Senior Desktop Engineer
Listed on 2026-07-04
-
IT/Tech
Windows Server, Systems Administrator, IT Infrastructure, IT Support
Job Summary
We are seeking an experienced Desktop Engineer to manage and evolve our enterprise endpoint environment—covering Windows devices, desktop applications, security configuration, imaging/provisioning, and lifecycle management. This role will focus heavily on modern endpoint management practices using Microsoft Intune, Windows Autopilot, and cloud‑first deployment/patching strategies, while maintaining and integrating with SCCM as needed.
The ideal candidate has hands‑on expertise in automated software packaging, application deployment at scale, software licensing/compliance, asset tracking, and endpoint security baselines. You will also contribute to systems architecture, helping design and implement innovative solutions based on leading‑edge technologies.
Key Tasks & Responsibilities (Essential Functions)- Engineer, deploy, and support enterprise endpoints using Microsoft Intune (Configuration Profiles, Compliance Policies, Conditional Access alignment, app deployment).
- Design and operationalize Windows Autopilot for zero‑touch provisioning, including device enrollment, profile design, and deployment workflows.
- Implement and manage Windows Intune‑based patching strategies, including ring design, deadlines, feature update controls, notifications and reporting (experience patching through AUTOMOX a plus).
- Maintain integration and co‑management practices between SCCM and Intune, optimizing for cloud‑first where possible.
- Create, test, and maintain automated application packages (Win
32 apps, MSI, MSIX where appropriate) and deployment workflows. - Build automation using Power Shell and/or other scripting tools to streamline installs, configurations, remediations, and reporting.
- Troubleshoot complex deployment failures and endpoint configuration issues across diverse hardware and user profiles.
- Support software lifecycle management: inventory, metering/usage signals, licensing alignment, and compliance reporting.
- Ensure accurate asset tracking, entitlement validation, and audit readiness.
- Produce compliance dashboards and executive‑ready reporting (patch compliance, encryption coverage, endpoint health KPIs).
- Implement endpoint hardening aligned to organizational standards (e.g., Bit Locker, CIS Level 1 policies).
- Partner with security teams to respond to endpoint vulnerabilities and to drive remediation at scale.
- Support endpoint provisioning approaches, including legacy SCCM imaging, with a focus on modern provisioning through Autopilot.
- Troubleshoot hardware/software issues that require engineering‑level analysis beyond standard service desk playbooks.
- Participate in systems architecture discussions; propose and implement new endpoint solutions leveraging modern technologies.
- Build technical documentation, runbooks, and knowledge articles for support and operations teams.
- Identify opportunities for standardization, automation, self‑service, and cost optimization.
- 5+ years of experience in enterprise desktop engineering / endpoint management.
- Strong hands‑on experience with:
- Microsoft Intune (app deployment, policy configuration, compliance, reporting)
- Windows Autopilot (deployment profiles, enrollment strategies, provisioning)
- SCCM (application deployment, collections, task sequences, reporting)
- Patching through Intune (rings, feature updates, compliance reporting)
- Proven experience creating and managing automated software packages.
- Strong working knowledge of Windows (Windows 10/11) and MacOS, device configuration, and troubleshooting.
- Scripting/automation skills—Power Shell required; ability to build scalable remediation and deployment scripts.
- Practical understanding of software licensing, inventory/asset concepts, and compliance reporting.
- Experience with endpoint security controls (Bit Locker, CIS Level 1, hardening baselines).
- Strong documentation and communication skills; able to translate technical designs into clear operational procedures.
- Ability to effectively collaborate within environments utilizing role‑based access controls, demonstrating productivity and accountability without requiring full administrative privileges to all systems.
- Ability to work effectively…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).