Staff System Engineer 1
Blue Yonder is seeking a highly experienced Senior Endpoint Engineering SME who will lead the design, engineering, modernization, and security of the enterprise endpoint ecosystem. The role owns the endpoint strategy and delivers transformational initiatives across Windows, MacBook, and mobile devices.
Key Responsibilities
Enterprise Device Management
- Lead modernization initiatives including ManageEngine Endpoint Central cloud migration, Microsoft Intune adoption, and transition away from legacy endpoint management platforms.
- Design and implement automated endpoint patching, software deployment, and application lifecycle management processes to improve security, compliance, and operational efficiency.
- Establish and maintain endpoint governance through device inventory management, compliance reporting, asset visibility, and endpoint health monitoring across the global environment.
Endpoint Modernization
- Lead programs such as Windows Autopilot deployment, Entra ID Join adoption, and migration from traditional Group Policy to cloud‑native Intune/MDM policies.
- Design and implement modern endpoint access and identity solutions, including certificate lifecycle management and replacement of legacy Hybrid Join VPN architectures with secure, cloud‑first access technologies.
- Establish and maintain Windows endpoint standards, including Windows 11 lifecycle management, security baselines, configuration governance, and endpoint compliance across the enterprise.
Secure Workforce
- Architect and deliver modern identity and access management solutions, including DUO MFA migration to Microsoft Authenticator and Intune Conditional Access integration.
- Implement password‑less authentication via biometrics such as Windows Hello for Business.
- Modernize guest network services, optimize Global Protect endpoint protection and connectivity, and implement device posture‑based access controls aligned with Zero Trust principles.
Endpoint Trust and Governance
- Implement endpoint trust and governance frameworks, including privileged access management, admin rights automation, and endpoint hardening initiatives aligned with Zero Trust principles.
- Drive endpoint compliance and mobile security strategies through software lifecycle governance, mobile device segmentation, and enhanced security controls for corporate‑owned and Blue Yonder devices.
Endpoint Strategy and Architecture
- Establish endpoint security, compliance, and governance standards through Microsoft Defender strategy, device posture controls, Zero Trust principles, and ongoing review of endpoint usage and security policies.
- Develop and execute the endpoint technology roadmap, driving hardware lifecycle automation, VDI architecture modernization, and future workplace technology strategies that enhance user experience, operational efficiency, and scalability.
- Own DaaS Architecture & Design, including solution design and capacity planning.
Security and Compliance
- Lead endpoint security engineering initiatives, including Microsoft Defender/XDR deployment, endpoint hardening, vulnerability management, Zero Trust controls, and Conditional Access integration.
- Establish and maintain enterprise endpoint security and compliance standards through device encryption, CIS benchmark alignment, and continuous security monitoring across all managed endpoints.
Automation and Engineering
- Develop automation for provisioning, patching, certificates, and compliance using Manage Engine and Microsoft Intune.
- Build Microsoft Graph API integrations for endpoint management workflows.
- Automate certificate renewal, device lifecycle events, and compliance remediation; create self‑healing endpoint configurations and monitoring scripts.
Qualifications
- Bachelor’s degree in computer science, MIS, engineering, or equivalent work experience.
- 10+ years in Enterprise Endpoint Engineering or End User Computing.
- 5+ years hands‑on experience with Microsoft Intune or Endpoint Manager.
- Proven experience managing 10,000+ enterprise endpoints globally.
- Experience delivering large‑scale endpoint modernization programs.
- Advanced troubleshooting methodology and ability to judge priorities and adjust work accordingly.
Preferred Skills
- Strong experience in Windows OS deployment, configuration, lifecycle management, and Windows security baselines/CIS benchmarks.
- Experience with Microsoft Entra ID / Azure AD Conditional Access, MFA, SSPR, and Microsoft Authenticator deployment and migration.
- Strong knowledge of Windows Autopilot – Zero‑touch provisioning.
- Proficiency in MS Defender and BitLocker for encryption and key management.
- Hands‑on experience in vulnerability management and device compliance enforcement.
- Hands‑on experience with ManageEngine patch management.
- Strong knowledge of PowerShell – advanced scripting, modules, and CI/CD integration.
- Working knowledge of DNS, DHCP, endpoint network diagnostics.
- Experience with VPN solutions – Global Protect, Always On VPN, or Microsoft VPN solutions.
- Solid foundational understanding of Group Policy (GPO) design and migration to Intune MDM policies.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.