Microsoft Endpoint Platform Lead
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Systems Engineer, IT Specialist
Microsoft Endpoint Platform Lead
Job Code: MSDEF2
Location: Bethesda/Rockville, MD / Hybrid-Telework Eligible
Employment: Full-Time
Status:
Contingent Upon Proposal Award
Essnova Solutions, Inc. is seeking an experienced Microsoft Endpoint Platform Lead to lead enterprise endpoint-management delivery supporting a large-scale Microsoft endpoint management and cybersecurity modernization program for the National Institutes of Health (NIH).
This position is contingent upon Essnova receiving contract award
.
The Microsoft Endpoint Platform Lead will lead technical delivery and governance across Microsoft Intune, Microsoft Endpoint Configuration Manager (MECM/SCCM), MECM/Intune co-management, Azure Arc alignment, and JAMF/macOS support across an enterprise environment of approximately 55,000 endpoints and 15,000+ servers
.
- Lead enterprise endpoint-management governance across Windows, macOS, and other approved endpoint populations.
- Lead Microsoft Intune and MECM/SCCM co-management
, cloud-native Intune configuration, migration, onboarding, and centralized endpoint-management activities. - Implement, maintain, troubleshoot, and document approved configuration baselines, security baselines, compliance settings, operational standards, and exceptions
. - Support enterprise Intune enrollment
, device compliance, policy configuration, migrations, and endpoint-management reporting. - Coordinate JAMF/macOS governance
, centralization planning, baseline documentation, onboarding evidence, and authorization support. - Support integration and dependencies involving Azure Arc, Microsoft Entra, Conditional Access, and device signals
. - Provide systems integration,
application-packaging standardization, automation, scripting
, and technical troubleshooting. - Develop and maintain endpoint governance artifacts, technical baselines, SOPs, operational documentation, dashboards, reports, implementation evidence, and knowledge-transfer materials.
- Monitor and report endpoint enrollment, compliance, migrations, baselines, exceptions, risks, dependencies, and operational trends
. - Support ATO, ATU, SSP, security assessments, audits, and compliance evidence for endpoint-management capabilities.
- Support applicable federal security and compliance requirements, including NIST control evidence and Section 508-compliant deliverables
. - Support transition of NIH endpoint-management capabilities from modernization and migration activities into steady-state enterprise operations
.
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Engineering
, or a related technical discipline. - 8+ years of enterprise endpoint-management experience
. - 5+ years of hands-on experience with Microsoft Intune and MECM/SCCM
. - Demonstrated hands‑on experience with:
- Microsoft Intune
- Microsoft Endpoint Configuration Manager (MECM/SCCM)
- MECM/Intune co‑management
- Intune enrollment and device onboarding
- Device compliance and policy configuration
- Configuration and security baselines
- Endpoint migrations
- Exception management
- Enterprise endpoint governance and reporting
- Experience supporting large‑scale enterprise device populations and complex, multi‑organization operating environments.
- Demonstrated experience creating technical baselines, operating procedures, implementation evidence, reports, dashboards, and knowledge‑transfer materials
. - Experience supporting enterprise endpoint migrations, centralized management initiatives, and transition into steady‑state operations.
- Experience supporting NIH, HHS, or another civilian federal health/science agency
. - Experience with Azure Arc, Microsoft Entra, Conditional Access, and device signals
. - Experience with JAMF and macOS endpoint management/governance
. - Experience with automation, scripting,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).