Endpoint Systems Engineer II

Spring EQ

Philadelphia (Philadelphia County)

Hybrid

USD 90,000 - 130,000

Full time

11 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

401k Company Match
Annual Charitable Matching Gift Prog
Company Holidays
Credit Union Membership
Dependent Care Plan
Disability Insurance
Employee Assistance Program
Life Insurance
Medical Insurance
Paid Time Off Plan
Vision Insurance
Weekly Non-Management Dinner Benefit

Job summary

Spring EQ is seeking an Endpoint Systems Engineer II to design, manage, and support the organization’s endpoint environment across Windows, macOS, Cloud PCs, and related platforms. This role owns configuration, deployment, policy management, automation, and lifecycle support of desktops and devices using Intune, Mosyle, Entra ID, Windows 365 Cloud PCs, Group Policy, MDM, and related tools.

This position partners closely with IT operations, service desk, security, and infrastructure teams to

Qualifications

  • Strong understanding of MDM concepts and endpoint security.
  • Experience with Microsoft Entra ID and Conditional Access.
  • Ability to troubleshoot complex endpoint, identity, policy, and app deployment issues.
  • Excellent documentation and cross-team collaboration.

Responsibilities

  • Manage Windows endpoints using Intune, Group Policy, configuration profiles, compliance policies, application deployment, update rings, and endpoint security baselines.
  • Manage macOS endpoints using Mosyle, including device enrollment, configuration profiles, software deployment, security controls, and compliance enforcement.
  • Administer and support Windows 365 Cloud PCs, including provisioning, assignment, policy configuration, troubleshooting, and lifecycle management.
  • Design and maintain endpoint management standards for Windows, macOS, mobile devices, and virtual or cloud desktop environments.
  • Configure and maintain Microsoft Entra ID device join, hybrid join, conditional access, device compliance, and identity-based access policies.
  • Package, deploy, and update applications across managed endpoints using Intune, Mosyle, scripting, and automation tools.
  • Develop and maintain endpoint security policies, including encryption, antivirus or EDR integration, firewall settings, patching, local admin controls, and device compliance.
  • Create, review, and maintain Group Policy Objects, MDM policies, configuration profiles, and security baselines.
  • Troubleshoot complex endpoint issues involving operating systems, user profiles, authentication, networking, device enrollment, application deployment, and policy conflicts.
  • Automate endpoint administration tasks using PowerShell, shell scripting, Microsoft Graph, or other relevant tools.
  • Maintain documentation for endpoint standards, configuration policies, troubleshooting procedures, and operational processes.
  • Collaborate with security teams to support audit requirements, vulnerability remediation, endpoint hardening, and compliance initiatives.
  • Evaluate new endpoint technologies and recommend improvements to increase security, reliability, automation, and user experience.

Skills

MDM concepts
Entra ID
Endpoint security
Troubleshooting
Documentation
Collaboration

Education

Bachelor’s degree in IT/CS
3–5 years endpoint engineering

Tools

Microsoft Intune
Mosyle
Group Policy
PowerShell
Microsoft Entra ID
Azure Virtual Desktop

Job description

Spring EQ is a national home equity lender providing flexible and tailored financing solutions directly to consumers with a national network of experienced brokers and partners. Since its founding in 2016, Spring EQ is among the fastest growing and highest-rated home equity financing partners in the United States. Spring EQ offers a broad range of home equity products and delivers a simple and streamlined process that results in faster funding, trustworthy loans, and less frustration for consumers today. To learn more about Spring EQ, visit www.springeq.com.

At Spring EQ, it is our mission to empower homeowners and buyers to achieve and maximize the value of homeownership in a simple, fast, and ethical manner. Our values are to

  • Be kind and treat all people – teammates, customers, and vendors – with respect and consideration
  • Be adaptable and embrace change
  • Be accountable and take responsibility and deliver the effort to fully complete the task
  • Be better and strive for continuous improvement in ourselves, our team, and the company for our customers
  • Be part of the solution and solve problems, find the answers, and collaborate
  • Work hard, have fun, and get things done

The Endpoint Systems Engineer II is responsible for designing, managing, securing, and supporting the organization’s modern endpoint environment across Windows, macOS, Cloud PCs, and related end-user computing platforms. This role owns the configuration, deployment, policy management, automation, and lifecycle support of corporate desktops and devices using technologies such as Microsoft Intune, Mosyle, Microsoft Entra ID, Windows 365 Cloud PCs, Group Policy, mobile device management, and related identity, security, and endpoint management tools. This position partners closely with IT operations, service desk, security, infrastructure, and business teams to ensure endpoints are secure, compliant, reliable, and easy for employees to use.

Responsibilities
  • Manage Windows endpoints using Microsoft Intune, Group Policy, configuration profiles, compliance policies, application deployment, update rings, and endpoint security baselines.
  • Manage macOS endpoints using Mosyle, including device enrollment, configuration profiles, software deployment, security controls, and compliance enforcement.
  • Administer and support Windows 365 Cloud PCs, including provisioning, assignment, policy configuration, troubleshooting, and lifecycle management.
  • Design and maintain endpoint management standards for Windows, macOS, mobile devices, and virtual or cloud desktop environments.
  • Configure and maintain Microsoft Entra ID device join, hybrid join, conditional access, device compliance, and identity-based access policies.
  • Package, deploy, and update applications across managed endpoints using Intune, Mosyle, scripting, and automation tools.
  • Develop and maintain endpoint security policies, including encryption, antivirus or EDR integration, firewall settings, patching, local admin controls, and device compliance.
  • Create, review, and maintain Group Policy Objects, MDM policies, configuration profiles, and security baselines.
  • Troubleshoot complex endpoint issues involving operating systems, user profiles, authentication, networking, device enrollment, application deployment, and policy conflicts.
  • Automate endpoint administration tasks using PowerShell, shell scripting, Microsoft Graph, or other relevant tools.
  • Maintain documentation for endpoint standards, configuration policies, troubleshooting procedures, and operational processes.
  • Collaborate with security teams to support audit requirements, vulnerability remediation, endpoint hardening, and compliance initiatives.
  • Evaluate new endpoint technologies and recommend improvements to increase security, reliability, automation, and user experience.
Required Skills/Abilities
  • Strong understanding of MDM concepts, device compliance, configuration profiles, application deployment, and endpoint security.
  • Working knowledge of Microsoft Entra ID, Conditional Access, device registration, SSO, and identity-based policy enforcement.
  • Familiarity with endpoint security concepts including encryption, EDR/AV tools, patching, least privilege, local admin management, and security baselines.
  • Ability to troubleshoot complex endpoint, identity, policy, and application deployment issues.
  • Strong documentation, oral/written communication, and cross-team collaboration skills.
Education and Experience
  • Bachelor’s degree in Information Technology, Computer Science, or a related field (or equivalent work experience).
  • 3–5 years of experience in endpoint engineering, systems administration, or a related IT role.
  • Experience managing Windows endpoints with Microsoft Intune, Group Policy, and Microsoft Entra ID.
  • Experience managing macOS devices with Mosyle or a similar Apple MDM platform.
  • Experience with Windows 365 Cloud PCs, Azure Virtual Desktop, or similar virtual desktop or cloud PC technologies.
Healthy work-life balance.

We are committed to supporting a healthy work-life balance and fostering an environment of productivity and collaboration. This position follows a hybrid schedule for team members working in our corporate offices, combining on-site presence with remote flexibility. Our hybrid model is designed to promote teamwork and engagement while also providing the adaptability professionals need to manage their responsibilities effectively.

  • 401k Company Match
  • Annual Charitable Matching Gift Program
  • Company Holidays
  • Credit Union Membership
  • Dependent Care Plan
  • Disability Insurance
  • Employee Assistance Program
  • Life Insurance
  • Medical Insurance
  • Paid Time Off Plan
  • Vision Insurance
  • Weekly Non-Management Dinner Benefit
Candidates must have current, unrestricted authorization to work in the United States. The Company does not sponsor or support employment‑based visas, extensions, renewals, or any immigration‑related programs now or in the future.
Spring EQ is an Equal Opportunity Employer. We make all employment decisions based on merit and business needs. If you require a reasonable accommodation at any stage of the hiring or employment process, please contact recruiting@springeq.com
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Endpoint & Cloud Security Engineer II
Endpoint & Cloud Security Engineer II

Spring EQ • Philadelphia

Hybrid
USD 90,000 - 130,000
401k Company Match
Annual Charitable Matching Gift Prog
Company Holidays
+9
Endpoint Engineer
Endpoint Engineer

Antero Resources Corp • Denver (CO), Northern (KY)

Hybrid
USD 125,000 - 140,000
Health care
HSA and DCA
Life Insurance
+8
Endpoint Engineer
Endpoint Engineer

Antero Resources Corporation • Denver (CO)

On-site
USD 125,000 - 140,000
Health insurance
401(k)
Vacation & sick time
+1
Endpoint Services Engineer
Endpoint Services Engineer

SchoolsFirst Federal Credit Union • Tustin (CA)

On-site
USD 65,000 - 103,000
Endpoint Engineer
Endpoint Engineer

Wildfire Talent Solutions • Tulsa (OK)

On-site
USD 80,000 - 120,000
Opportunities for professional growth
Certification support
Competitive compensation
+1
End Point System Engineer
End Point System Engineer

Encore Technologies • Cincinnati (OH)

On-site
USD 90,000 - 120,000
Senior Intune Engineer
Senior Intune Engineer

Pennant • Eagle (ID)

Hybrid
USD 90,000 - 120,000
True Work-Life balance
Full benefits package
Paid time off
+1
Endpoint Services Engineer
Endpoint Services Engineer

SchoolsFirst Federal Credit Union • United States

On-site
USD 98,000 - 156,000
IT Endpoint Engineer
IT Endpoint Engineer

Spheros Environmental • Denver (CO)

Hybrid
USD 100,000 - 125,000
Hybrid flexibility
Bonuses & 401(k) contributions
Professional growth
+1
Endpoint Services Engineer
Endpoint Services Engineer

Schoolsfirst-Federal-Credit-Union • Tustin (CA)

On-site
USD 98,000 - 156,000