Lead Mobility Engineering SME
Listed on 2026-10-05
-
IT/Tech
Systems Engineer, Cybersecurity
At AIG, we are reimagining the way we help customers to manage risk. Join us as a
Lead Mobility Engineering SMEto play your part in that transformation. It’s an opportunity to grow your skills and experience as a valued member of the team.
Make your mark in Information TechnologyAt AIG, technology is at the heart of everything we do, from underwriting risks to processing claims. The Information Technology (IT) team equips our colleagues with the latest tools to complete their work efficiently, with the highest standards of excellence. The team is responsible for shielding the company’s systems from security risks, while designing technology strategies that enable AIG’s businesses to achieve their goals.
Innovation in IT drives innovation across the organization.
The Lead Mobility Engineering SME is the senior hands‑on engineer accountable for the architecture, engineering, security, automation, and operational health of the enterprise mobile and modern endpoint ecosystem — Microsoft 365 mobile services, Microsoft Intune, MDM and MAM, Apple iOS/iPadOS, Android Enterprise, and modern Windows provisioning including Autopilot. This is not a coordination or console‑administration role, and it is deliberately not a single‑discipline one: the estate depends on mobility platform engineering, modern authentication, endpoint security and network connectivity, and automation, and strength across all four is the bar.
The role designs, builds, tests, automates, troubleshoots to root cause, documents, and leads controlled production change end to end.
Own the architecture and configuration standards for Intune, enrollment, MAM and app protection, compliance policies, configuration profiles, app deployment, certificates, and secure access. Own the Apple stack end to end — Apple Business Manager, Automated Device Enrollment, APNs certificate lifecycle, VPP, supervision, Declarative Device Management, managed software updates — and Android Enterprise in every mode: fully managed, dedicated/kiosk, COPE, and work profile, including managed Google Play, zero‑touch enrollment, OEMConfig and Knox.
Define compatibility, ring‑based rollout, and lifecycle plans so major OS releases are planned events, not fire drills.
Apply working knowledge of other enterprise mobility platforms — Omnissa Workspace ONE UEM (formerly VMware Workspace ONE / Air Watch), Mobile Iron/Ivanti Neurons, Jamf, SOTI or Black Berry UEM — to migration, coexistence, and platform‑selection decisions, and translate legacy profile, policy, and app configurations into their modern Intune equivalents without loss of control coverage.
Modern authentication and identity.Engineer device authentication across Entra , Entra join and hybrid join, Primary Refresh Token behavior, device‑based Conditional Access, and token and session controls. Deliver passwordless and phishing‑resistant authentication on mobile — platform credentials, FIDO2 and passkeys, certificate‑based authentication, Authenticator broker behavior. Own certificate infrastructure: SCEP and PKCS, the Intune Certificate Connector, Cloud PKI, NDES, trusted roots, and renewal automation. Design Conditional Access and prove blast radius in report‑only mode before production.
Debug OAuth 2.0, OIDC, SAML, and MSAL failures at protocol level.
Own Windows Autopilot end to end — user‑driven and self‑deploying modes, pre‑provisioning, Autopilot device preparation, Enrollment Status Page tuning, hardware hash and attestation, and the OEM supply process. Operate settings catalog, security baselines, filters, scope tags and RBAC, Windows Update for Business and Autopatch…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).