Endpoint Management Engineer

Encore Technologies LLC

United States

Hybrid

USD 110,000 - 150,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Encore Technologies LLC is seeking an Endpoint Management Engineer to design, deploy, and secure multi‑tenant endpoint platforms across Windows, macOS, iOS, Android, and Linux. You will lead zero‑touch provisioning, software packaging, patching, and enforcement of security baselines while driving modernization across Intune, MECM, NinjaOne, BigFix, and other tools.

You will automate tasks with PowerShell, Graph API, and platform scripting, and act as a senior escalation point for

Qualifications

  • Bachelor’s degree or equivalent work experience.
  • Minimum 5 years of hands‑on endpoint management experience.
  • Experience with multiple enterprise endpoint management platforms.
  • Strong scripting and automation skills in PowerShell; Graph API knowledge.
  • Familiarity with Windows Autopilot, co‑management, and modern management workflows.

Responsibilities

  • Design, deploy, configure, and maintain endpoint management platforms (Intune, MECM, NinjaOne, BigFix).
  • Build and maintain zero-touch provisioning workflows (Autopilot, ABM/ADE, Android Enterprise).
  • Package, test, publish, and version enterprise apps with detection rules and rollback paths.
  • Own patch cycles and vulnerability remediation across platforms within SLAs.
  • Enforce security baselines, manage identity integration, and ensure endpoint posture for access decisions.
  • Develop and maintain automation/scripts to streamline deployments and reporting.
  • Monitor endpoint health and telemetry, drive proactive issue resolution.
  • Lead modernization efforts like co‑management migrations and tenant moves.
  • Configure RBAC, scope tags, and change control across client tenants.
  • Provide tier‑3 escalation support and document knowledge for teams.

Skills

PowerShell scripting
Automation
Analytical troubleshooting
Cross-functional collaboration
Communication skills

Education

Bachelor’s degree

Tools

Microsoft Intune
Configuration Manager (MECM)
NinjaOne
HCL BigFix
Tanium
Jamf
Workspace ONE

Job description

The Endpoint Management Engineer is responsible for the design, deployment, security, and ongoing operation of the endpoint management platforms Encore Technologies uses to manage client device estates. This is a platform-agnostic role: the engineer works across Microsoft Intune and Configuration Manager, NinjaOne, HCL BigFix, and other unified endpoint management (UEM) and remote monitoring and management (RMM) toolsets, supporting Windows, macOS, iOS, Android, and Linux endpoints across multiple client tenants.

The role owns the full endpoint lifecycle zero-touch provisioning, application packaging and delivery, patch and vulnerability remediation, security baseline enforcement, telemetry and reporting, and secure device retirement. The engineer is expected to work automation-first, using PowerShell, Microsoft Graph, and native platform scripting to eliminate manual effort, and to lead modernization efforts such as co-management, Configuration Manager to Intune migration, and RMM platform consolidation during client transitions.

This position serves as the senior technical escalation point for endpoint issues raised by the Service Desk, ITOCC, and On-Site Support teams, and partners with Security Operations, client stakeholders, and Encore delivery leadership to translate business and compliance requirements into scalable, well-documented endpoint standards.

Responsibilities:
  • Platform Administration – Design, deploy, configure, and maintain endpoint management platforms including Microsoft Intune, Microsoft Configuration Manager (MECM), NinjaOne, and HCL BigFix across single-tenant and multi-tenant client environments.
  • Zero-Touch Provisioning – Build and maintain modern provisioning workflows using Windows Autopilot, Apple Business Manager and Automated Device Enrollment, and Android Enterprise, reducing image-based build effort and shortening device delivery timelines.
  • Application Packaging and Delivery – Package, test, publish, and version control enterprise applications (Win32, MSIX, MSI, Winget, Homebrew, PKG) with defined detection rules, dependencies, supersedence, and rollback paths.
  • Patch and Vulnerability Remediation – Own operating system and third-party patch cycles across all managed platforms, coordinate maintenance windows using ring-based deployment, and remediate findings surfaced by vulnerability management tooling within contracted SLAs.
  • Security Baseline Enforcement – Implement and maintain ‘hardening’ baselines and compliance policies (CIS Benchmarks, Microsoft Security Baselines, NIST) including disk encryption, attack surface reduction, application control, local administrator management, endpoint detection and agent health.
  • Identity and Access Integration – Configure device compliance, Conditional Access policies, certificate and Wi‑Fi/VPN profile delivery in partnership with the identity team, ensuring endpoint posture is a trusted signal in access decisions.
  • Automation and Scripting – Develop and maintain PowerShell, Bash, Microsoft Graph API automations, Intune remediation scripts, tool specific scripting (Ex. BigFix custom scripting) to automate deployments, configuration drift correction, and reporting.
  • Endpoint Health and Digital Employee Experience – Monitor agent health, policy compliance, and device performance telemetry; use DEX data to proactively identify and resolve endpoint issues before they generate tickets.
  • Platform Migration and Modernization – Lead endpoint workstreams during client transitions and modernization projects, including co‑management enablement, Configuration Manager to Intune workload migration, tenant‑to‑tenant moves, and RMM platform consolidation.
  • Multi‑Tenant Governance – Configure and maintain role‑based access control, scope tags, organizational units, policy naming standards, and change control across client tenants to protect data separation and enforce least privilege.
  • Technical Escalation – Serve as tier‑3 escalation for endpoint incidents and problems raised by the Service Desk, ITOCC, and field teams; perform root cause analysis and drive permanent corrective action.
  • ITSM and Change Management – Integrate endpoint platforms with ITSM tooling for asset, incident, and request automation, and submit endpoint changes through the established change management process with tested back‑out plans.
  • Reporting and Client Reviews – Produce compliance, patch, and lifecycle reporting for internal leadership and client business reviews, translating platform telemetry into clear risk and health narratives.
  • Documentation and Enablement – Maintain run books, standard operating procedures, and configuration‑as‑documented records for every managed platform, and transfer knowledge to Service Desk and field teams through training and knowledge base content.
  • Technology Evaluation – Track vendor roadmaps and emerging endpoint capabilities, evaluate new tooling against Encore service standards, and recommend improvements that reduce cost, risk, or manual effort.
Qualifications:
  • Bachelor’s degree in Computer Science, Information Technology, or a related field, or equivalent work experience.
  • Minimum of 5 years of hands‑on endpoint management experience in enterprise or managed services environments.
  • Demonstrated production experience with at least two enterprise endpoint management platforms, such as Microsoft Intune, Microsoft Configuration Manager, NinjaOne, HCL BigFix, Tanium, Jamf, or Workspace ONE.
  • Working knowledge of modern Windows management, including Autopilot, co‑management, Windows Update for Business, and Windows Update rings.
  • Experience managing non‑Windows endpoints, including macOS and iOS/Android mobile device and application management.
  • Strong scripting and automation skills in PowerShell, with working knowledge of Microsoft Graph API; Bash or Python experience is a plus.
  • Solid understanding of Microsoft Entra ID, Active Directory, Group Policy, certificate services, and Conditional Access.
  • Practical experience with endpoint security tooling and hardening standards, including Microsoft Defender for Endpoint, disk encryption, privilege management, and CIS or NIST baselines.
  • Application packaging and software distribution experience across multiple formats and platforms.
  • Familiarity with ITSM practices and platforms, including incident, problem, and change management workflows.
  • Excellent analytical and troubleshooting skills, with the ability to isolate complex issues across identity, network, application, and device layers.
  • Effective written and verbal communication skills, with the ability to work across cross‑functional teams and explain technical concepts to non‑technical stakeholders.
  • Preferred certifications: Microsoft 365 Certified: Endpoint Administrator Associate (MD‑102), Microsoft Certified: Identity and Access Administrator Associate, CompTIA Security+, Apple Certified Support Professional, ITIL 4 Foundation, or platform‑specific NinjaOne or BigFix certifications.
  • Prior experience in a managed service provider or multi‑client environment is strongly preferred.
Physical Requirements:
  • Prolonged periods sitting at a desk and working on the computer.
  • Occasional lifting, pushing, and pulling up to 15 lbs.
  • Hybrid position: in-office and remote workdays.
  • Occasional travel to client sites within the greater Cincinnati and Northern Kentucky region.
  • Participation in a scheduled on‑call rotation and periodic after‑hours maintenance windows.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

End Point System Engineer
End Point System Engineer

Encore Technologies • Cincinnati (OH)

On-site
USD 90,000 - 120,000
Endpoint Services Specialist
Endpoint Services Specialist

NetCov • New York (NY)

On-site
USD 55,000 - 85,000
Endpoint Engineer
Endpoint Engineer

Wildfire Talent Solutions • Tulsa (OK)

On-site
USD 80,000 - 120,000
Opportunities for professional growth
Certification support
Competitive compensation
+1
Senior Endpoint Engineer
Senior Endpoint Engineer

Kwik Trip, Inc. • La Crosse (WI)

On-site
USD 90,000 - 120,000
Senior Endpoint Engineer (Applications)
Senior Endpoint Engineer (Applications)

The AES Corporation • Indianapolis (IN)

On-site
USD 80,000 - 120,000
Endpoint Platform Engineer
Endpoint Platform Engineer

EXOS • Indianapolis (IN)

On-site
USD 130,000 - 190,000
Desktop Engineer
Desktop Engineer

Vaco Recruiter Services • Jacksonville (FL)

On-site
USD 90,000 - 130,000
Senior Endpoint Engineer
Senior Endpoint Engineer

Jobtailor • Neptune Township (NJ)

On-site
USD 140,000 - 190,000
Endpoint Engineer
Endpoint Engineer

DivergeIT • Dallas (TX)

On-site
USD 90,000 - 110,000
Senior Endpoint Engineer
Senior Endpoint Engineer

Jobtailor • Sanford (FL)

On-site
USD 130,000 - 175,000