Skip to main content
Loading
loadingbar
Loading, Please wait..!!

Endpoint Management Engineer

  • Job type Posted on: Jul 23, 2026
  • Experience level VDart Inc
  • Employment type Atlanta, Georgia
  • Employment type Onsite
  • Salary Full-time

Point Apply Here APPLY LATER

Curious about compensation?

Explore the historical salary trends, average pay, and estimated compensation for Endpoint Management Engineer roles in Georgia.

View Salary Guide →

Job Title :

Endpoint Management Engineer

Job Type :

Full-time

Job Location :

Atlanta Georgia United States

Remote :

No

Jobcon Logo Job Description :

Job Title : Endpoint Management Engineer
Location : Atlanta, GA 30308(Hybrid - 2days/Week)
Duration - 12+ month contract


About the Role

We're looking for an IT Systems Engineer to take day-to-day ownership of our Windows endpoint management function. You will operate with significant autonomy in execution and technical judgment, working within our established governance and change management processes and in close partnership with IT leadership, inside an established, cloud-native Intune environment.

This role requires strong independent judgment on operational and technical execution. Significant architecture or security-impacting decisions are made in partnership with IT leadership and follow our standard change management process. You'll also document thoroughly and mentor to help build broader in-house Windows endpoint capability over time.

You'll own day-to-day Windows endpoint management: patching, application deployment, compliance, driver/firmware management across our Dell and Lenovo hardware, and PowerShell-based automation. You'll work closely with IT Operations, Security, and Identity teams, and submit changes affecting the broader environment through our change management process.

Key Responsibilities

Endpoint Management Architecture & Deployment

  • Administer, configure, and continuously optimize Microsoft Intune for the Windows fleet, including enrollment (Autopilot), configuration profiles, and application deployment.
  • Develop and refine scalable device enrollment and provisioning strategies using Autopilot and modern deployment approaches.
  • Serve as the primary technical owner for day-to-day Windows Intune operations, partnering with IT leadership to define endpoint management standards and deployment methodologies and to align capabilities with broader IT and Security requirements.
  • Submit and manage changes through our formal IT change management process, including risk assessment, peer/leadership review, and rollback planning for endpoint-impacting changes.

Endpoint Security & Compliance

  • Maintain and troubleshoot Conditional Access integrations tied to device compliance.
  • Maintain device compliance policies and coordinate with the Security team on EDR posture.
  • Create and maintain CyberArk EPM (Endpoint Privilege Management) policies for Windows, taking requests through InfoSec approval.
  • Track BitLocker key escrow, compliance, and recovery processes.
  • Support audit and compliance evidence requests related to endpoint controls.

Patch Management & Endpoint Lifecycle

  • Architect and maintain Windows Update for Business (WUfB) deployment rings, testing, and remediation workflows.
  • Support endpoint lifecycle activities: provisioning, retirement, hardware refresh coordination.
  • Driver & Firmware Management - own driver and firmware management across a mixed Dell and Lenovo hardware fleet:
    • Diagnose and remediate driver-related regressions introduced by Windows Feature Updates.
    • Manage driver ranking/prioritization behavior between Windows Update and vendor driver update tooling (e.g., Dell Command Update), including designing phased rollout rings so problematic drivers don't reach the full fleet.
    • Account for the interplay between driver/firmware update cadence and Secure Boot/TPM certificate lifecycle timing when sequencing rollouts.
    • Build dynamic Intune device groups and staged deployment logic to safely sequence driver updates across the fleet.
    • Support driver management considerations tied to hardware vendor transitions (e.g., Dell to Lenovo), including packaging and deployment tooling differences between vendors.

Application Management & Software Deployment

  • Package, deploy, and maintain enterprise applications via Intune.
  • Support WSL2-based developer workflows, including certificate trust configuration inside WSL2 distros so decrypted traffic is trusted by CLI tools, package managers, and language runtimes.
  • Balance developer velocity against compliance requirements across managed developer workstations.

Automation & Continuous Improvement

  • Develop and maintain PowerShell scripts for proactive remediation, reporting, and automated operational workflows.
  • Identify and implement opportunities to reduce manual operational effort.

Documentation & Knowledge Transfer

  • Develop comprehensive support documentation to enable Tier 2 and operational teams to manage day-to-day activities effectively.
  • Document all changes, SOPs, and non-obvious operational logic thoroughly.
  • Provide mentorship and knowledge transfer to help build broader in-house Windows endpoint capability over time.

Required Skills & Qualifications

  • 7+ years of experience in enterprise Windows endpoint management, with a demonstrated track record of sound technical judgment and independent execution within a structured governance and change management environment.
  • Strong, demonstrable hands-on experience with:
    • Microsoft Intune (Windows-focused: Autopilot, compliance, app deployment, configuration profiles)
    • Microsoft Entra ID (Conditional Access, device compliance integration)
    • Windows Update for Business (WUfB) - deployment rings, remediation
    • BitLocker administration
  • Driver and firmware management across Dell and Lenovo hardware is a critical, active requirement. Candidates must have hands-on experience troubleshooting Feature Update related driver regressions, managing driver ranking/prioritization behavior against Windows Update, designing phased rollout rings, and sequencing driver updates.
  • Advanced PowerShell scripting and automation ability.
  • Experience planning and executing major Windows OS version rollouts at enterprise scale (e.g., 23H2 25H2), including compatibility testing and phased deployment strategy.
  • Experience supporting developer workflows and workstations- specifically, experience managing certificate trust for environments where web traffic undergoes SSL/TLS deep packet inspection (e.g., Prisma Access).
  • Experience with WSL2 preferred.
  • Experience working alongside CrowdStrike as the sole EDR platform.
  • Experience creating and maintaining Idira (CyberArk) EPM (Endpoint Privilege Management) policies on Windows.
  • Experience working within a formal IT change management process (change submission, risk assessment, rollback planning, CAB or equivalent review) in an enterprise environment.
  • Strong documentation skills are required - SOPs, architectural decisions, and non-obvious operational logic must be written clearly enough for someone else to pick up and operate.
  • Strong troubleshooting and analytical skills; proven ability to exercise sound technical judgment while working effectively within governance and change management processes.
  • Nice to have qualifications:
    • Experience with Palo Alto GlobalProtect.
    • Understanding of SSL/TLS deep packet inspection (DPI) concepts.
    • Experience with Windows 365 / Cloud PC provisioning and management.
    • Experience with osQuery

Jobcon Logo Position Details

Posted:

Jul 23, 2026

Reference Number:

99448-5195

Employment:

Full-time

Salary:

Not Available

City:

Atlanta

Job Origin:

CIEPAL_ORGANIC_FEED

Share this job:

  • linkedin

Jobcon Logo
A job sourcing event
In Dallas Fort Worth
Aug 19, 2017 9am-6pm
All job seekers welcome!

Endpoint Management Engineer    Apply

Click on the below icons to share this job to Linkedin, Twitter!

Job Title : Endpoint Management Engineer
Location : Atlanta, GA 30308(Hybrid - 2days/Week)
Duration - 12+ month contract


About the Role

We're looking for an IT Systems Engineer to take day-to-day ownership of our Windows endpoint management function. You will operate with significant autonomy in execution and technical judgment, working within our established governance and change management processes and in close partnership with IT leadership, inside an established, cloud-native Intune environment.

This role requires strong independent judgment on operational and technical execution. Significant architecture or security-impacting decisions are made in partnership with IT leadership and follow our standard change management process. You'll also document thoroughly and mentor to help build broader in-house Windows endpoint capability over time.

You'll own day-to-day Windows endpoint management: patching, application deployment, compliance, driver/firmware management across our Dell and Lenovo hardware, and PowerShell-based automation. You'll work closely with IT Operations, Security, and Identity teams, and submit changes affecting the broader environment through our change management process.

Key Responsibilities

Endpoint Management Architecture & Deployment

  • Administer, configure, and continuously optimize Microsoft Intune for the Windows fleet, including enrollment (Autopilot), configuration profiles, and application deployment.
  • Develop and refine scalable device enrollment and provisioning strategies using Autopilot and modern deployment approaches.
  • Serve as the primary technical owner for day-to-day Windows Intune operations, partnering with IT leadership to define endpoint management standards and deployment methodologies and to align capabilities with broader IT and Security requirements.
  • Submit and manage changes through our formal IT change management process, including risk assessment, peer/leadership review, and rollback planning for endpoint-impacting changes.

Endpoint Security & Compliance

  • Maintain and troubleshoot Conditional Access integrations tied to device compliance.
  • Maintain device compliance policies and coordinate with the Security team on EDR posture.
  • Create and maintain CyberArk EPM (Endpoint Privilege Management) policies for Windows, taking requests through InfoSec approval.
  • Track BitLocker key escrow, compliance, and recovery processes.
  • Support audit and compliance evidence requests related to endpoint controls.

Patch Management & Endpoint Lifecycle

  • Architect and maintain Windows Update for Business (WUfB) deployment rings, testing, and remediation workflows.
  • Support endpoint lifecycle activities: provisioning, retirement, hardware refresh coordination.
  • Driver & Firmware Management - own driver and firmware management across a mixed Dell and Lenovo hardware fleet:
    • Diagnose and remediate driver-related regressions introduced by Windows Feature Updates.
    • Manage driver ranking/prioritization behavior between Windows Update and vendor driver update tooling (e.g., Dell Command Update), including designing phased rollout rings so problematic drivers don't reach the full fleet.
    • Account for the interplay between driver/firmware update cadence and Secure Boot/TPM certificate lifecycle timing when sequencing rollouts.
    • Build dynamic Intune device groups and staged deployment logic to safely sequence driver updates across the fleet.
    • Support driver management considerations tied to hardware vendor transitions (e.g., Dell to Lenovo), including packaging and deployment tooling differences between vendors.

Application Management & Software Deployment

  • Package, deploy, and maintain enterprise applications via Intune.
  • Support WSL2-based developer workflows, including certificate trust configuration inside WSL2 distros so decrypted traffic is trusted by CLI tools, package managers, and language runtimes.
  • Balance developer velocity against compliance requirements across managed developer workstations.

Automation & Continuous Improvement

  • Develop and maintain PowerShell scripts for proactive remediation, reporting, and automated operational workflows.
  • Identify and implement opportunities to reduce manual operational effort.

Documentation & Knowledge Transfer

  • Develop comprehensive support documentation to enable Tier 2 and operational teams to manage day-to-day activities effectively.
  • Document all changes, SOPs, and non-obvious operational logic thoroughly.
  • Provide mentorship and knowledge transfer to help build broader in-house Windows endpoint capability over time.

Required Skills & Qualifications

  • 7+ years of experience in enterprise Windows endpoint management, with a demonstrated track record of sound technical judgment and independent execution within a structured governance and change management environment.
  • Strong, demonstrable hands-on experience with:
    • Microsoft Intune (Windows-focused: Autopilot, compliance, app deployment, configuration profiles)
    • Microsoft Entra ID (Conditional Access, device compliance integration)
    • Windows Update for Business (WUfB) - deployment rings, remediation
    • BitLocker administration
  • Driver and firmware management across Dell and Lenovo hardware is a critical, active requirement. Candidates must have hands-on experience troubleshooting Feature Update related driver regressions, managing driver ranking/prioritization behavior against Windows Update, designing phased rollout rings, and sequencing driver updates.
  • Advanced PowerShell scripting and automation ability.
  • Experience planning and executing major Windows OS version rollouts at enterprise scale (e.g., 23H2 25H2), including compatibility testing and phased deployment strategy.
  • Experience supporting developer workflows and workstations- specifically, experience managing certificate trust for environments where web traffic undergoes SSL/TLS deep packet inspection (e.g., Prisma Access).
  • Experience with WSL2 preferred.
  • Experience working alongside CrowdStrike as the sole EDR platform.
  • Experience creating and maintaining Idira (CyberArk) EPM (Endpoint Privilege Management) policies on Windows.
  • Experience working within a formal IT change management process (change submission, risk assessment, rollback planning, CAB or equivalent review) in an enterprise environment.
  • Strong documentation skills are required - SOPs, architectural decisions, and non-obvious operational logic must be written clearly enough for someone else to pick up and operate.
  • Strong troubleshooting and analytical skills; proven ability to exercise sound technical judgment while working effectively within governance and change management processes.
  • Nice to have qualifications:
    • Experience with Palo Alto GlobalProtect.
    • Understanding of SSL/TLS deep packet inspection (DPI) concepts.
    • Experience with Windows 365 / Cloud PC provisioning and management.
    • Experience with osQuery

Loading
Please wait..!!