Senior Endpoint Engineer
Listed on 2026-09-13
-
IT/Tech
Systems Engineer, IT Infrastructure
Senior Endpoint Engineer
Department: IT
Employment Type: Full Time
Location: Sanford, FL
DescriptionTrilon is building a supercharged, technology-enabled future for our people and partners. The Senior Endpoint Engineer is the senior technical owner for Trilon's workplace endpoint ecosystem, standards, and operating model across Windows, Apple devices, Microsoft Teams Rooms, and the enterprise copier and plotter fleet.
Reporting to the Vice President, Infrastructure & Operations, this role leads the design, modernization, and reliable operation of endpoint management through Microsoft Intune, Windows Autopilot, Windows Autopatch, Patch My PC, Microsoft Entra , Apple Business Manager, and related technologies. The goal is a secure, consistent, measurable, and increasingly zero-touch experience for employees across Trilon partner firms.
This is an individual-contributor technical-lead role, not a formal people-manager position. Working within a small, highly capable engineering function, the role sets technical direction and builds the platforms, automation, standards, and documentation that allow endpoint services to operate reliably vice Delivery and Field Support retain responsibility for routine incidents, requests, onsite assistance, consumables, and first-line troubleshooting. This role becomes directly engaged when platform design, configuration, vendor coordination, automation, or support processes break down, and serves as the senior technical escalation point for complex or systemic issues.
Key Responsibilities- Provide hands-on technical leadership, architecture, design review, and practical guidance through expertise and influence, without formal direct-report or performance-management responsibility.
- Establish platform priorities, service ownership, technical standards, cross-training, escalation coverage, and an executable roadmap aligned with enterprise infrastructure and security strategy.
- Serve as the technical authority and senior escalation point for enterprise endpoint management; set technical direction, review engineering work, and maintain an executable roadmap.
- Own endpoint engineering documentation, change control, testing and rollback standards, support handoffs, knowledge transfer, and cross-training so services are repeatable and resilient.
- Establish service metrics and use operational reviews to drive accountability, reliability, security, and continuous improvement.
- Define and maintain enterprise standards for Windows endpoints, including configuration profiles, security baselines, compliance policies, assignment groups, role-based access, and policy exceptions.
- Own Microsoft Intune and Windows Autopilot architecture, including OEM registration, deployment profiles, pre-provisioning, Enrollment Status Page design, reset and redeployment workflows, and zero-touch readiness.
- Design enrollment and migration patterns for cloud-native Microsoft Entra join, hybrid Entra join, automatic MDM enrollment, and legacy-device transition while reducing long-term dependence on on-premises infrastructure.
- Maintain clear targeting and group-design standards and validate that enrollment, assignment, compliance, encryption, and application results are measured separately rather than inferred from group membership.
- Own enterprise management of Mac, iPhone, and iPad devices through Microsoft Intune and Apple Business Manager, including Automated Device Enrollment, supervision, enrollment, configuration and compliance, security, updates, remote actions, mobile application management, and lifecycle.
- Govern Apple platform integrations and controls, including Apple MDM Push certificates, device and MDM server assignments, Apps and Books licensing and location tokens, renewals, administrative access, procurement and reseller assignment, zero-touch setup, inventory, offboarding, secure wipe or recovery, and retirement.
- Own the application packaging lifecycle in Intune, including Win
32 packages, Power Shell App Deployment Toolkit (PSADT), requirements, detection rules, dependencies, supersedence, pilot testing, production assignments, remediation, and retirement. - Use Patch My PC's catalog and Custom Apps capabilities to publish and maintain third-party and specialized applications through Intune; require automated deployment as the standard path and document controlled fallback methods.
- Define the software-delivery model:
Required assignments for security and business-critical applications, Company Portal for approved optional or…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).