×
Register Here to Apply for Jobs or Post Jobs. X

IT Senior Endpoint Engineer - Microsoft Endpoint Configuration Manager; MECM & Intune

Job in Amarillo, Potter County, Texas, 79161, USA
Listing for: Pantex Plant
Full Time position
Listed on 2026-07-27
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer, Systems Administrator
Salary/Wage Range or Industry Benchmark: 100000 - 130000 USD Yearly USD 100000.00 130000.00 YEAR
Job Description & How to Apply Below
Position: IT Senior Endpoint Engineer - Microsoft Endpoint Configuration Manager (MECM) & Intune

Location: Amarillo, TX
- Pantex Plant

Job Title: IT Senior Endpoint Engineer
- Microsoft Endpoint Configuration Manager (MECM) & Intune

Career Level From: Senior Associate

Career Level To: Senior Specialist

Organization: End User Computing )

Job Specialty: System Administration

What You ll Do

As a hands-on technical specialist, you will serve as the enterprise owner for endpoint management across Windows devices. Your primary responsibility will be the design, configuration, operation, and troubleshooting of Microsoft Endpoint Configuration Manager (MECM) and Microsoft Intune, along with the Azure/Entra  that keep Intune resilient and secure. You will drive patch/update compliance, application and Operating System (OS) deployments, client health, and co‑management strategy Microsoft Endpoint Configuration Manager (MECM + Intune), while closely collaborating with Cybersecurity, Network, and Support teams to ensure reliability, security, and compliance of our endpoint fleet.

You are responsible for maintaining a thorough knowledge of applicable Federal, State, Department of Energy (DOE), Corporate and Plant rules, regulations, and Plant-wide operating policies and procedures.

Essential

Job Duties

Microsoft Core Infrastructure (MCM) Platform Ownership & Optimization

  • Own, administer, and continually optimize MCM core infrastructure (site server, Management Point (MP)/Distribution Point (DP) roles, Structured Query Language (SQL), Windows Server Update Services (WSUS)/Software Update Point (SUP), boundary groups, content distribution, and backup/disaster recovery (DR) `readiness).
  • Drive client‑health improvement using telemetry, automation, and consistent collection hygiene.
  • Enhance platform performance and scalability across multiple locations and networks.

OS Deployment (OSD) Engineering

  • Lead design, maintenance, and modernization of OSD task sequences for Windows 11.
  • Engineer efficient driver‑lifecycle management, secure imaging standards, pre‑provisioning (Bit Locker), post‑install hardening, and automation to reduce build time and increase reliability.
  • Evaluate migration from traditional OSD to Autopilot‑first strategies where appropriate.

Software Packaging & Deployment

  • Establish packaging standards and best practices for Microsoft Installer (MSI)/Executable File (EXE)/Win
    32 deployments across MECM and Intune.
  • Build, test, and deploy applications at scale; optimize distribution‑point content placement and success‑rate visibility.
  • Expand capabilities using third‑party patch/catalog solutions to increase coverage.

Patch & Update Compliance

  • Lead monthly update cycles for Windows OS, Microsoft 365 Apps, and third‑party applications.
  • Rapidly remediate non‑compliant devices through automation and targeted deployments.
  • Ensure WSUS/SUP synchronization health and maintain a reliable update pipeline.

Intune & Modern Device Management

  • Own Intune configuration strategy, including Autopilot, configuration profiles, compliance policies, and Windows Update for Business rings.
  • Implement and maintain Endpoint Security Baselines (Bit Locker, Defender, firewall, attack surface reduction, Credential Guard).
  • Drive clarity and evolution of MECM/Intune workload split using co‑management and Tenant Attach.

Identity & Security Integration

  • Manage Entra  (Azure AD) device identity, Conditional Access policies, role‑based access control, and SCEP/NDES/PKI integrations.
  • Ensure secure enrollment, compliance signaling, and alignment with cybersecurity requirements.

Automation, Monitoring & Troubleshooting

  • Use Power Shell, Microsoft Graph API (API), Kusto Query Language (KQL) (Log Analytics/Azure Monitor), and SQL Server Reporting Services (SSRS)/Power BI reporting to automate operations and improve visibility.
  • Troubleshoot complex endpoint failures (WMI, BITS, policy conflict, client registration, SUP sync, CMG connectivity) and deliver long‑term fixes.

Documentation & Leadership

  • Create and maintain enterprise runbooks, engineering standards, and troubleshooting guides.
  • Lead technical workshops, mentor peers, and contribute to continuous improvement of endpoint management processes.

Minimum Job Requirements

  • Bachelor s degree in…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary