Senior Endpoint Engineer/Administrator, Systems Management

AmerisourceBergen Services Corporation

Pennsylvania

Hybrid

USD 110,000 - 140,000

Full time

39 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical, dental, and vision care
Adoption assistance
Paid parental leave
Training programs

Job summary

AmerisourceBergen Services Corporation seeks a Senior Endpoint Engineer/Administrator to design, deploy, and support endpoint management with MECM and Intune in a co‑managed environment. This role leads packaging, patching, automation, and incident resolution for a large distributed fleet.

Requires 8+ years IT experience, 5+ years in endpoint engineering, and deep MECM/Intune expertise. Collaboration with Security, Networking, and Support is essential to maintain security, compliance, and

Qualifications

  • Bachelor's degree in a technology field or equivalent experience.
  • 8+ years IT experience with 5+ years in endpoint engineering.
  • Deep MECM/SCCM and Intune expertise in co-management.
  • Experience remediating OS and application vulnerabilities (CVE triage).
  • PowerShell scripting with Graph API/Intune experience.
  • Troubleshooting at scale in distributed endpoint environments.
  • Experience packaging Win32 apps (.MSI/.MST) and PSAppDeployToolkit.
  • Experience with third-party patching (Patch My PC, Ivanti).

Responsibilities

  • Package, test, and deploy Windows and third‑party apps via MECM/Intune.
  • Configure co-management settings and deployment groups across the enterprise.
  • Develop PowerShell scripts for automation, remediation, and reporting.
  • Remediate security vulnerabilities and report CVE status with timelines.
  • Manage third‑party patching lifecycle to minimize exposure windows.
  • Apply AD/GP tooling knowledge for endpoint management and distribution.
  • Collaborate with Architecture, Networking, Security, Support teams.
  • Triage escalations from Endpoint Support and Security.

Skills

PowerShell scripting
MECM/SCCM
Intune co-management
Automation
OS deployment
Patch management
Active Directory
Networking basics
Troubleshooting
Git/Azure DevOps

Education

Bachelor's degree in Computer Science / MIS

Tools

PSAppDeployToolkit
Advanced Installer
Orca
Patch My PC
Ivanti

Job description

Job Details

Senior Endpoint Engineer/Administrator (Level 3) responsible for the design, deployment, and advanced support of endpoint management solutions across a large, distributed physical and virtual device estate using Microsoft Endpoint Configuration Manager (MECM) and Microsoft Intune in a co‑managed environment.

Owns application packaging, third‑party patch management, security vulnerability remediation, advanced PowerShell automation, and at‑scale incident troubleshooting, partnering closely with Information Security, Networking, and Support teams to keep the endpoint fleet secure, compliant, and reliable.

Full time

Key Responsibilities
  • Package, test, and deploy Windows and third‑party applications through MECM and Intune (Win32 apps), using PSADT and other silent‑install packages with reliable detection logic and dependency handling.
  • MECM/Intune co‑management experience: client settings, boundaries and boundary groups, deployment collections, Autopilot profiles, compliance policies, and configuration baselines across the enterprise endpoint estate.
  • Design, write, and maintain advanced PowerShell scripts for automation, remediation, and reporting, including Intune and MECM.
  • Identify, prioritize, and remediate security vulnerabilities across the endpoint fleet in partnership with Information Security – driving CVE/patch‑compliance reporting and mitigation timelines for OS and third‑party applications.
  • Third‑party application patching lifecycle – identifying, packaging, testing, and deploying updates (e.g., via Patch My PC, MECM, application/patch deployment) to minimize vulnerability exposure windows.
  • Networking knowledge (DNS, DHCP, IP addressing/subnetting, VLANs, boundary/content distribution) to resolve connectivity issues affecting client communication, application delivery, and patch distribution.
  • Leverage AI‑assisted tools (Claude, Copilot and other scripting assistants) and automation/orchestration to streamline packaging, remediation, and reporting – tracking work in JIRA and version‑controlling scripts/configs in GitHub.
  • Partner and collaborate with multiple technical teams (Architecture, Networking, Information Security, Support, etc.) to develop and support endpoint solutions.
  • Triage and resolve escalations from Endpoint Support and Security, acting as a technical escalation point for Level 1/2 teams.

This job profile description is a standardized, non‑contractual reference description and global reference tool provided for organizational consistency and talent architecture purposes across Cencora. It does not alter actual job duties, responsibilities, reporting lines, working conditions, grading, compensation, or other essential terms and conditions of employment. Actual duties and responsibilities may vary based on business needs, local requirements, and operational practices. Where a team member's role is governed by an employment agreement, local terms and conditions, prior job description or collective bargaining agreement, those documents shall prevail in case of any inconsistency. Mandatory local laws shall also prevail.

Experience and Educational Requirements
  • Bachelor's degree, preferably in Computer Science, Management Information Systems, or a related technology field (equivalent experience considered).
  • At least 8 years of IT experience, including 5+ years in infrastructure/endpoint engineering.
  • Advanced, hands‑on expertise with Microsoft Endpoint Configuration Manager (MECM/SCCM) and Microsoft Intune, including co‑management, Autopilot, compliance policies, and Win32 application deployment.
  • Demonstrated experience remediating security vulnerabilities – identifying, prioritizing, and patching OS and third‑party application vulnerabilities, including CVE triage and patch‑compliance reporting (Microsoft Defender/vulnerability management tooling).
  • Advanced PowerShell scripting ability (functions, modules, error handling, remoting, Graph API/Intune scripting), plus familiarity with VBScript for legacy support.
  • Proven ability to troubleshoot complex incidents at scale across large, distributed endpoint environments, with strong root‑cause analysis skills.
  • Strong application packaging experience (.MSI/.MST, Win32; App‑V/MSIX familiarity a plus) using PSAppDeployToolkit, Advanced Installer, and Orca.
  • Experience managing third‑party application patching programs (e.g., Patch My PC, Ivanti, or similar).
  • Solid understanding of Active Directory and Group Policy for managing user/computer objects, including GPO troubleshooting (gpresult, RSoP).
  • Working knowledge of wired/wireless networking fundamentals: DHCP, DNS, IP addressing, subnetting, and VLANs, and how they affect client‑server communication and content distribution.
  • Familiarity with Windows 11 Enterprise features, settings, and deployment; BIOS/UEFI configuration; Bitlocker and Microsoft Defender.
  • Experience with virtualization technologies (Citrix, VMware) and thin/zero‑client delivery is a plus.
  • Solid track record of delivering thoughtful, effective, and timely solutions to complex business problems that enhance the end‑user experience.
Additional / Preferred Skills
  • AI‑assisted automation and Copilot‑style tools (Microsoft Copilot, GitHub Copilot, Claude) to speed up scripting, triage, and remediation.
  • Service‑Now for Incident, request logging.
  • GitHub (or Azure DevOps) for version‑controlled scripts and Intune/MECM configuration‑as‑code, including basic CI/CD pipelines.
  • JIRA (or similar) for ticketing, sprint/backlog tracking, and change management.
  • Working familiarity with Azure AD/Microsoft Entra ID, conditional access, and Windows Autopatch.
  • Experience mentoring Level 1/2 engineers and producing clear runbooks/knowledge‑base documentation.
  • ITIL foundations or equivalent incident/problem/change management experience.
What Cencora offers

We provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members’ ability to live with purpose every day.

  • medical, dental, and vision care
  • backup dependent care
  • adoption assistance
  • infertility coverage
  • family building support
  • behavioral health solutions
  • paid parental leave
  • paid caregiver leave
  • training programs
  • professional development resources
  • mentorship programs
  • employee resource groups
  • volunteer activities
  • much more
Full time Equal Employment Opportunity

Cencora is committed to providing equal employment opportunity without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, age, disability, veteran status or membership in any other class protected by federal, state or local law. The company’s continued success depends on the full and effective utilization of qualified individuals. Therefore, harassment is prohibited and all matters related to recruiting, training, compensation, benefits, promotions and transfers comply with equal opportunity principles and are non‑discriminatory. Cencora is committed to providing reasonable accommodations to individuals with disabilities during the employment process which are consistent with legal requirements. If you wish to request an accommodation while seeking employment, please call 888.692.2272 or email hrsc@cencora.com. We will make accommodation determinations on a request‑by‑request basis. Messages and emails regarding anything other than accommodations requests will not be returned.

Affiliated Companies

Affiliated Companies: AmerisourceBergen Services Corporation

Cencora is a leading global pharmaceutical solutions company that is committed to improving the lives of people and animals everywhere. We connect manufacturers, providers, and patients to ensure that anyone can get the therapies they need, where and when they need them. We’re a purpose‑driven organization, where all of our team members around the world are united in our responsibility to create healthier futures. We work together every day to help our partners bring their innovations to patients worldwide, creating unparalleled access and impact at the center of health.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Engineer III, Endpoint Engineering
Engineer III, Endpoint Engineering

AmerisourceBergen Services Corporation • Pennsylvania

Hybrid
USD 140,000 - 180,000
Principal Engineer, Security Engineering
Principal Engineer, Security Engineering

AmerisourceBergen Services Corporation • Conshohocken

On-site
USD 140,000 - 190,000
Medical, dental, and vision care
Paid parental leave
Training programs
+2
Senior Administrator, Systems Management
Senior Administrator, Systems Management

Cencora • Conshohocken

On-site
USD 120,000 - 160,000
Senior Endpoint Engineer | MECM/Intune Automation Champion
Senior Endpoint Engineer | MECM/Intune Automation Champion

Cencora • Conshohocken

On-site
USD 120,000 - 160,000
Specialist I, End-User Support
Specialist I, End-User Support

AmerisourceBergen Drug Corporation • Corona (CA)

On-site
USD 52,000 - 82,000
Lead Engineer, IAM Platform Engineering
Lead Engineer, IAM Platform Engineering

AmerisourceBergen Services Corporation • Conshohocken

On-site
USD 140,000 - 210,000
Inclusive culture
Comprehensive benefits package
Mentorship programs
+1
Automation Support Specialist II-2
Automation Support Specialist II-2

AmerisourceBergen Drug Corporation • Whitestown (IN), Indianapolis (IN)

On-site
USD 75,761,000 - 127,282,000
Senior Administrator, Systems Management
Senior Administrator, Systems Management

Cencora • Harrisburg

On-site
USD 120,000 - 160,000
Senior Engineer, IAM Platform Engineering
Senior Engineer, IAM Platform Engineering

MWI Buying Group • Conshohocken, Northern (KY)

On-site
USD 140,000 - 190,000
Medical
Dental
Vision care
+12
Senior Manager, Identity and Access Management
Senior Manager, Identity and Access Management

AmerisourceBergen Services Corporation • Conshohocken

On-site
USD 120,000 - 180,000
Medical benefits
Dental & Vision
Parental leave
+2