Job Summary
We are seeking an experienced Desktop Engineer to manage and evolve our enterprise endpoint environment—covering Windows devices, desktop applications, security configuration, imaging/provisioning, and lifecycle management. This role will focus heavily on modern endpoint management practices using Microsoft Intune, Windows Autopilot, and cloud‑first deployment/patching strategies, while maintaining and integrating with SCCM as needed.
The ideal candidate has hands‑on expertise in automated software packaging, application deployment at scale, software licensing/compliance, asset tracking, and endpoint security baselines. You will also contribute to systems architecture, helping design and implement innovative solutions based on leading‑edge technologies.
Key Tasks & Responsibilities (Essential Functions)
- Engineer, deploy, and support enterprise endpoints using Microsoft Intune (Configuration Profiles, Compliance Policies, Conditional Access alignment, app deployment).
- Design and operationalize Windows Autopilot for zero‑touch provisioning, including device enrollment, profile design, and deployment workflows.
- Implement and manage Windows Intune‑based patching strategies, including ring design, deadlines, feature update controls, notifications and reporting (experience patching through AUTOMOX a plus).
- Maintain integration and co‑management practices between SCCM and Intune, optimizing for cloud‑first where possible.
- Create, test, and maintain automated application packages (Win32 apps, MSI, MSIX where appropriate) and deployment workflows.
- Build automation using PowerShell and/or other scripting tools to streamline installs, configurations, remediations, and reporting.
- Troubleshoot complex deployment failures and endpoint configuration issues across diverse hardware and user profiles.
- Support software lifecycle management: inventory, metering/usage signals, licensing alignment, and compliance reporting.
- Ensure accurate asset tracking, entitlement validation, and audit readiness.
- Produce compliance dashboards and executive‑ready reporting (patch compliance, encryption coverage, endpoint health KPIs).
- Implement endpoint hardening aligned to organizational standards (e.g., BitLocker, CIS Level 1 policies).
- Partner with security teams to respond to endpoint vulnerabilities and to drive remediation at scale.
- Support endpoint provisioning approaches, including legacy SCCM imaging, with a focus on modern provisioning through Autopilot.
- Troubleshoot hardware/software issues that require engineering‑level analysis beyond standard service desk playbooks.
- Participate in systems architecture discussions; propose and implement new endpoint solutions leveraging modern technologies.
- Build technical documentation, runbooks, and knowledge articles for support and operations teams.
- Identify opportunities for standardization, automation, self‑service, and cost optimization.
Skills and Minimum Experience Required
- 5+ years of experience in enterprise desktop engineering / endpoint management.
- Strong hands‑on experience with:
- Microsoft Intune (app deployment, policy configuration, compliance, reporting)
- Windows Autopilot (deployment profiles, enrollment strategies, provisioning)
- SCCM (application deployment, collections, task sequences, reporting)
- Patching through Intune (rings, feature updates, compliance reporting)
- Proven experience creating and managing automated software packages.
- Strong working knowledge of Windows (Windows 10/11) and MacOS, device configuration, and troubleshooting.
- Scripting/automation skills—PowerShell required; ability to build scalable remediation and deployment scripts.
- Practical understanding of software licensing, inventory/asset concepts, and compliance reporting.
- Experience with endpoint security controls (BitLocker, CIS Level 1, hardening baselines).
- Strong documentation and communication skills; able to translate technical designs into clear operational procedures.
- Ability to effectively collaborate within environments utilizing role‑based access controls, demonstrating productivity and accountability without requiring full administrative privileges to all systems.
- Ability to work effectively across teams and maintain positive, professional relationships in a team‑oriented environment.
The range for this position is $83,300 to $164,400. Placement within this range may vary, depending on the applicant’s experience and geographic location. Acuity offers generous benefits including health care, dental coverage, vision plans, 401K benefits, and commissions/incentive compensation depending on the role. For a list of our benefits, clickhere.
We value diversity and are an equal‑opportunity employer. All qualified applicants will be considered for employment without regard to race, color, age, gender, sexual orientation, gender identity and expression, ethnicity or national origin, disability, pregnancy, religion, covered veteran status, protected genetic information, or any other characteristic protected by law.