Senior Endpoint Engineer

Dunhill Professional Search & Government Solutions

Washington (District of Columbia)

Hybrid

USD 150,000 - 175,000

Full time

2 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Dunhill Professional Search & Government Solutions seeks a Senior Endpoint Engineer to define and drive modernization of federal agency device provisioning and management. You will guide architecture, policy, and tool selections while remaining hands-on with ConfigMgr, Intune, Autopilot and related tooling.

You will own multi-year roadmaps, coordinate with cross-functional teams, and serve as escalation point for complex endpoint issues, all in a hybrid Washington, DC setting with security-first

Qualifications

  • Bachelor's degree or 12+ years of relevant experience in lieu of a degree.
  • 8+ years of enterprise Windows endpoint management experience, including 2+ years leading the design of significant endpoint initiatives.
  • Hands-on experience with both ConfigMgr and Microsoft Intune, including co-management, having moved at least one workload or device population from ConfigMgr to Intune.
  • Has designed and deployed Windows Autopilot for production users in at least one deployment mode.
  • PowerShell scripting for automation; able to read and adapt scripts that use the Microsoft Graph API.
  • Clear writing of design documents, diagrams and SOPs that other engineers can carry out.
  • Experience with incidents, problems and change requests in ServiceNow or a comparable ITSM tool.
  • CompTIA Security+ held at start or earned within 90 days.
  • On site in Washington, DC at least 2 days per week.
  • US Citizenship (no dual citizenship) and the ability to pass a federal background investigation in order to be granted access to sensitive information.

Responsibilities

  • Define and maintain the endpoint target-state architecture across identity, provisioning, configuration, application delivery, update management, security and support tooling.
  • Own the multi-year endpoint modernization roadmap, with phases, dependencies, entry and exit criteria, and risk for each phase.
  • Produce architecture artifacts: current- and target-state diagrams, design documents, architecture decision records (ADRs) and reference configurations.
  • Evaluate new Microsoft and vendor capabilities, run proofs of concept, and recommend adoption, deferral or retirement with cost, risk and effort analysis.
  • Define the user persona model and set endpoint engineering standards for naming, policy design, assignment and filtering, app packaging and baseline management.
  • Advise program leadership on endpoint risk, technical debt, licensing and investment priorities.
  • Lead the transition from ConfigMgr to Intune, moving co-management workloads in planned waves with pilot groups and defined success criteria.
  • Drive the move from hybrid join toward Entra ID join and zero-touch provisioning with Windows Autopilot.
  • Modernize update management with Windows Update for Business and Windows Autopatch, including ring design and driver and firmware update policy.
  • Move application delivery to Intune Win32 apps and catalog‑based app management, and retire legacy packages.
  • Replace on‑premises dependencies with cloud services where approved, such as Windows LAPS, cloud‑based certificate delivery and Intune Remediations.
  • Plan the reduction and eventual decommissioning of ConfigMgr infrastructure.
  • Coordinate cutovers with imaging, identity, network, security and service desk teams, with tested rollback plans for each wave.
  • Act as senior escalation point for ConfigMgr, Intune, co‑management, Autopilot and Windows 11 client issues.

Skills

Windows endpoint management
ConfigMgr
Microsoft Intune
PowerShell
Microsoft Graph API
Co-management
Windows Autopilot
Windows Autopatch
Azure DevOps Boards
ServiceNow
Security+

Education

Bachelor's degree in Information Technology or Computer Science or related field

Tools

ConfigMgr
Intune
PowerShell
Microsoft Graph API
Azure DevOps Boards
ServiceNow
BeyondTrust
Dell enterprise tooling

Job description

Hybrid in Washington, DC — on site at least 2 days per week

The Senior Endpoint Engineer defines the target state for how a federal agency's devices are provisioned, managed, secured and supported, and leads the engineering work to get there. The central mission is modernization: moving the fleet from a ConfigMgr-centric, on-premises model to a cloud-native model built on Microsoft Intune, Entra ID, Windows Autopilot and Windows Autopatch, aligned to federal Zero Trust requirements. You own the roadmap, the design decisions and the reference standards for that transition while staying hands‑on with ConfigMgr, Intune, Dell enterprise tooling and BeyondTrust. This is an individual-contributor role with no supervisory duties; it leads through technical direction. Work is tracked in ServiceNow and Azure DevOps (ADO) Boards.

Endpoint Architecture and Strategy:
  • Define and maintain the endpoint target-state architecture across identity, provisioning, configuration, application delivery, update management, security and support tooling.
  • Own the multi-year endpoint modernization roadmap, with phases, dependencies, entry and exit criteria, and risk for each phase.
  • Produce architecture artifacts: current- and target-state diagrams, design documents, architecture decision records (ADRs) and reference configurations.
  • Evaluate new Microsoft and vendor capabilities, run proofs of concept, and recommend adoption, deferral or retirement with cost, risk and effort analysis.
  • Define the user persona model and set endpoint engineering standards for naming, policy design, assignment and filtering, app packaging and baseline management.
  • Advise program leadership on endpoint risk, technical debt, licensing and investment priorities.
Modernization Delivery:
  • Lead the transition from ConfigMgr to Intune, moving co-management workloads in planned waves with pilot groups and defined success criteria.
  • Drive the move from hybrid join toward Entra ID join and zero-touch provisioning with Windows Autopilot.
  • Modernize update management with Windows Update for Business and Windows Autopatch, including ring design and driver and firmware update policy.
  • Move application delivery to Intune Win32 apps and catalog‑based app management, and retire legacy packages.
  • Replace on‑premises dependencies with cloud services where approved, such as Windows LAPS, cloud‑based certificate delivery and Intune Remediations.
  • Plan the reduction and eventual decommissioning of ConfigMgr infrastructure.
  • Coordinate cutovers with imaging, identity, network, security and service desk teams, with tested rollback plans for each wave.
  • Act as senior escalation point for ConfigMgr, Intune, co‑management, Autopilot and Windows 11 client issues.
Security, Automation and Leadership:
  • Design endpoint security configuration to meet NIST SP 800-53 controls, Microsoft security baselines and applicable DISA STIG or CIS benchmarks.
  • Define device compliance signals for Entra Conditional Access in partnership with the identity and security teams.
  • Build automation in PowerShell and the Microsoft Graph API for provisioning, configuration, compliance checks and reporting.
  • Develop KQL and SQL queries and dashboards (SSRS, Power BI, or Intune and Endpoint Analytics reports), and report modernization metrics.
  • Author and present Change Advisory Board (CAB) requests for architecture‑level and high‑risk changes, and review other engineers' changes.
  • Plan roadmap work in ADO Boards linked to ServiceNow records; write SOPs, runbooks and knowledge articles.
  • Mentor engineers through design reviews, pairing and walkthroughs.
Requirements:
  • Bachelor's degree in Information Technology, Computer Science or a related field, or 12+ years of relevant experience in lieu of a degree.
  • 8+ years of enterprise Windows endpoint management experience, including 2+ years leading the design of significant endpoint initiatives.
  • Hands‑on experience with both ConfigMgr and Microsoft Intune, including co‑management, having moved at least one workload or device population from ConfigMgr to Intune.
  • Has designed and deployed Windows Autopilot for production users in at least one deployment mode.
  • PowerShell scripting for automation; able to read and adapt scripts that use the Microsoft Graph API.
  • Clear writing of design documents, diagrams and SOPs that other engineers can carry out.
  • Experience with incidents, problems and change requests in ServiceNow or a comparable ITSM tool.
  • CompTIA Security+ held at start or earned within 90 days.
  • On site in Washington, DC at least 2 days per week.
  • US Citizenship (no dual citizenship) and the ability to pass a federal background investigation in order to be granted access to sensitive information.
Preferred:
  • Windows Update for Business or Windows Autopatch, Intune Remediations and Endpoint Analytics.
  • Working knowledge of Entra ID, Conditional Access and device compliance in a Zero Trust model.
  • SQL and KQL for querying ConfigMgr, Intune and endpoint telemetry data.
  • Endpoint work in a federal environment under FISMA, NIST SP 800-53 and CISA directives, including Microsoft government cloud.
  • Dell enterprise tooling (Dell Command | Update, Dell Command | Configure, BIOS and Secure Boot management).
  • BeyondTrust or a comparable privileged access or remote support platform; Microsoft Defender for Endpoint, Windows LAPS or Azure DevOps Boards.
  • Certifications such as Microsoft MD-102, MS-102, SC-300 or ITIL 4 Foundation.

Compensation: $150,000 - $175,000 per year

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Endpoint Engineer / DHS Desktop Support Services
Endpoint Engineer / DHS Desktop Support Services

Jobgether SRL • Washington

Hybrid
USD 135,000 - 150,000
Salary range $135,000--$150,000 per yr
Endpoint Engineer / DHS Desktop Support Services
Endpoint Engineer / DHS Desktop Support Services

Jobgether SRL • United States

Hybrid
USD 135,000 - 150,000
Salary: $135,000–$150,000 per year
Primarily remote work
Hybrid meetings in DMV area
Sr. Endpoint Management Engineer
Sr. Endpoint Management Engineer

Cypress HCM • Denver (CO)

Hybrid
USD 76,000 - 85,000
Modern Endpoint Engineer - IT
Modern Endpoint Engineer - IT

Frank, Rimerman + Co. LLP • San Jose (CA)

On-site
USD 115,000 - 130,000
Senior Endpoint Engineer (Applications)
Senior Endpoint Engineer (Applications)

The AES Corporation • Indianapolis (IN)

On-site
USD 80,000 - 120,000
Sr. Endpoint Engineer
Sr. Endpoint Engineer

MSM Technology • Arlington (VA)

On-site
USD 100,000 - 130,000
Endpoint Engineer
Endpoint Engineer

nTech Workforce • Maryland

Remote
USD 120,000 - 160,000
Sr. Endpoint Engineer
Sr. Endpoint Engineer

MSM Tech Inc. • Arlington (VA)

On-site
USD 120,000 - 160,000
Senior Endpoint Engineer
Senior Endpoint Engineer

asmexternalcareersite • Washington

On-site
USD 140,000 - 190,000
Senior Endpoint Engineer
Senior Endpoint Engineer

ZENITH INFOTEK LLC • North Carolina

Hybrid
USD 120,000 - 170,000