About Alvarez & Marsal
Alvarez & Marsal (A&M) is a global consulting firm with over 10,000 entrepreneurial, action and results‑oriented professionals in over 40 countries. We take a hands‑on approach to solving our clients' problems and assisting them in reaching their potential. Our culture celebrates independent thinkers and doers who positively impact our clients and shape our industry. The collaborative environment and engaging work—guided by A&M's core values of Integrity, Quality, Objectivity, Fun, Personal Reward, and Inclusive Diversity—are why our people love working at A&M.
The Team
GESS group at A&M provides critical business support to the firm and encompasses a range of functions including Information Technology, Marketing, Information Security, Insight Centre & Knowledge Management, Corporate Real Estate, Human Resources, and Operations. GESS enables A&M’s client service delivery, go‑to‑market, risk management and growth goals as a strategic partner.
How You Will Contribute
We are seeking an experienced Privilege Management Engineer at Level 3 to own, administer, and continuously improve our privilege management solution. This is a senior technical role sitting at the intersection of endpoint security, application control, and IT operations. The successful candidate will be responsible for configuring and maintaining privilege management policies and filters, ensuring applications run securely without unnecessary elevation, and working closely with packaging, security, and desktop engineering teams to support a stable and compliant endpoint environment. A key focus of this role is the configuration of our privilege management solution for applications requiring manual installation, tracking application version updates, and coordinating with the packaging team to ensure timely remediation and minimal end‑user disruption. Available capacity will also be directed toward proactive update tracking and cross‑team coordination. In addition to privilege management responsibilities, this role encompasses the management and administration of Microsoft Intune, covering device compliance, Win32 application deployment, policy configuration, and endpoint lifecycle management across the Windows and macOS estate.
Key Responsibilities
- Privilege Management Configuration: Configure and manage the privilege management solution for applications requiring manual installation, ensuring appropriate elevation rules and policies are in place.
- Implement and maintain required settings within the privilege management solution to ensure applications run without disruption to end users, minimising unnecessary UAC prompts and elevation failures.
- Design, test, and deploy application‑specific privilege policies including allow‑listing, on‑demand elevation, and sandboxed execution rules.
- Review and validate privilege requests, assessing risk and ensuring least‑privilege principles are upheld across the estate.
- Maintain and optimise policy sets, ensuring they remain accurate, effective, and aligned with organisational security standards.
- Troubleshoot and resolve L3 escalations relating to privilege management, application blocking, and elevation failures.
- Version Tracking & Packaging Coordination: Track version updates for all manually packaged applications within scope, maintaining an up‑to‑date register of current and target versions; proactively notify the packaging team of available updates, provide release notes and compatibility considerations; coordinate with the packaging team to prioritise and schedule updates; manage records of application versions, policy changes, and update history for audit and compliance.
- Endpoint Management (Microsoft Intune): Manage device compliance policies, configuration profiles, and remediation scripts within Intune across Windows and macOS fleets; package, deploy, and maintain Win32 applications via Intune, including detection rules, dependencies, and supersede configurations; author and maintain PowerShell‑based platform scripts and remediation scripts adhering to logging and auditing standards; coordinate Intune application assignments and resolve L3 Intune escalations; integrate Intune with complementary tooling; support Windows Autopilot provisioning and pre‑provisioning scenarios.
- Security, Compliance & Governance: Ensure privilege management policies align with organisational security frameworks, including CIS benchmarks, Cyber Essentials, and internal policies; support security audits and compliance reviews; work with the security team to identify and remediate privilege‑related risks, misconfigurations, and policy gaps; contribute to ongoing development and improvement of the privilege management strategy.
- Collaboration & Documentation: Collaborate with desktop engineering, application packaging, and IT security teams; produce and maintain technical documentation including policy designs, runbooks, process guides, and knowledge‑base articles; participate in change management processes ensuring proper assessment, approval, and communication.
Qualifications
- 3+ years of experience in a senior IT engineering or endpoint security role with demonstrable hands‑on experience with a privilege‑management solution (e.g., BeyondTrust EPM, CyberArk Endpoint Privilege Manager, Ivanti).
- Strong understanding of Windows privilege management concepts including UAC, least privilege, application control, and elevation policies.
- Experience configuring privilege policies for complex or manually installed applications, including custom elevation rules and policy exceptions.
- Solid understanding of application packaging practices and their relationship to privilege management.
- Ability to assess and triage application elevation requests, balancing user productivity with security requirements.
- Experience within ITSM frameworks including change management, incident management, and request fulfilment.
- Strong analytical and troubleshooting skills with the ability to investigate and resolve complex privilege‑related issues.
- Excellent documentation skills, able to produce clear technical and non‑technical content.
- Good communication and stakeholder management skills; experience working across IT, security, and business teams.
- Hands‑on experience with Microsoft Intune, including device compliance, Win32 deployment, configuration profiles, and PowerShell scripting for policy automation.
Your Journey at A&M
We recognise that our people are the driving force behind our success, so we prioritise an employee experience that fosters each person’s unique professional and personal development. Our robust performance development process promotes continuous learning, rewards contributions, and fosters a meritocratic culture. With top‑notch training and on‑the‑job learning opportunities, you can acquire new skills and advance your career. We prioritise your well‑being, providing benefits and resources to support you personally. Our people consistently highlight the growth opportunities, the unique entrepreneurial culture, and the fun we have together as their favourite aspects of working at A&M. The possibilities are endless for high‑performing and passionate professionals.