Desktop Engineer; Contractor
Listed on 2026-09-29
-
IT/Tech
Cybersecurity, Systems Administrator
Allogene Therapeutics, with headquarters in South San Francisco, is a clinical-stage biotechnology company pioneering the development of allogeneic chimeric antigen receptor T cell (AlloCAR T) products for cancer and autoimmune disease. Led by a management team with significant experience in cell therapy, Allogene is developing a pipeline of “off-the-shelf” CAR T cell product candidates with the goal of delivering readily available cell therapy on-demand, more reliably, and at greater scale to more patients.
About the role:We are seeking an experienced Desktop Engineer to manage and support the organization’s endpoint and workplace technology environment across Windows and macOS devices. This role owns day-to-day endpoint operations and helps ensure corporate laptops and desktops remain secure, compliant, patched, reliable, and productive within a Microsoft-centric environment.
The successful candidate will combine strong endpoint engineering skills with a hands-on, customer-focused support approach. This role is a tier 3 escalation.
The role can be based remote or can be based onsite at the South San Francisco offices.
Responsibilities:Endpoint Management and Configuration
- Administer and maintain enterprise desktop management platforms for Windows and macOS devices without dependency on a single technology or vendor.
- Develop, implement, and maintain device standards, security baselines, configuration profiles, compliance policies, and enrollment settings.
- Manage the complete endpoint lifecycle, including procurement coordination, enrollment, provisioning, deployment, refresh, reassignment, and secure retirement.
- Monitor endpoint health and compliance, investigate configuration drift, and remediate devices that fall outside established standards.
- Automate repeatable deployment and configuration activities using appropriate scripting and administration methods.
Software Deployment and Application Management
- Packaging, testing, deployment, maintenance, and removal of windows/third party applications across supported endpoint platforms. Experience with Microsoft Intune, JAMF, and Automox are considered an additional qualification.
- Maintain standard application catalogs and self-service delivery capabilities where appropriate.
- Coordinate application upgrades, compatibility testing, licensing considerations, and rollout communications.
- Troubleshoot failed installations, application conflicts, performance issues, and deployment errors.
Patch and Vulnerability Management
- Plan and execute operating system, browser, firmware, driver, and third-party application patching based on defined maintenance schedules and risk priorities.
- Monitor patch deployment success, investigate failures, and drive remediation of noncompliant or vulnerable endpoints.
- Coordinate urgent security updates and out-of-band maintenance in partnership with Information Security and Infrastructure teams.
Endpoint Security and Compliance
- Implement and maintain endpoint security settings, including encryption, host firewall, local privilege controls, device restrictions, authentication-related configurations, and approved security baselines.
- Partner with Information Security to investigate endpoint alerts, remediate vulnerabilities, support incident response, and reduce endpoint risk.
- Apply configuration and software changes through documented testing, approval, deployment, validation, and rollback practices.
Microsoft 365 and Identity-Integrated Workplace Support
- Configure and support Microsoft 365 settings that affect endpoint access, productivity, collaboration, device compliance, and the end-user experience.
- Troubleshoot endpoint integration with cloud identity, authentication, productivity applications, collaboration services,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).