×
Register Here to Apply for Jobs or Post Jobs. X

End Point Management Engineer

Job in North Chicago, Lake County, Illinois, 60086, USA
Listing for: TEKsystems c/o Allegis Group
Full Time position
Listed on 2026-08-25
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Administrator, IT Support, Systems Engineer
Job Description & How to Apply Below
Description
Our client is seeking an Endpoint Management Engineer to design, automate, and operate the enterprise device management platform supporting a global workforce. This role owns hands-on engineering and operations across Microsoft Intune and Microsoft Configuration Manager (SCCM/MECM) in a co-management architecture, with Hybrid Entra  (Azure AD) joined, Active Directory domain-bound Windows endpoints and a multi-platform Intune estate spanning Windows, macOS, iOS/iPadOS, and Android - including Android-based teleconferencing and conference room systems.
Automation is central to this role. The successful candidate writes production-quality Power Shell, Bash, and .NET code, builds Intune remediation and detection scripts, and uses the Microsoft Graph API to manage the estate programmatically rather than solely through the console. Fluency with modern AI-assisted engineering tools is expected - including Claude or CoPilot - to accelerate script development, log analysis, documentation, and reporting.
Equally important is the discipline required in a regulated environment. You will advance modern management objectives - Zero Trust, Conditional Access, cloud-first policy delivery, and progressive workload migration from Configuration Manager to Intune - while respecting the reliability requirements of standard corporate devices and the constraints of non-standard, purpose-built systems, manufacturing workstations, kiosks, and validated GxP endpoints. The role partners closely with Information Security, Identity, Networking, Infrastructure, Site IT, and Site Service Support teams.
Key Responsibilities
Automation, Scripting, and Development
  • Design, write, and maintain production-quality Power Shell for endpoint provisioning, configuration enforcement, bulk administration, reporting, and incident remediation across the Windows estate.
  • Write and maintain shell/Bash scripts for macOS configuration, compliance validation, and application delivery through Intune macOS shell scripting.
  • Build and manage Intune Remediations (proactive remediations) - paired detection and remediation script logic - to identify and self-heal configuration drift, failed agents, certificate issues, and compliance gaps without user impact.
  • Automate platform operations against the Microsoft Graph API, including device and policy inventory, assignment management, application lifecycle tasks, reporting extracts, and integration with adjacent systems.
  • Apply engineering discipline to automation assets: source control, code review, parameterization, error handling, logging, idempotency, and controlled release through test rings.
  • Convert recurring manual and Service Desk activities into automated or self-service capabilities.
Core Device Management
  • Engineer and maintain Intune compliance policies across all platforms, including device health, OS version floors, and custom compliance scripts.
  • Build and maintain configuration profiles and settings catalog policies, administrative templates, and custom OMA-URI/configuration profiles for Windows, macOS, iOS/iPadOS, and Android.
  • Familiar with Windows Update for Business and update rings, feature and quality update deployments, driver and firmware update governance, macOS and iOS update policies.
  • Manage monthly and out-of-band patch operations in Configuration Manager through Software Update Groups, automatic deployment rules, and maintenance windows; drive patch compliance to defined service-level targets and remediate delinquent endpoints.
  • Package, test, and deploy applications across platforms
    - Win
    32 (.intunewin), MSI/MSIX, Microsoft Store, Microsoft 365 Apps, macOS PKG/DMG and shell-script apps, iOS/Android managed apps via volume purchasing - with correct detection rules, dependencies, supersedence, requirement rules, and assignment logic.
  • Implement and maintain security baselines and industry benchmarks
    - Microsoft security baselines for Windows, Edge, and Defender; CIS Benchmarks; DISA STIG-derived controls - including deviation tracking, exception documentation, and drift detection.
  • Administer the Configuration Manager hierarchy: site systems, distribution points, boundary groups, client health, content distribution, task sequences, OS deployment, and hardware/software inventory accuracy.
  • Manage non-standard Windows endpoints - manufacturing and shop-floor workstations, kiosks, shared and standalone systems - with tailored collections, restricted patch windows, exception handling, and documented deviations.
Identity, Conditional Access, and Endpoint Security
  • Manage device identity across Entra  on-premises Active Directory, including Hybrid Entra , Entra , AD domain-bound systems, and resolution of stale, duplicate, or mis-registered device objects.
  • Configure and maintain co-management settings, pilot collections, and the controlled transition of individual workloads (compliance policies, Windows Update, device configuration, client apps, Office Apps) from Configuration Manager to Intune.
  • Support Conditional…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary