Stand out for this role — generate a tailored resume and cover letter in about a minute.
FlexiTalent China in Kuala Lumpur seeks an Endpoint Engineer to own Microsoft Endpoint Manager (SCCM and Intune) environments, driving device lifecycle, security policies, and automation. You will work with security and IT teams to ensure a seamless experience across corporate and BYOD.
You will design MDM/MAM policies for Windows, iOS, and Android, enforce Conditional Access, and automate tasks with PowerShell while documenting solutions for ongoing reliability.
We are looking for a skilled Endpoint Engineer to take ownership of our Microsoft Endpoint Manager environment (SCCM and Intune). In this role, you will be the go‑to expert for managing the full lifecycle of Windows devices, enforcing security and compliance policies, and driving automation through scripting. You will work closely with security and infrastructure teams to ensure a seamless, secure, and productive experience for all users – whether on corporate‑owned or BYOD devices.
Deploy, configure, and maintain Microsoft Endpoint Manager solutions, including both SCCM (Configuration Manager) and Microsoft Intune, ensuring high availability and optimal performance.
Manage the complete lifecycle of Windows devices – from provisioning and software distribution to patch management, asset tracking, and retirement.
Design and implement Mobile Device Management (MDM) and Mobile Application Management (MAM) policies to protect corporate data while enabling user productivity across iOS, Android, and Windows platforms.
Collaborate with security teams to enforce device compliance policies (e.g., Conditional Access, compliance profiles) and respond to security incidents related to endpoints.
Support enrollment of both corporate‑owned and BYOD devices, ensuring policies are correctly applied and user experience is frictionless.
Troubleshoot and resolve complex endpoint management issues; continuously monitor system health and optimize performance, scalability, and reliability.
Automate routine tasks using PowerShell scripting to reduce manual effort and improve operational efficiency.
Document processes, configurations, and troubleshooting guides, and mentor junior team members as needed.
Deep technical knowledge of SCCM and Intune architecture, including co‑management, tenant attach, and migration scenarios.
Strong hands‑on experience with Windows client management (Windows 10/11), including OS deployment, driver management, and servicing.
Proficiency in PowerShell scripting for automation, reporting, and configuration management.
Solid understanding of Azure Active Directory (Azure AD / Entra ID), Conditional Access, Windows Autopilot, and other modern device management technologies.
Experience managing endpoints in a large‑enterprise environment (1,000+ devices) is preferred – you understand the challenges of scale, change control, and performance tuning.
Excellent communication skills – able to explain technical concepts to non‑technical stakeholders and collaborate effectively across teams.
Language: Fluency in English (written and spoken) is required
Microsoft certifications – especially MD‑102 (Endpoint Administrator) or MS‑500 (Microsoft 365 Security Administrator).
Cross‑platform management experience with mobile OS (iOS, Android) and macOS endpoints using Intune or third‑party solutions.
Familiarity with modern zero‑trust security principles and endpoint detection & response (EDR) tools.
Experience with co‑management and cloud‑native endpoint management strategies.