Systems Engineer II - Endpoint

SCCU Simple

Melbourne (FL)

On-site

USD 113,900 - 120,628

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health & Wellness: Medical, dental, &
Financial Perks: 401(k) match, HSA
Education Support: Tuition & fraud
Generous Time Off: PTO & holidays

Job summary

SCCU Simple is seeking a Systems Engineer II to design, implement, and secure the enterprise workstation and mobile endpoint estate across Windows, macOS, and iOS managed via Intune. The role covers OS patching, deployment, policy administration, and end‑to‑end lifecycle management in a regulated financial services environment.

The position emphasizes strong Tanium administration, CSP/APP packaging, and automation with PowerShell, Python, and Bash, with a contract-to-hire term and a schedule of

Qualifications

  • 5–8 years of enterprise endpoint engineering experience, including Tanium, Intune, GPO, and third‑party patching.
  • Strong scripting and software packaging skills (PowerShell, Python, Bash).
  • 4-year degree in Information Systems, Computer Science, Computer Engineering, or related field preferred.

Responsibilities

  • Administer Tanium as the primary endpoint management and patching platform.
  • Design and improve enterprise patching strategies for Windows and macOS.
  • Coordinate patch testing, pilot rings, phased deployment, and rollback procedures.
  • Package and deploy Windows, macOS, and iOS applications using Tanium Deploy and Intune.
  • Manage Autopilot, Apple Business Manager/Intune, and ADE enrollment workflows.
  • Own GPO and Intune policy lifecycles across Windows/macOS/iOS with CIS‑based hardening.
  • Develop automation for provisioning, deployment, and health checks with PowerShell, Python, and Bash.
  • Collaborate with Cybersecurity to prioritize vulnerabilities and track remediation.
  • Create and maintain runbooks, standards, and change records.

Skills

Tanium
Intune management
PowerShell
Python
Bash
GPO administration

Education

4-year degree

Tools

SCCM/MECM
Kaseya VSA

Job description

Location: Baytree Headquarters
8045 North Wickham Road
Melbourne, FL 32940, USA

Job Title: Systems Engineer II

Contract Term: 6 month contract-to-hire.

Role Overview: As a Systems Engineer II you will be responsible for designing, implementing, maintaining, and securing the enterprise workstation and mobile endpoint estate, including Windows, macOS, and iOS devices managed through Microsoft Intune. This role owns operating system and third‑party application patching, OS lifecycle management, software packaging and deployment, Group Policy (GPO) and Intune policy administration, configuration baselines, and endpoint security tooling across on‑premises, cloud‑managed, and remote endpoints in a regulated financial services environment.

Responsibilities
  • Administer, maintain, and optimize Tanium as the primary endpoint management and patching platform, including module configuration (Patch, Deploy, Comply, Asset, Interact), sensor/package authoring, content distribution, and operational reporting.
  • Design, execute, and continuously improve enterprise patching strategies for Windows and macOS operating systems and third‑party applications, including monthly Patch Tuesday cycles, out‑of‑band releases, zero‑day remediation, and Windows feature update servicing.
  • Coordinate patch testing, pilot rings, phased production deployment, validation, and rollback procedures across on‑site and remote/VPN workstations; monitor patch compliance dashboards and remediate failures or non‑reporting devices promptly.
  • Package, test, and deploy enterprise applications for Windows (MSI, EXE, MSIX, Win32), macOS (PKG, DMG), and iOS (App Store and line‑of‑business apps) using Tanium Deploy and Microsoft Intune (with SCCM/MECM where applicable); maintain a curated software catalog and self‑service application access.
  • Manage endpoint provisioning and enrollment workflows for Windows (Autopilot), macOS (Automated Device Enrollment via Apple Business Manager / Intune), and iOS (ADE via ABM / Intune), including driver libraries, in‑place feature upgrades, and zero‑touch provisioning experiences.
  • Own the full lifecycle of Group Policy Objects (GPOs) and Microsoft Intune policies for endpoints across Windows, macOS, and iOS. This includes configuration profiles, compliance policies, security baselines, endpoint protection policies, app configuration and protection policies, update rings, and conditional access. Design policies, test in pilot rings, deploy to production, troubleshoot, document, and continuously tune them to align with CIS‑based hardening standards and business requirements.
  • Develop and maintain automation for endpoint provisioning, software deployment, patch orchestration, health checks, and reporting using Tanium sensors/packages, PowerShell, Python, and Bash/shell scripting for macOS.
  • Manage workstation lifecycle activities including provisioning, refresh, decommissioning, asset reconciliation, and timely retirement of unsupported operating systems and applications.
  • Partner with the Cybersecurity team to analyze vulnerability scan results (e.g., Qualys, Tenable, Rapid7), prioritize remediation based on risk and exploitability, and track remediation to closure within defined SLAs.
  • Provide Tier 3 escalation support for complex endpoint, software deployment, OSD, patch compliance, and client health issues; perform root cause analysis and drive permanent remediation.
  • Participate in platform upgrades and migrations (e.g., Tanium module rollouts, Windows 10 to 11, macOS major version transitions, Intune co‑management and cloud‑native moves) while following established operational, risk, and change control processes.
  • Create and maintain technical documentation, runbooks, standards, procedures, and change records to support operational consistency, audit readiness, and knowledge transfer to peers and the service desk.
  • Collaborate with cybersecurity, network, identity, cloud, and application teams to support secure, resilient, and high‑performing endpoint services; other duties as assigned.

Compensation: $113,900.00 - $120,628.00

Benefits
  • Health & Wellness: Medical, dental, and vision insurance, plus an Employee Assistance Program.
  • Financial Perks: 401(k) match (5%), HSA match, and SCCU‑paid insurance (short/long‑term disability, life insurance).
  • Education Support: Tuition reimbursement after one year of service.
  • Generous Time Off: 20+ days of PTO, birthday PTO, and 11 federal holidays.
  • Exclusive Discounts: Lower rates on loans, credit cards, and no‑fee SCCU accounts.
Work Schedule
  • Monday – Friday: 8:00 a.m. - 5:00 p.m.
  • This role requires flexibility for after hours and weekend work, as needed, to perform changes and maintenance without impacting business operations.
Qualifications

5 to 8 years of progressively responsible endpoint engineering experience in enterprise environments, including strong hands‑on administration of Tanium for endpoint management and patching, Microsoft Intune for Windows/macOS/iOS, Group Policy (GPO) and Intune policy administration and deployment, third‑party application patching, software packaging, scripting (PowerShell), and Tier 3 troubleshooting. Experience with SCCM/MECM, Kaseya VSA, or similar platforms is a plus. A 4‑year degree in Information Systems, Computer Science, Computer Engineering, or a related field is preferred. Equivalent combinations of education, certifications, and directly related enterprise endpoint engineering experience will also be considered. Experience in regulated industries such as financial services, healthcare, or government is strongly preferred.

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Endpoint Systems Engineer
Endpoint Systems Engineer

System One • Palm Shores (FL)

Hybrid
USD 110,000 - 120,000
Health benefits
401(k) plan
Equal opportunity employer
Tanium Security Engineer
Tanium Security Engineer

Compunnel, Inc. • Charlotte (NC)

On-site
USD 100,000 - 120,000
Security Endpoint Engineer/Admin
Security Endpoint Engineer/Admin

AHU Technologies Inc • Washington

On-site
USD 85,000 - 110,000
Sr IT Engineer- Tanium Administrator
Sr IT Engineer- Tanium Administrator

Honeywell Aerospace • Phoenix (AZ)

On-site
USD 90,000 - 120,000
Medical, Vision, Dental benefits
Paid vacation
401(k) plan / retirement benefits
+2
Senior Endpoint Client Engineer
Senior Endpoint Client Engineer

SynapOne • Washington

On-site
USD 120,000 - 150,000
Systems Engineer II - Endpoint
Systems Engineer II - Endpoint

Space Coast Credit Union • Melbourne (FL)

On-site
USD 114,000 - 121,000
Health & Wellness
Financial Perks
Education Support
+2
IT Services Supervisor – Endpoint Management
IT Services Supervisor – Endpoint Management

WithumSmith+Brown PC • Buffalo (NY)

On-site
USD 120,000 - 160,000
Senior Systems Engineer: Endpoint & Patch Management
Senior Systems Engineer: Endpoint & Patch Management

SCCU Simple • Melbourne (FL)

On-site
USD 113,000 - 121,000
Health & Wellness: Medical, dental, &
Financial Perks: 401(k) match, HSA
Education Support: Tuition & fraud
+1
Senior Endpoint Engineer: Tanium & Intune Expert
Senior Endpoint Engineer: Tanium & Intune Expert

System One • Palm Shores (FL)

Hybrid
USD 110,000 - 120,000
Health benefits
401(k) plan
Equal opportunity employer
Systems Engineer II - Endpoint
Systems Engineer II - Endpoint

SCCU Simple • Town of Florida (NY)

On-site
USD 113,000 - 121,000
Health & Wellness
401(k) match
Tuition reimbursement
+2