AS

Senior Endpoint Engineer

Hiring from
United States
Work type
Hybrid
Posted
Is this job info correct?
Show job description

This role defines the target state for how FERC devices are provisioned, managed, secured, and supported, and leads the engineering work to get there. The central mission is modernization: moving the fleet from a ConfigMgr-centric, on-premises model to a cloud-native model built on Microsoft Intune, Entra ID, Windows Autopilot, and Windows Autopatch, aligned to federal Zero Trust requirements. The architect owns the roadmap, the design decisions, and the reference standards for that transition, while remaining hands-on with ConfigMgr, Intune, Dell enterprise tooling, and BeyondTrust. The position is an individual contributor with no supervisory duties. It leads through technical direction: setting standards, reviewing designs and changes, guiding engineers, and advising program leadership on endpoint risk, investment, and sequencing. Work is tracked in ServiceNow (operations and change) and Azure DevOps (ADO) Boards (roadmap, epics, and engineering backlog).

  1. Endpoint Architecture and Strategy
    • Define and maintain the endpoint target-state architecture covering identity, provisioning, configuration, application delivery, update management, security, and support tooling.
    • Own the multi-year endpoint modernization roadmap, with phases, dependencies, entry and exit criteria, and risk for each phase.
    • Produce architecture artifacts: current- and target-state diagrams, design documents, architecture decision records (ADRs), and reference configurations.
    • Evaluate new Microsoft and vendor capabilities, run proofs of concept, and recommend adoption, deferral, or retirement with cost, risk, and effort analysis.
    • Define the user persona model, and set endpoint engineering standards for naming, policy design, assignment and filtering, app packaging, and baseline management, and enforce them through design and change review.
    • Advise program leadership on endpoint risk, technical debt, licensing, and investment priorities.
  2. Modernization Delivery
    • Lead the transition from ConfigMgr to Intune, moving co-management workloads to Intune in planned waves using pilot groups and defined success criteria.
    • Design and drive the move from hybrid join toward Entra ID join and zero-touch provisioning with Windows Autopilot, as described in the Windows Autopilot section.
    • Modernize update management with Windows Update for Business and Windows Autopatch, including ring design, quality and feature update policy, and driver and firmware update policy.
    • Move application delivery to Intune Win32 apps and catalog-based app management, and retire legacy packages and deployment methods.
    • Replace on-premises dependencies with cloud services where approved, such as Windows LAPS, cloud-based certificate delivery, and Intune Remediations in place of ConfigMgr scripts and baselines.
    • Plan the reduction and eventual decommissioning of ConfigMgr infrastructure, keeping only the services the roadmap still requires.
    • Coordinate cutovers with the imaging, identity, network, security, and service desk teams, with tested rollback plans for each wave.
    • Act as senior escalation point for ConfigMgr, Intune, co-management, Autopilot, and Windows 11 client issues; resolve complex problems end to end.
  3. Endpoint Security and Compliance
    • Design endpoint security configuration to meet NIST SP 800-53 controls, Microsoft security baselines, and applicable DISA STIG or CIS benchmarks.
    • Support the program's Zero Trust work by defining device compliance signals for Entra Conditional Access, in partnership with the identity and security teams who own those policies.
  4. Automation, Analytics, and Reporting
    • Build automation in PowerShell and the Microsoft Graph API for provisioning, configuration, compliance checks, and reporting.
    • Develop KQL queries, SQL queries, and dashboards (SSRS, Power BI, or Intune and Endpoint Analytics reports) for operations, compliance, and leadership audiences.
    • Define and report modernization metrics, such as share of devices on the target-state model, workloads moved, and legacy components retired.
    • Analyze endpoint data to find trends, compliance gaps, and recurring failures, and turn findings into engineering fixes.
  5. Governance, Work Management, and Technical Leadership (5%)
    • Author and present change requests at the Change Advisory Board (CAB) for architecture-level and high-risk endpoint changes, and review changes submitted by other engineers.
    • Plan and track roadmap work in ADO Boards as epics, features, and stories, linked to related ServiceNow records.
    • Write and maintain SOPs, runbooks, and ServiceNow knowledge articles for new target-state processes, and hand off steady-state operations to the support teams.
    • Mentor engineers through design reviews, pairing, and walkthroughs, and build the team's skills in Intune, Graph, and cloud-native endpoint management.
    • Other duties as assigned within endpoint management.

Minimum Qualifications

  • Bachelor's degree in Information Technology, Computer Science, or a related field, or 12+ years of relevant experience in lieu of a degree
  • 8+ years of enterprise Windows endpoint management experience, including 2+ years leading the design of significant endpoint initiatives.
  • Ability to obtain and maintain a Public Trust determination; CompTIA Security+ held at start or earned within 90 days; on site in Washington, DC, at least 2 days per week.

Other Job Specific Skills

  • Hands-on experience with both ConfigMgr and Microsoft Intune, including co-management, and has moved at least one workload or device population from ConfigMgr to Intune.
  • Has designed and deployed Windows Autopilot for production users in at least one deployment mode.
  • PowerShell scripting skills for automation; able to read and adapt scripts that use the Microsoft Graph API.
  • Ability to write clear design documents, diagrams, and SOPs that other engineers can carry out.
  • Experience with incidents, problems, and change requests in ServiceNow or a comparable ITSM tool.

Preferred Skills

  • Experience with Windows Update for Business or Windows Autopatch, Intune Remediations, and Endpoint Analytics.
  • Working knowledge of Entra ID, Conditional Access, and device compliance in a Zero Trust model.
  • SQL and KQL skills for querying ConfigMgr, Intune, and endpoint telemetry data.
  • Experience delivering endpoint work in a federal environment under FISMA, NIST SP 800-53, and CISA directives, including Microsoft government cloud environments.
  • Hands-on experience with Dell enterprise tooling, such as Dell Command | Update, Dell Command | Configure, and BIOS and Secure Boot management.
  • Experience with BeyondTrust or a comparable privileged access or remote support platform.
  • Experience with Microsoft Defender for Endpoint, Windows LAPS, or Azure DevOps Boards.
  • Certifications such as Microsoft MD-102, MS-102, SC-300, or ITIL 4 Foundation (not required).

Compensation Ranges

Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.

EEO Requirements

It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.

All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.

Physical Requirements

The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.

Disclaimer

The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.

Similar jobs

Apply for this job