Desktop Endpoint Specialist

Tetra Tech

Boulder (CO)

On-site

USD 110,000 - 140,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical insurance
Dental insurance
Vision insurance
Life insurance
401(k) plan
Tuition assistance
Commuter benefits
Paid time off
11 federal holidays

Job summary

Halvik Corp is seeking a candidate to design, deploy, configure, administer, and support enterprise endpoint management solutions focused on Jamf Pro and Apple device management, with supporting Microsoft Intune expertise. This on-site role is based in Boulder, CO, Monday through Friday.

The ideal candidate will have direct Jamf Pro experience, ABM/ADE integration, Bash scripting, and strong macOS administration knowledge, supported by MS Entra ID/AD and SSO/SAML familiarity.

Qualifications

  • AA/AS degree (or equivalent).
  • Minimum 6 years of experience supporting endpoint management, enterprise mobility, systems administration, or related enterprise IT environments.
  • Strong hands-on experience with Jamf Pro server deployment and administration.
  • Experience installing, configuring, upgrading, and troubleshooting Jamf Pro infrastructure.
  • Strong knowledge of macOS administration and Apple MDM.
  • Experience with Apple Business Manager, Automated Device Enrollment, APNs, PreStage Enrollments, configuration profiles, policies, and Smart Groups.
  • Experience with Bash/shell scripting and endpoint automation.
  • Knowledge of FileVault, certificates, SSL/TLS, endpoint security, and compliance.
  • Experience integrating Jamf with Entra ID/Active Directory and SSO/SAML.
  • Working knowledge of Microsoft Intune and Microsoft endpoint management.
  • Strong troubleshooting and enterprise endpoint-management experience.
  • Experience with Jamf Protect and Jamf Connect.

Responsibilities

  • Design, deploy, configure, and administer Jamf Pro server infrastructure in enterprise environments.
  • Perform Jamf Pro installation, initial configuration, upgrades, patching, backup, and troubleshooting.
  • Configure Jamf Pro components including JSS, database, web/application services, APNs, SSL certificates, and integrations.
  • Configure Apple Business Manager (ABM) and integrate it with Jamf Pro for Automated Device Enrollment (ADE).
  • Configure and manage PreStage Enrollments, enrollment profiles, configuration profiles, policies, Smart Groups, and Extension Attributes.
  • Manage macOS, iOS, and iPadOS device enrollment, configuration, compliance, and lifecycle management.
  • Package, test, deploy, and maintain macOS applications using Jamf Pro.
  • Create Jamf policies and Bash/shell scripts to automate endpoint configuration and administration.
  • Manage FileVault encryption, recovery keys, security settings, certificates, and endpoint compliance.
  • Troubleshoot Jamf enrollment, policy execution, application deployment, configuration profile, certificate, APNs, and connectivity issues.
  • Perform Jamf Pro upgrades and migrations, including pre-upgrade validation, backups, testing, and post-upgrade verification.
  • Integrate Jamf with Microsoft Entra ID, Active Directory, SSO/SAML, and enterprise security platforms.
  • Support Microsoft Intune for Windows and mobile device management, including enrollment, configuration policies, compliance policies, and application deployment.
  • Support integration/co-management between Jamf Pro and Microsoft Intune where required.
  • Support endpoint security solutions such as Microsoft Defender, CrowdStrike, and Zscaler.
  • Monitor endpoint inventory, compliance, application status, and Jamf infrastructure health.
  • Develop endpoint standards, technical documentation, deployment procedures, and troubleshooting guides.
  • Work with Security, Network, Infrastructure, and Service Desk teams to resolve complex endpoint issues.
  • Participate in endpoint migration, device refresh, OS upgrade, and enterprise deployment projects.
  • Follow enterprise change, incident, problem-management, and security processes.

Skills

Jamf Pro
Apple device management
Microsoft Intune
ABM & ADE
PreStage Enrollments
Bash scripting
FileVault
Entra ID/AD & SSO/SAML
Jamf Connect
Jamf Protect

Education

AA/AS degree (or equivalent)

Job description

Halvik Corp delivers a wide range of services to 13 executive agencies and 15 independent agencies. Halvik is a highly successful WOB business with more than 50 prime contracts and 500+ professionals delivering Digital Services, Advanced Analytics, Artificial Intelligence/Machine Learning, Cyber Security and Cutting-Edge Technology across the US Government. Be a part of something special!

Position Overview

Halvik is seeking a candidate who will be responsible for designing, deploying, configuring, administering, and supporting enterprise endpoint management solutions. The ideal candidate will have direct experience with Jamf Pro and Apple device management, with supporting experience in Microsoft Intune.

This role in on-site in Boulder, CO daily M-F.

Core Responsibilities

  • Design, deploy, configure, and administer Jamf Pro server infrastructure in enterprise environments.
  • Perform Jamf Pro installation, initial configuration, upgrades, patching, backup, and troubleshooting.
  • Configure Jamf Pro components including JSS, database, web/application services, APNs, SSL certificates, and integrations.
  • Configure Apple Business Manager (ABM) and integrate it with Jamf Pro for Automated Device Enrollment (ADE).
  • Configure and manage PreStage Enrollments, enrollment profiles, configuration profiles, policies, Smart Groups, and Extension Attributes.
  • Manage macOS, iOS, and iPadOS device enrollment, configuration, compliance, and lifecycle management.
  • Package, test, deploy, and maintain macOS applications using Jamf Pro.
  • Create Jamf policies and Bash/shell scripts to automate endpoint configuration and administration.
  • Manage FileVault encryption, recovery keys, security settings, certificates, and endpoint compliance.
  • Troubleshoot Jamf enrollment, policy execution, application deployment, configuration profile, certificate, APNs, and connectivity issues.
  • Perform Jamf Pro upgrades and migrations, including pre-upgrade validation, backups, testing, and post-upgrade verification.
  • Integrate Jamf with Microsoft Entra ID, Active Directory, SSO/SAML, and enterprise security platforms.
  • Support Microsoft Intune for Windows and mobile device management, including enrollment, configuration policies, compliance policies, and application deployment.
  • Support integration/co-management between Jamf Pro and Microsoft Intune where required.
  • Support endpoint security solutions such as Microsoft Defender, CrowdStrike, and Zscaler.
  • Monitor endpoint inventory, compliance, application status, and Jamf infrastructure health.
  • Develop endpoint standards, technical documentation, deployment procedures, and troubleshooting guides.
  • Work with Security, Network, Infrastructure, and Service Desk teams to resolve complex endpoint issues.
  • Participate in endpoint migration, device refresh, OS upgrade, and enterprise deployment projects.
  • Follow enterprise change, incident, problem-management, and security processes.

Minimum Requirements

  • Education: AA/AS degree (or equivalent).
  • Experience: Minimum 6 years of experience supporting endpoint management, enterprise mobility, systems administration, or related enterprise IT environments.
  • Technical Proficiency:
    • Strong hands-on experience with Jamf Pro server deployment and administration.
    • Experience installing, configuring, upgrading, and troubleshooting Jamf Pro infrastructure.
    • Strong knowledge of macOS administration and Apple MDM.
    • Experience with Apple Business Manager, Automated Device Enrollment, APNs, PreStage Enrollments, configuration profiles, policies, and Smart Groups.
    • Experience with Bash/shell scripting and endpoint automation.
    • Knowledge of FileVault, certificates, SSL/TLS, endpoint security, and compliance.
    • Experience integrating Jamf with Entra ID/Active Directory and SSO/SAML.
    • Working knowledge of Microsoft Intune and Microsoft endpoint management.
    • Strong troubleshooting and enterprise endpoint-management experience.
    • Experience with Jamf Protect and Jamf Connect.
  • Certifications: While not mandatory, possession will have more weight in consideration (i.e., Jamf Certified Associate, Administrator or Engineer).
  • Must be able to obtain and maintain a Public Trust security clearance

Preferred Expertise

  • Demonstrated success supporting Federal contracts.
  • Strong technical analysis and troubleshooting capability and skills; ability to escalate complex issues; strong technical documentation skills.
  • Strong analytical, written, and verbal communication skills, with the ability to translate technical risks and content into terms suitable for executive and government stakeholders.
  • Ability to work collaboratively with others and contribute to a team environment.

Halvik offers a competitive full benefits package including:
Company-supported medical, dental, vision, life, STD, and LTD insurance
Benefits include 11 federal holidays and PTO
Eligible employees may receive performance-based incentives in recognition of individual and/or team achievements.
401(k) with company matching
Flexible Spending Accounts for commuter, medical, and dependent care expenses
Tuition Assistance
Charitable Contribution matching

Halvik Corp is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status.

Halvik'spay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Desktop Endpoint Specialist
Desktop Endpoint Specialist

Halvik • Boulder (CO)

On-site
USD 95,000 - 150,000
Medical, dental, vision, life, STD, LT
401(k) with company matching
11 holidays and PTO
+3
Network Engineer
Network Engineer

Tetra Tech • Washington

On-site
USD 120,000 - 150,000
Company-paid health benefits
401(k) with company match
Paid federal holidays and PTO
+2
Mid-Level Security Engineer
Mid-Level Security Engineer

Halvik • Alexandria (VA)

Hybrid
USD 110,000 - 140,000
Medical insurance
Dental insurance
Vision insurance
+8
Endpoint Security Engineer
Endpoint Security Engineer

Halvik • Alexandria (VA)

On-site
USD 120,000 - 160,000
Full benefits package
401(k) with company matching
Tuition assistance
+3
Azure Engineer
Azure Engineer

Halvik • Washington

On-site
USD 120,000 - 160,000
Health insurance
401(k) with company matching
Paid time off (PTO)
Endpoint Security Engineer
Endpoint Security Engineer

Tetra Tech • Alexandria (VA)

On-site
USD 110,000 - 150,000
Medical Insurance
Dental Insurance
Vision Insurance
+1
Sr. Security Engineer
Sr. Security Engineer

Halvik • Alexandria (VA)

Hybrid
USD 140,000 - 190,000
Medical, dental, vision insurance
401(k) with company matching
Flexible Spending Accounts
+2
Web Apps Developer
Web Apps Developer

Halvik • Destin (FL)

On-site
USD 70,000 - 90,000
Company-supported medical, dental, vision, life, STD, and LTD insurance
401(k) with company matching
Tuition Assistance
AI/ML SME
AI/ML SME

Tetra Tech • Alexandria (VA)

On-site
USD 140,000 - 190,000
Company-supported medical, dental, and
Vision insurance
401(k) with company matching
+1
Web Apps Developer
Web Apps Developer

Halvik- • Destin (FL)

On-site
USD 80,000 - 100,000
Company-supported medical, dental, vision, life, STD, and LTD insurance
11 federal holidays and PTO
401(k) with company matching
+3