Principal Architect, IT Corporate Services
Listed on 2026-09-17
-
IT/Tech
Cybersecurity, Systems Engineer, IT Support, IT Specialist
The Principal Architect serves as the enterprise technology owner and principal architect for all endpoint computing and enterprise mobility services across Ascensus. This role is the senior technical authority for End User Computing, Endpoint Engineering, Modern Endpoint Management, and Enterprise Mobility Services and is responsible for defining and executing the enterprise endpoint strategy while maintaining ongoing operational ownership of the platforms, processes, standards, and technologies that support approximately 7,500 Windows, macOS, and mobile endpoints.
The Principal Architect provides architectural leadership and technical governance for Microsoft Intune, Windows Autopilot, Apple Business Manager, Entra e registration, Ninja One, Addigy, operating system standards, Group Policy, endpoint configuration baselines, device provisioning, software distribution, patching, application packaging, hardware and peripheral standards, endpoint lifecycle management, and enterprise mobility. The role leads through technical influence and coordination with internal teams and service providers and serves as the final technical escalation point for complex endpoint engineering issues.
2:
Job Functions,
Essential Duties and Responsibilities Endpoint Architecture and Strategy
- Develop and execute the enterprise endpoint architecture strategy, standards, governance, and technology roadmaps for Windows, macOS, and mobile platforms.
- Own Windows and macOS operating system standards, upgrade planning, feature adoption, and endpoint configuration baselines.
- Lead endpoint technology planning and execution for acquisitions, divestitures, office openings and consolidations, migrations, and large-scale device refreshes.
- Serve as technical owner for Microsoft Intune and the overall Modern Endpoint Management strategy, including architecture, design, implementation, governance, optimization, and operational ownership.
- Own Windows Autopilot, Apple Business Manager, Entra e registration, Ninja One, Addigy, and related endpoint management technologies.
- Design and maintain endpoint enrollment, zero-touch provisioning, imaging, software distribution, patching, and device-management processes across supported platforms.
- Drive adoption of cloud-based endpoint management and automation while ensuring solutions remain secure, scalable, supportable, and aligned with enterprise requirements.
- Design, test, implement, and govern end-user Group Policies in Active Directory and establish consistent enterprise endpoint configuration standards.
- Serve as the final technical escalation point for complex desktop engineering, application packaging, imaging, patching, Group Policy, software distribution, device enrollment, and endpoint-management issues.
- Own application packaging and compatibility standards; coordinate testing and implementation activities performed by Desktop Support and service provider teams.
- Provide technical direction to internal teams and service providers without direct supervisory responsibility.
- Establish and maintain the enterprise mobility strategy, standards, governance model, and technology roadmap for corporate mobile phones and tablets.
- Serve as the primary technology and vendor owner for T-Mobile, including service planning, escalations, technology evaluation, rate-plan and device-standard input, and roadmap alignment in partnership with Procurement.
- Define standards for mobile devices, operating systems, accessories, enrollment, eSIM, zero-touch provisioning, refresh, replacement, recovery, and retirement.
- Partner with Cybersecurity and operational teams to align mobility services with security, compliance, risk, and business continuity requirements.
- Coordinate with Cybersecurity to design and implement endpoint security controls through Group Policy, Intune, and operating system configurations.
- Own Bit Locker administration and governance while partnering with Cybersecurity on vulnerability remediation and Zero Trust initiatives.
- Participate in major incidents and security incidents involving endpoints, providing technical leadership for investigation, containment, remediation, and recovery activities.
- Contribute technical expertise to endpoint observability, compliance reporting, audit support, and operational metrics without serving as the primary owner of those functions.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).