Windows Device Engineering Lead

Takeda

Exton (PA)

On-site

USD 140,000 - 190,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Takeda is seeking an experienced Windows Device Engineering Lead to own the global endpoint management strategy for ~50,000 Windows devices. Lead, mentor, and direct an offshore delivery team while coordinating with security and business stakeholders to ensure compliant, resilient endpoint operations.

The role requires hands-on mastery of Intune, SCCM/MEMCM, and PowerShell, plus strong leadership skills to guide provisioning, patching, and security hardening across time zones.

Qualifications

  • 7+ years of hands-on experience in Windows endpoint management at enterprise scale (10,000+ endpoints).
  • Demonstrated experience managing a globally distributed Windows device fleet across geographies.
  • 3+ years of experience directly leading or coordinating technical teams, including offshore/nearshore resources.
  • Prior experience in a 24/7 global IT operations model preferred.

Responsibilities

  • Architect, maintain, and continuously improve the global Windows device management platform using Intune and SCCM/MEMCM.
  • Define and own configuration baselines, enrollment profiles, compliance policies, and conditional access rules.
  • Drive modernization toward cloud-native device management (Autopilot, Intune-only, co-management).
  • Oversee device lifecycle management including provisioning, imaging, refresh, and decommissioning.

Skills

Intune
SCCM / MEMCM
PowerShell
App Packaging
CIS Benchmarks
Defender for Endpoint

Job description

Job Description
Position Summary

We are seeking an experienced and technically deep Windows Device Engineering Lead to own and drive the global endpoint management strategy for approximately 50,000 Windows devices across our worldwide operations. This is a high-impact technical leadership role responsible for the full device lifecycle — from provisioning and configuration to monthly patching, security hardening, and decommission — while coordinating a distributed team of contractors across time zones. The ideal candidate combines hands‑on technical mastery in Microsoft Intune, SCCM/MEMCM, PowerShell scripting, and application packaging with the organizational skills to lead, mentor, and direct an offshore delivery team. You will serve as the primary liaison between endpoint engineering, security, and business stakeholders, ensuring our endpoint estate is compliant, resilient, and operationally excellent.

Key Responsibilities
Endpoint Management & Strategy
  • Architect, maintain, and continuously improve the global Windows device management platform using Microsoft Intune and SCCM/MEMCM (co-management and cloud-only environments).
  • Define and own configuration baselines, enrollment profiles, compliance policies, and conditional access rules across the ~50,000 endpoint estate.
  • Drive the organization’s modernization roadmap toward cloud-native device management (Autopilot, Intune-only, co-management).
  • Oversee device lifecycle management including provisioning, imaging, refresh cycles, and decommissioning procedures.
Patching & Vulnerability Management
  • Own the end-to-end monthly Patch Tuesday cycle planning, ring-based deployment, remediation tracking, and executive reporting.
  • Manage software update servicing (WSUS/SUP, Intune Update Rings, Windows Autopatch) and ensure SLA compliance across all global regions.
  • Partner with the Security Operations team to remediate critical and high vulnerabilities within agreed SLO windows.
  • Maintain a documented patching run book and escalation path for failures and exceptions.
Security Policy & Compliance (CIS & MDE)
  • Implement and enforce CIS Benchmark controls for Windows (Level 1 and Level 2) across the global fleet via Intune configuration profiles and SCCM baselines.
  • Own the Microsoft Defender for Endpoint (MDE) deployment, configuration, and health monitoring — including onboarding policies, ASR rules, tamper protection, and threat & vulnerability management.
  • Collaborate with the Security team to operationalize MDE alerts, Secure Score improvements, and endpoint detection & response (EDR) posture.
  • Conduct periodic compliance reporting against CIS benchmarks and remediate drift; maintain audit‑ready documentation.
  • Manage and tune Intune compliance and conditional access policies to enforce Zero Trust principles.
PowerShell & Scripting
  • Develop, maintain, and peer‑review PowerShell scripts for automation across device management tasks including compliance remediation, reporting, inventory, and configuration drift detection.
  • Build and maintain CI/CD‑friendly script repositories with version control (Git), testing frameworks, and documentation standards.
  • Leverage Graph API and PowerShell SDK for Intune to automate tenant configuration, bulk operations, and reporting.
  • Champion scripting best practices and provide guidance/code reviews to contractor team members.
Application Packaging & Deployment
  • Lead application packaging efforts including Win32 apps (Intune), MSI/EXE/MSIX transforms, and SCCM packages/task sequences.
  • Define and maintain application packaging standards, testing procedures, and approval workflows.
  • Manage the application catalog, ensuring software is current, licensed, and securely deployed.
  • Coordinate with software vendors and internal stakeholders to resolve packaging challenges and dependency conflicts.
Team Leadership & Offshore Coordination
  • Lead, coordinate, and quality‑assure the work of a team of offshore contractors based primarily in India, including task assignment, sprint planning, and performance feedback.
  • Establish clear SLAs, runbooks, and escalation paths to ensure consistent delivery quality across time zones.
  • Conduct regular stand‑ups, knowledge‑transfer sessions, and technical mentorship for the contractor team.
  • Manage staffing levels, onboarding, and knowledge continuity to minimize single points of failure.
  • Collaborate closely with IT leadership to prioritize the team’s backlog against project and operational demands.
Documentation, Reporting & Governance
  • Maintain comprehensive documentation for all device management processes, configurations, and operational procedures.
  • Produce regular management reporting on endpoint health, patch compliance, security posture, and KPIs.
  • Participate in change management processes (CAB), ensuring all changes to the endpoint platform are risk‑assessed and communicated.
  • Represent the endpoint team in cross‑functional meetings with IT Security, Networking, Help Desk, and business units.
Experience
Required Qualifications
  • 7+ years of hands‑on experience in Windows endpoint management at enterprise scale (10,000+ endpoints).
  • Demonstrated experience managing a globally distributed Windows device fleet across multiple geographies.
  • 3+ years of experience directly leading or coordinating technical teams, including offshore/nearshore resources.
  • Prior experience working within a 24/7 global IT operations model preferred.
Technical Skills — Must Have
  • Microsoft Intune — Deep, hands‑on expertise in Intune device enrollment (AADJ, Hybrid AADJ, Autopilot), configuration profiles, compliance policies, app deployment, and update rings. Experience with Intune co‑management and tenant‑attach scenarios. Microsoft Intune
  • SCCM / MEMCM — Strong working knowledge of SCCM site design, client deployment, task sequences, OSD, software update management, and reporting (SSRS). Experience migrating workloads to Intune preferred. SCCM / MEMCM
  • PowerShell — Advanced scripting ability; able to write production‑grade scripts without supervision. Proficient with PowerShell modules for Intune (Microsoft.Graph), Active Directory, and Windows management. Comfortable with error handling, logging, and modular script design. PowerShell
  • App Packaging — Proficient with Win32 app packaging for Intune (IntuneWinAppUtil), MSI/MSIX repackaging, silent install parameters, detection rules, and dependency management. Experience with SCCM packages and task sequences. App Packaging
  • CIS Benchmarks — Working knowledge of CIS Microsoft Windows Benchmark controls; experience translating CIS controls into Intune/SCCM policies and tracking compliance. CIS Benchmarks
  • Microsoft Defender for Endpoint (MDE) — Experience deploying and managing
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Windows Device Engineering Lead
Windows Device Engineering Lead

Scorpion Therapeutics • Exton (PA)

On-site
USD 140,000 - 180,000
Medical/dental/vision insurance
401(k) match
Disability & life insurance
+3
Intune Architect
Intune Architect

Stefanini North America and APAC • Indianapolis (IN)

On-site
USD 100,000 - 130,000
Senior Microsoft Endpoint Management Engineer
Senior Microsoft Endpoint Management Engineer

alllinestechnology • Pittsburgh

On-site
USD 120,000 - 160,000
Ralph Lauren Sr Windows Engineer
Ralph Lauren Sr Windows Engineer

BoF Careers • Nutley (NJ)

On-site
USD 120,000 - 180,000
Endpoint Management Administrator
Endpoint Management Administrator

Delta Computer Consulting • Marysville (OH)

Hybrid
USD 66,000 - 76,000
Health insurance
Vision insurance
Dental insurance
+3
Ralph Lauren Sr Windows Engineer
Ralph Lauren Sr Windows Engineer

Ralph Lauren • Nutley (NJ)

On-site
USD 140,000 - 190,000
Director, Enterprise Platform Engineering (Mac & Windows Endpoints)
Director, Enterprise Platform Engineering (Mac & Windows Endpoints)

Vanguard • Dallas (TX)

On-site
USD 130,000 - 180,000
AVD/Intune Endpoint Engineer
AVD/Intune Endpoint Engineer

Veriipro • United States

On-site
USD 120,000 - 160,000
Microsoft Intune Engineer- End User Computing Services Administrator
Microsoft Intune Engineer- End User Computing Services Administrator

iFlow Inc. • Palo Alto (CA)

Hybrid
USD 100,000 - 130,000
Microsoft Endpoint Configuration Manager Administrator
Microsoft Endpoint Configuration Manager Administrator

Vets Hired • Adelphi (MD)

On-site
USD 90,000 - 120,000