Windows Endpoint Automation Engineer

The Vanguard Group

Wayne (PA)

Hybrid

USD 110,000 - 150,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Vanguard seeks a Senior Windows Endpoint Engineer to lead automation across provisioning, compliance, remediation, and configuration for the Windows fleet. This role focuses on repeatable, safe, scalable patterns and strong observability.

You will implement Intune, SCCM/MECM, Windows Autopilot, and PowerShell-based frameworks, aligning OS baselines and security standards with enterprise needs. Expect collaboration with QA, CI/CD, and identity platforms.

Qualifications

  • Eight years of related work experience.
  • Undergraduate degree in a related field or equivalent experience.
  • Sponsorship not offered for this position.

Responsibilities

  • Lead endpoint automation for provisioning, compliance, remediation, and standard configuration across the Windows fleet.
  • Engineer and modernize deployment workflows using Microsoft Intune, SCCM/MECM, and Windows Autopilot.
  • Build reusable PowerShell-based frameworks for device configuration, drift detection, self-healing remediation, and operational consistency.
  • Define and evolve Windows endpoint standards including OS baseline configuration, security baselines, and lifecycle practices.
  • Partner with QA and release governance to improve validation practices for patches, feature updates, policy changes, security configuration, and application rollouts.
  • Implement and expand CI/CD practices for endpoint engineering content, using Git-based workflows, reviews, and promotion patterns.
  • Collaborate across Workplace Engineering to standardize engineering patterns and share automation approaches.

Skills

PowerShell
Windows endpoint engineering
CI/CD concepts
Git workflows
Automation
Troubleshooting
Documentation

Education

Undergraduate degree

Tools

Intune
SCCM/MECM
Windows Autopilot
Git
OS provisioning
Entra ID

Job description

Core Responsibilities: Lead endpoint automation for provisioning, compliance, remediation, and standard configuration across the Windows fleet. Engineer and modernize deployment workflows using Microsoft Intune, SCCM/MECM, and Windows Autopilot, with a focus on repeatability, safety, and scale. Build reusable PowerShell-based frameworks (and supporting tooling) for device configuration, drift detection, self-healing remediation, and operational consistency. Define and evolve Windows endpoint standards including OS baseline configuration, security baselines, and lifecycle practices aligned with enterprise requirements. Partner with QA and release governance to improve validation practices for patches, feature updates, policy changes, security configuration, and application rollouts. Implement and expand CI/CD practices for endpoint engineering content (scripts, configuration, packaging, policy-as-code where applicable), using Git-based workflows, reviews, and promotion patterns. Integrate with identity and security platforms (e.g., Microsoft Entra ID) to support secure provisioning, access, and device compliance patterns. Reduce operational toil and improve reliability by automating routine work, codifying repeatable runbooks, and improving observability and troubleshooting signals. Collaborate across Workplace Engineering (Windows, VDI, macOS/mobility, Digital Workplace) to standardize engineering patterns and share automation approaches.

Technical Requirements

Strong experience with Windows endpoint engineering in an enterprise environment (OS configuration, policy management, troubleshooting, and lifecycle management). Hands-on experience with Microsoft Intune and SCCM/MECM for application delivery, device management, and endpoint configuration. Experience with Windows Autopilot and modern provisioning patterns. Proficiency in PowerShell for automation, packaging, and remediation workflows. Working knowledge of CI/CD concepts and Git-based workflows (code reviews, branching strategies, reusable templates/modules). Familiarity with Microsoft Entra ID and endpoint identity/compliance patterns. Experience with Desired State concepts (e.g., Desired State Configuration or similar) is a plus. Understanding of enterprise endpoint security concepts (security baselines, hardening, least privilege, patching/updates). Familiarity with monitoring/telemetry and operational observability concepts is a plus.

What it takes

Undergraduate degree in a related field or equivalent experience. 3–5+ years of relevant experience in Windows endpoint engineering, automation, or platform engineering roles. Strong analytical, problem-solving, and troubleshooting skills. Strong written and verbal communication skills, with the ability to document standards and enable others. Ability to work across teams, influence standards, and drive automation-first engineering practices. Strong planning, organization, and delivery discipline.

Qualifications

Minimum of eight years related work experience. Undergraduate degree in a related field or the equivalent combination of training and experience. Special Factors Sponsorship Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a mission—we're on a mission. To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience. Vanguard, one of the world's leading investment management companies, serves individual investors, institutions, employer-sponsored retirement plans, and financial professionals. We have a diverse and talented crew with a culture that promotes teamwork, along with an unwavering focus on serving our clients' best interests.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Windows Endpoint Automation Engineer
Windows Endpoint Automation Engineer

Vanguard • Town of Charlotte (NY)

Hybrid
USD 110,000 - 170,000
Windows Endpoint Automation Engineer
Windows Endpoint Automation Engineer

Vanguard • Wayne (PA)

Hybrid
USD 120,000 - 150,000
Hybrid work model
Domain Architect, Windows Endpoint
Domain Architect, Windows Endpoint

Vanguard • Dallas (TX)

Hybrid
USD 120,000 - 150,000
Director, Enterprise Platform Engineering (Windows Endpoint)
Director, Enterprise Platform Engineering (Windows Endpoint)

Vanguard • Wayne (PA)

Hybrid
USD 260,000 - 360,000
Hybrid working model
Professional development opportunities
Collaborative culture
Senior Windows Endpoint Automation Engineer
Senior Windows Endpoint Automation Engineer

The Vanguard Group • Wayne (PA)

Hybrid
USD 110,000 - 150,000
Microsoft 365 Platform Administrator
Microsoft 365 Platform Administrator

Vanguard • Wayne (PA)

Hybrid
USD 120,000 - 170,000
Microsoft 365 Platform Administrator
Microsoft 365 Platform Administrator

Vanguard • Dallas (TX)

Hybrid
USD 120,000 - 160,000
Hybrid work model
Competitive benefits
Director, Enterprise Platform Engineering (Mac & Windows Endpoints)
Director, Enterprise Platform Engineering (Mac & Windows Endpoints)

Vanguard • Dallas (TX)

On-site
USD 130,000 - 180,000
Chief Architect - End User Technologies
Chief Architect - End User Technologies

Vanguard • Dallas (TX)

On-site
USD 150,000 - 200,000
Microsoft 365 Platform Administrator
Microsoft 365 Platform Administrator

Vanguard • Scottsdale (AZ)

Hybrid
USD 120,000 - 150,000
Health coverage
Retirement plans
Paid time off
+2