Endpoint Engineer, Technology & Security
Job in
Los Angeles, Los Angeles County, California, 90001, USA
Listed on 2026-08-09
Listing for:
Oaktree Capital Management
Full Time
position Listed on 2026-08-09
Job specializations:
-
IT/Tech
Cybersecurity, Systems Administrator, IT Support, Systems Engineer
Job Description & How to Apply Below
Endpoint Engineer
Oaktree is seeking a highly motivated and technical Endpoint Engineer to support the Information Security team at Oaktree.
Endpoint Management & Engineering- Own and continuously improve the modern endpoint management platform, including Microsoft Intune, Windows Autopilot, Microsoft Entra , and related technologies.
- Manage the full Windows endpoint lifecycle, including provisioning, enrollment, configuration, compliance, application deployment, patching, OS upgrades, troubleshooting, and retirement.
- Lead the transition from SCCM/MECM and Group Policy–based management to modern, cloud-native endpoint management, including decommissioning legacy infrastructure.
- Leverage AI-assisted tools and automation to improve endpoint engineering, monitoring, troubleshooting, reporting, and operational consistency.
- Design, implement, and optimize Intune configuration profiles, compliance and security policies, application deployments, update rings, remediation scripts, and enrollment profiles.
- Support Microsoft Entra joined, hybrid-joined, co-managed, and cloud-native device management scenarios.
- Develop standardized processes for device provisioning, refresh, rebuilds, feature updates, and hardware lifecycle management.
- Implement and maintain endpoint security controls, including Bit Locker, Microsoft Defender, Windows LAPS, Windows Hello for Business, firewall policies, attack surface reduction rules, and security baselines.
- Configure and monitor compliance policies to ensure devices meet organizational security requirements.
- Package, deploy, test, and support applications using Intune, Win
32 app deployment, Microsoft Store, Power Shell, and enterprise software distribution tools. - Plan and execute Windows feature updates and OS migrations, including readiness assessments, pilot deployments, issue remediation, reporting, and production rollouts.
- Develop scripts, detection rules, remediation packages, and automation to improve operational efficiency.
- Act as the escalation point for complex endpoint issues involving Windows, Intune, Autopilot, SCCM, application deployment, compliance, authentication, and device management.
- Diagnose and resolve issues using endpoint logs, Intune reporting, Autopilot diagnostics, Power Shell, Event Viewer, SCCM client logs, and Entra device records.
- Participate in incident response, change management, root cause analysis, and continuous service improvement.
- Maintain documentation for endpoint architecture, standards, policies, deployment processes, application packaging, and support procedures.
- Partner with Security, Identity, Infrastructure, Networking, Procurement, and Service Desk teams to deliver endpoint initiatives.
- Support audits, compliance efforts, risk assessments, and endpoint modernization projects.
Required Qualifications:
- 5+ years of relevant experience
- Strong troubleshooting skills across Windows OS, device enrollment, endpoint policy, application deployment, network connectivity, certificates, user profiles, and endpoint security controls.
- Ability to write clear technical documentation and communicate effectively with technical and non-technical stakeholders.
Preferred Qualifications:
- Microsoft certifications such as Microsoft 365 Certified:
Endpoint Administrator Associate, Azure Administrator Associate, or related Microsoft security and identity certifications. - Experience migrating from SCCM/GPO-based environments to Microsoft Intune and modern endpoint management.
- Experience with Microsoft Entra Conditional Access, device compliance, Zero Trust, and Microsoft Defender for Endpoint.
- Experience managing Apple Business Manager, macOS, iOS/iPadOS, and Android devices through Intune.
- Experience with enterprise application packaging and deployment, including Win
32, MSI/MSIX, detection rules, dependencies, and deployment rings. - Experience supporting Windows Hello for Business, Cloud Kerberos Trust, Universal Print, VPN, virtual desktop/Citrix environments, and line-of-business applications.
- Experience using AI-assisted tools (e.g., Microsoft Copilot or Security Copilot) to improve endpoint automation, troubleshooting, reporting, and documentation.
- Strong endpoint engineering mindset with the ability to design for scale, reliability, security, and operational simplicity.
- Ability to modernize legacy endpoint practices while maintaining business continuity.
- Strong analytical and troubleshooting skills.
- Security-first mindset with practical understanding of user experience and operational supportability.
- Ability to work independently while collaborating across multiple technical teams.
- Strong documentation discipline and process orientation.
Bachelor's degree required.
Base Salary$125,000 - $160,000
In addition to a competitive base salary, you will be eligible to receive discretionary bonus incentives, a…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×