Windows Device Engineering Lead
Listed on 2026-08-28
-
IT/Tech
Cybersecurity, Systems Administrator
Job Description Position Summary
We are seeking an experienced and technically deep Windows Device Engineering Lead to own and drive the global endpoint management strategy for approximately 50,000 Windows devices across our worldwide operations. This is a high-impact technical leadership role responsible for the full device lifecycle — from provisioning and configuration to monthly patching, security hardening, and decommission — while coordinating a distributed team of contractors across time zones.
The ideal candidate combines hands‑on technical mastery in Microsoft Intune, SCCM/MEMCM, Power Shell scripting, and application packaging with the organizational skills to lead, mentor, and direct an offshore delivery team. You will serve as the primary liaison between endpoint engineering, security, and business stakeholders, ensuring our endpoint estate is compliant, resilient, and operationally excellent.
- Architect, maintain, and continuously improve the global Windows device management platform using Microsoft Intune and SCCM/MEMCM (co-management and cloud-only environments).
- Define and own configuration baselines, enrollment profiles, compliance policies, and conditional access rules across the ~50,000 endpoint estate.
- Drive the organization’s modernization roadmap toward cloud-native device management (Autopilot, Intune-only, co-management).
- Oversee device lifecycle management including provisioning, imaging, refresh cycles, and decommissioning procedures.
- Own the end-to-end monthly Patch Tuesday cycle planning, ring-based deployment, remediation tracking, and executive reporting.
- Manage software update servicing (WSUS/SUP, Intune Update Rings, Windows Autopatch) and ensure SLA compliance across all global regions.
- Partner with the Security Operations team to remediate critical and high vulnerabilities within agreed SLO windows.
- Maintain a documented patching run book and escalation path for failures and exceptions.
- Implement and enforce CIS Benchmark controls for Windows (Level 1 and Level
2) across the global fleet via Intune configuration profiles and SCCM baselines. - Own the Microsoft Defender for Endpoint (MDE) deployment, configuration, and health monitoring — including onboarding policies, ASR rules, tamper protection, and threat & vulnerability management.
- Collaborate with the Security team to operationalize MDE alerts, Secure Score improvements, and endpoint detection & response (EDR) posture.
- Conduct periodic compliance reporting against CIS benchmarks and remediate drift; maintain audit‑ready documentation.
- Manage and tune Intune compliance and conditional access policies to enforce Zero Trust principles.
- Develop, maintain, and peer‑review Power Shell scripts for automation across device management tasks including compliance remediation, reporting, inventory, and configuration drift detection.
- Build and maintain CI/CD‑friendly script repositories with version control (Git), testing frameworks, and documentation standards.
- Leverage Graph API and Power Shell SDK for Intune to automate tenant configuration, bulk operations, and reporting.
- Champion scripting best practices and provide guidance/code reviews to contractor team members.
- Lead application packaging efforts including Win
32 apps (Intune), MSI/EXE/MSIX transforms, and SCCM packages/task sequences. - Define and maintain application packaging standards, testing procedures, and approval workflows.
- Manage the application catalog, ensuring software is current, licensed, and securely deployed.
- Coordinate with software vendors and internal stakeholders to resolve packaging challenges and dependency conflicts.
- Lead, coordinate, and quality‑assure the work of a team of offshore contractors based primarily in India, including task assignment, sprint planning, and performance feedback.
- Establish clear SLAs, runbooks, and escalation paths to ensure consistent delivery quality across time zones.
- Conduct regular stand‑ups, knowledge‑transfer…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).