This position is responsible for the day-to-day administration, operational support, maintenance, and security enforcement of enterprise endpoint devices and virtual desktop environments across a global, hybrid, cloud-first infrastructure. This role focuses on operational excellence, system availability, asset lifecycle management, and user-facing technical support escalation.
Essential Duties/Responsibilities
Nothing in this job description restricts management’s right to assign or reassign duties and responsibilities to this job at any time.
Executes daily device management tasks across the Workplace portfolio of services using technologies such as but not limited to Microsoft Intune, MECM/SCCM co-management, Azure Virtual Desktop (AVD), and Idira/Cyberark Privileged Access Management (PAM) / Endpoint Privilege Manager (EPM)
Works closely with Service Desk teams, Infrastructure Engineers, and Information Security personnel, the administrator ensures consistent patch compliance, seamless software packaging and distribution, robust asset tracking, and rapid resolution of endpoint-related incidents
Administers and maintains enterprise endpoint management platforms across Microsoft Intune, MECM/SCCM, and Entra ID in a co-managed configuration
Monitors system health, enrollment status, and configuration policy compliance for Hybrid Entra ID Joined and cloud-native endpoints
Maintains and troubleshoots Intune Configuration Profiles to maintain enterprise device standards
Packages, tests, and deploys standard Win32, MSIX, and web applications using Patch My PC, Intune Management Extension and MECM
Utilizes PowerShell scripts for administrative automation, software installation wrappers, and baseline remediation tasks
Oversees application lifecycle updates, self-service software availability via Company Portal / Software Center, and third-party software catalog maintenance
Performs operational administration of AVD host pools, session host health monitoring, and user session management
Assists in updating session host gold images, managing FSLogix user profile storage containers, and troubleshooting virtual desktop connection or performance bottlenecks
Process daily Idira/Cyberark Endpoint Privilege Manager (EPM) policy requests, elevation approvals, and policy exception reviews in accordance with zero-trust and least-privilege principles
Supports Windows LAPS (Local Administrator Password Solution) implementation and password rotation tracking across domain and cloud environments
Executes monthly Windows Update for Business (WUfB), Microsoft Autopatch, and third-party application patch distribution cycles across global endpoints
Monitors Microsoft Defender for Endpoint alerts, BitLocker encryption status, and Attack Surface Reduction (ASR) policy compliance; remediate non-compliant devices promptness
Collaborates with Security and Audit teams to fulfill vulnerability remediation tasks and routine security compliance reporting
Operates and supports Windows Autopilot deployment profiles and Enrollment Status Page (ESP) configurations for rapid global device staging and provisioning
Manages dynamic device groups, monitor enrollment trends, and carry out structured asset onboarding, re-imaging, and offboarding recovery workflows
Serves as a Tier-2/3 technical escalation point for Service Desk technicians regarding complex endpoint, virtual desktop, and deployment failures
Adheres to IT Service Management (ITSM) processes for Incident, Change, and Request management in tools such as ServiceNow
Documents technical resolution procedures, create knowledge base (KB) articles for Tier-1 support, and assist in maintaining standard operating procedures (SOPs)
Other duties as assigned
Minimum Qualifications
Bachelor’s Degree in Information Systems, Computer Science, or equivalent practical work experience.
3+ years of hands-on endpoint administration and technical support experience in an enterprise environment using Microsoft Intune, MECM/SCCM, and Active Directory / Entra ID.
Practical proficiency with PowerShell for routine administration, custom software packaging, and endpoint troubleshooting script execution.
Operational experience administering Azure Virtual Desktop (AVD) or equivalent enterprise VDI platforms.
Hands-on experience supporting least-privilege administrative workflows using Idira/Cyberark EPM or equivalent Endpoint Privilege Management / PAM solutions.
Solid understanding of Windows 10/11 operating systems, Windows Autopilot, co-management concepts, and TCP/IP networking fundamentals.
Preferred Qualifications
Active Microsoft Certifications in Modern Workplace / Endpoint Management (e.g., Microsoft Certified: Endpoint Administrator Associate - MD-102 or Azure Virtual Desktop Specialty - AZ-140).
ITIL Foundation Certification (v3 or v4) with experience working within structured Change Advisory Board (CAB) and incident management processes.
Direct experience working with enterprise ITSM platforms (e.g., ServiceNow) and drafting technical escalation knowledge base articles.
Working Conditions and Physical Demands
For an office-based position, work is primarily performed in a professional indoor environment with minimal exposure to physical hazards. The role requires extended periods of sitting, frequent use of a computer and telephone, and occasional standing, walking, bending, or lifting light items up to 25 pounds.
About UsWe’re one of the world’s leading practitioners of circularity, transforming materials from the animal agriculture and food industries into valuable ingredients. Ingredients that nourish people, feed animals and crops, and fuel the world with renewable energy. About the TeamDarling Ingredients is an equal opportunity employer and gives consideration to qualified applicants without regard to race, color, creed, religion, age, pregnancy, sex, sexual orientation, gender identity, national origin, genetic information, physical or mental disability, military service, protected veteran status, or any other characteristic protected by applicable federal, state and local law. Know Your Rights: If you would like more information, please click on the link and paste into your browser: https://www.eeoc.gov/poster of this job.Skills Required
- Bachelor's degree in Information Systems, Computer Science, or equivalent practical work experience
- 3+ years of hands-on endpoint administration and technical support experience in an enterprise environment
- Experience using Microsoft Intune, MECM/SCCM, and Active Directory or Entra ID
- Practical proficiency with PowerShell for administration, software packaging, and troubleshooting
- Experience administering Azure Virtual Desktop or an equivalent enterprise VDI platform
- Experience supporting least-privilege workflows using CyberArk EPM or equivalent endpoint privilege management/PAM solutions
- Understanding of Windows 10/11, Windows Autopilot, co-management, and TCP/IP networking fundamentals
- Microsoft Modern Workplace or Endpoint Management certification, such as MD-102 or AZ-140
- ITIL Foundation certification, version 3 or 4
- Experience with enterprise ITSM platforms such as ServiceNow and technical knowledge-base documentation
What We Do
In a transitioning world, many things change. Global population growth, climate change, increased life expectancy and wealth have put pressure on our natural resources providing us with food, feed, fuel and general well-being. Now, more than ever we need to find viable ways to provide for our changing needs and those of future generations. That’s where we come in. With over 200 processing plants on five continents and sales and distribution offices throughout the world, Darling Ingredients serves the agri-food industry and reduce food waste by collecting and repurposing animal-based co-products and other natural materials that would otherwise be discarded. We convert these into unique and valuable ingredients that fit market demands. This way we connect global supply and demand and contribute to a circular economy.
.jpeg)







