device encryption, CIS benchmark alignment and continuous security monitoring across all managed endpoints.

Automation and Engineering

  • Develop automation for provisioning, patching, certificates, and compliance utilizing both Manage Engine and Microsoft Intune.
  • Build Microsoft Graph API integrations for endpoint management workflows
  • Automate certificate renewal, device lifecycle events, and compliance remediation
  • Create self-healing endpoint configurations and monitoring scripts

Qualifications

  • Bachelor's degree in computer science, MIS or engineering related field or equivalent work experience  
  • 10+ years in Enterprise Endpoint Engineering or End User Computing
  • 5+ years hands-on experience with Microsoft Intune or Endpoint Manager
  • Proven experience managing 10,000+ enterprise endpoints globally
  • Experience delivering large-scale endpoint modernization programs
  • Ability to interact with various levels of professionals 
  • Ability to work under pressure in a fast-paced environment and meet tight deadlines 
  • Ability to act independently to drive IT goals and changes 
  • Advanced troubleshooting methodology 
  • Ability to judge priorities and adjust their work accordingly 

Preferred skills

  • Strong experience in Windows OS deployment, configuration, and lifecycle management along with windows security baselines and CIS benchmarks.
  • Experience in Microsoft Entra ID / Azure AD - Conditional Access, MFA, SSPR and Microsoft Authenticator deployment and migration
  • Strong knowledge on Windows Autopilot – Zero-touch provisioning
  • Proficiency in MS Defender and BitLocker for encryption and key management
  • Hands-on experience on Vulnerability management and device compliance enforcement
  • Hands-on experience in ManageEngine patch management
  • Strong knowledge on PowerShell — advanced scripting, modules, and CI/CD integration.
  • Working knowledge on DNS, DHCP, and endpoint network diagnostics
  • VPN solutions — Global Protect, Always On VPN, or Microsoft VPN solutions
  • Solid foundational understanding of Group Policy (GPO) design and migration to Intune MDM policies.

Our Values

If you want to know the heart of a company, take a look at their values. Ours unite us. They are what drive our success – and the success of our customers. Does your heart beat like ours? Find out here: Core Values

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.

Skills Required

  • Bachelor's degree in computer science, MIS, engineering or equivalent experience
  • 10+ years in Enterprise Endpoint Engineering or End User Computing
  • 5+ years hands-on experience with Microsoft Intune or Endpoint Manager
  • Proven experience managing 10,000+ enterprise endpoints globally
  • Experience delivering large-scale endpoint modernization programs
  • Advanced troubleshooting methodology and ability to work under pressure
  • Expertise with Microsoft Entra ID / Azure AD, Conditional Access, MFA and passwordless (Windows Hello for Business)
  • Hands-on experience with Windows Autopilot, Windows OS deployment and lifecycle management
  • Experience with Microsoft Defender, endpoint hardening, vulnerability management and CIS benchmarks
  • Experience with ManageEngine patch management and ManageEngine Endpoint Central
  • Strong PowerShell scripting skills, modules and CI/CD integration
  • Familiarity with VPN solutions (Global Protect, Always On VPN, Microsoft VPN) and endpoint network diagnostics (DNS, DHCP)
  • Experience building Microsoft Graph API integrations for endpoint workflows
  • Knowledge of Group Policy design and migration to Intune MDM policies

Blue Yonder Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Blue Yonder and has not been reviewed or approved by Blue Yonder.

  • Leave & Time Off Breadth PTO is described as generous or “unlimited” in the U.S., alongside paid holidays, sick time, and two paid volunteer days. These policies are often highlighted as strengths that support work–life balance.
  • Flexible Benefits Remote-work options and flexible arrangements are emphasized as part of the package. This flexibility is valued alongside compensation and can help offset middling pay for some roles.
  • Healthcare Strength Medical, dental, and vision coverage are provided, with mental health/EAP support and HSA/FSA options referenced. These core coverages are portrayed as solid and comprehensive.

Blue Yonder Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Scottsdale, AZ
5,001 Employees
Year Founded: 1985

What We Do

Blue Yonder is the world leader in digital supply chain and omni-channel commerce fulfillment. Our intelligent, end-to-end platform enables retailers, manufacturers and logistics providers to seamlessly predict, pivot and fulfill customer demand. With Blue Yonder, you can make more automated, profitable business decisions that deliver greater growth and re-imagined customer experiences. Blue Yonder - Fulfill your Potential Blue Yonder’s tagline “Fulfill Your Potential” reflects the company’s mission to empower every organization and person on the planet to fulfill their potential. Each day, our global teams of associates and business partners work together to accelerate global economic growth, increase sustainability and prosperity with a Sonoran Spirit.

Similar Jobs

SailPoint Logo SailPoint

Sales Executive

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
India
2461 Employees

MetLife Logo MetLife

Platform Engineer

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Hybrid
Hyderabad, Telangana, IND
43000 Employees
Hybrid
Hyderabad, Telangana, IND
289097 Employees

Crunchyroll Logo Crunchyroll

Staff Software Engineer

Digital Media • eCommerce • Gaming • Mobile • News + Entertainment
Hybrid
Hyderabad, Telangana, IND
1300 Employees

Similar Companies Hiring

PRIMA Thumbnail
Travel • Software • Marketing Tech • Hospitality • eCommerce
US
15 Employees
Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account