Sr. Endpoint Engineer

HKS, Inc.

Dallas (TX)

On-site

USD 120,000 - 160,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

HKS, Inc. is seeking an experienced Patch and Endpoint Management Lead to own the monthly patch cycle for Windows, macOS, Windows Server, and firmware across ~2,500 devices in 28 locations, spanning Azure and on‑prem workloads.

You will design deployment rings, coordinate testing, apply CVE remediation, and ensure compliance across the enterprise. You will manage Intune, SCCM/MECM co‑management, Autopilot, Azure Arc, and device configurations, partner with security, and implement automation

Qualifications

  • Bachelor's degree in a computer science or related field or equivalent work experience

Responsibilities

  • Owns the monthly patch cycle for Windows and macOS endpoints and Windows Server
  • Designs and maintains deployment rings (pilot, early adopter, broad) with test groups
  • Patches third‑party applications and manages firmware, drivers, and BIOS updates
  • Meets remediation SLAs for CVEs and executes emergency patching when needed
  • Partners with the security team on findings and remediation planning
  • Maintains QA methodology for packages, patches, and configuration changes
  • Administers Intune across Windows, macOS, iOS/iPadOS, and Android
  • Onboards and manages servers in Azure Arc to extend update and configuration management
  • Maintains SCCM/Intune co‑management and drives cloud native adoption
  • Writes and maintains policies and standards for patching and device configuration
  • Automates operational work using PowerShell, Graph, and bash/zsh
  • Builds patch compliance and device health dashboards for IT leadership
  • Supports change requests and communicates maintenance windows and rollback plans
  • Assists application owners with packaging, deployment, and patching
  • Supports service desk on escalated endpoint issues and after‑hours incidents
  • Ensures compliance with security, regulatory and regional requirements
  • Keeps up with industry trends to improve operations

Skills

Intune
PowerShell
Microsoft Graph
Azure Arc
Autopilot
Azure AD
SCCM/MECM
Patch management

Education

B.A./B.S. in Computer Science or related field

Tools

Intune
Autopilot
Azure Arc
Azure AD

Job description

Overview

Responsible for the enterprise patch and update management platform and the endpoint services supporting approximately 2,500 devices across 28 locations, spanning Azure and on-premises workloads. Leads the monthly patch cycle for Windows, macOS, Windows Server, and firmware, including deployment ring design, test coordination, and critical CVE remediation. Manages the device, application, policy, and security configurations to remain compliant. Partners across IT, leveraging Intune and other endpoint management tools to deliver endpoint solutions to the firm.

Overview

Responsible for the enterprise patch and update management platform and the endpoint services supporting approximately 2,500 devices across 28 locations, spanning Azure and on-premises workloads. Leads the monthly patch cycle for Windows, macOS, Windows Server, and firmware, including deployment ring design, test coordination, and critical CVE remediation. Manages the device, application, policy, and security configurations to remain compliant. Partners across IT, leveraging Intune and other endpoint management tools to deliver endpoint solutions to the firm.

Responsibilities
  • Owns the monthly patch cycle for Windows and macOS endpoints and Windows Server
  • Designs and maintains deployment rings (pilot, early adopter, broad), coordinating with test groups to validate patch levels for monthly publication
  • Patches third-party applications (browsers, runtimes, 7zip, etc.) through Intune or a dedicated patch management tool
  • Manages firmware, driver, and BIOS updates for laptops and server hardware
  • Meets remediation SLAs for critical and high‑severity CVEs, executes out‑of‑band emergency patching for actively exploited vulnerabilities, and reports on compliance, exceptions, and drift
  • Partners with the security team on scan findings, false positives, risk acceptance, and remediation planning
  • Packages, deploys, updates, and retires applications (Win32, MSIX, Store, macOS pkg/dmg) and drivers, including detection rules, dependencies, and supersedence
  • Maintains a documented QA methodology for packages, patches, and configuration changes — test plans, acceptance criteria, and documented results before broad release
  • Administers Intune across Windows, macOS, iOS/iPadOS, and Android, including enrollment (Autopilot, Apple Business Manager/ADE, Android Enterprise), configuration profiles, compliance policies, and Conditional Access inputs
  • Onboards and manages servers in Azure Arc to extend update and configuration management on‑premises and cloud servers
  • Maintains SCCM/Intune co‑management and drives cloud native adoption
  • Maintains device and security baselines and hardening configurations
  • Helps design, build, and document the patch and device management system end to end, including architecture, runbooks, and standard operating procedures
  • Writes and maintains policies and standards for patching, update rings, device configuration, and application lifecycle
  • Evaluates, pilots, and recommends tooling to close gaps in the current platform
  • Automates operational work using PowerShell, Microsoft Graph, and bash/zsh
  • Builds patch compliance and device health dashboards for IT leadership
  • Submits and drives change requests for all production work, represents those changes at change advisory board review, and communicates maintenance windows, impact, and rollback plans
  • Assists application owners and other IT teams with packaging, deployment, and patching
  • Supports the service desk on escalated endpoint issues, patch‑related breakage, and rollbacks
  • Participates in scheduled after‑hours maintenance and supports high‑severity incidents after‑hours
  • Ensures all technology and departmental activities comply with company, security, regulatory and regional requirements
  • Stays current with industry trends, technological advancements, and leverages these capabilities to improve and streamline the operation
Qualifications
  • B.A./B.S. degree in Computer Science or related field, or equivalent work experience
  • Typically, with 6+ years of experience, with 4+ years of experience administering Microsoft Intune in a production enterprise environment
  • Advanced competency of Microsoft Endpoint Management (MEM) technologies, including Intune, Autopilot, Azure ARC, AZURE AD
  • Advanced competency of CVE/CVSS scoring, vulnerability scanner output, and remediation SLA reporting
  • Working knowledge of SCCM/MECM, including co‑management with Intune
  • Experience with managing macOS in an enterprise environment, plus iOS and Android mobile device management
  • Experience with third‑party application patching using Intune integrations or a dedicated patch management tool
  • Experience with application packaging and deployment (Win32, MSIX, macOS pkg/dmg) and with a documented QA and testing methodology
  • Experience with scripting for automation: PowerShell required; Microsoft Graph and bash/zsh for macOS strongly preferred
  • Experience with disciplined change management practice (ITIL‑aligned) and a genuine willingness to write and maintain documentation and policy
  • Experience in MS Office Suite
  • Strong communication and interpersonal skills, with the ability to interact with all levels of staff
  • Strong work ethic and eagerness to produce high quality, accurate results
  • Ability to hold sensitive information with a high level of confidentiality and integrity
  • Ability to present ideas in a clear, concise and professional manner both verbally and in writing
  • Ability to proactively solve problems and apply innovative solutions
  • Ability to collaborate in a team environment and ability to work independently
  • Ability to prioritize competing demands
  • Ability to effectively meet deadlines at expected quality
  • Travel may be required

If you currently work for HKS, please submit your application via the Internal Careers Portal.

HKS is an EEO/AA Employer: M/F/Disabled/Veteran

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Endpoint Engineer
Sr. Endpoint Engineer

HKS, Inc • Dallas (TX)

On-site
USD 120,000 - 150,000
Sr. Endpoint Engineer
Sr. Endpoint Engineer

HKS INC • Dallas (TX)

On-site
USD 110,000 - 140,000
Senior Endpoint & Patch Management Engineer
Senior Endpoint & Patch Management Engineer

HKS, Inc. • Dallas (TX)

On-site
USD 120,000 - 160,000
Systems Administrator-Endpoint Operations & Security
Systems Administrator-Endpoint Operations & Security

Combined Metals Company LLC • Hampshire Township (IL), Northern (KY)

Hybrid
USD 90,000 - 130,000
Systems Engineer II - Endpoint
Systems Engineer II - Endpoint

SCCU Simple • Melbourne (FL)

On-site
USD 113,000 - 121,000
Health & Wellness: Medical, dental, &
Financial Perks: 401(k) match, HSA
Education Support: Tuition & fraud
+1
Systems Administrator-Endpoint Operations & Security
Systems Administrator-Endpoint Operations & Security

Combined Metals Company, LLC • Hampshire Township (IL)

Hybrid
USD 90,000 - 120,000
Senior Endpoint Engineer
Senior Endpoint Engineer

Jobtailor • Neptune Township (NJ)

On-site
USD 140,000 - 190,000
Senior Endpoint Engineer
Senior Endpoint Engineer

Kwik Trip, Inc. • La Crosse (WI)

On-site
USD 90,000 - 120,000
Manager, Endpoint Security & M365 Engineering
Manager, Endpoint Security & M365 Engineering

Columbia University Information Technology • New York (NY)

On-site
USD 120,000 - 190,000
Ralph Lauren Sr Windows Engineer
Ralph Lauren Sr Windows Engineer

BoF Careers • Nutley (NJ)

On-site
USD 120,000 - 180,000