Modern Desktop Engineer

Shop2Shop

Stellenbosch

Hybrid

ZAR 600,000 - 900,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Shop2Shop is seeking a Modern Desktop Engineer to support, secure and progressively improve its endpoint environment across Windows, macOS and mobile platforms. You’ll focus on provisioning, configuration, compliance, app delivery, OS management and endpoint security using Intune and Apple Business Manager, delivering a consistent, secure device experience at scale.

Collaborating with security and IT teams, you’ll automate workflows, maintain standard device builds, and drive lifecycle

Qualifications

  • 4–6 years’ experience managing and supporting enterprise endpoint environments.
  • Hands-on experience with Microsoft Intune and modern Windows device management.
  • Experience with Defender for Endpoint, BitLocker or FileVault.
  • Microsoft Endpoint Administrator Associate certification is required or strongly preferred; other endpoint-management certifications would be beneficial.

Responsibilities

  • Provision and configure Windows and macOS devices using automated deployment methods.
  • Manage Windows Autopilot and zero-touch provisioning processes.
  • Configure device policies through Microsoft Intune and maintain security baselines.
  • Monitor device compliance and address enrolment failures.
  • Coordinate OS and application updates and third-party patches.
  • Configure and maintain endpoint controls within Defender stack and manage local admin access.
  • Work with Security Operations to remediate endpoint vulnerabilities and support incident containment.

Skills

Windows 11 admin
macOS management
Microsoft Intune
Windows Autopilot
Apple Business Manager
Zero-touch provisioning
Defender for Endpoint
BitLocker
FileVault
Windows LAPS
Endpoint hardening
CIS benchmarks
App packaging
App deployment
OS servicing
Patch management
Troubleshooting
Inventory management
Asset lifecycle
Decommissioning

Education

IT / CS degree

Job description

The Modern Desktop Engineer is a hands-on technical role responsible for supporting, securing and continuously improving Shop2Shop’s endpoint environment across Windows, macOS and supported mobile platforms.

You will focus on device provisioning, configuration, compliance, application delivery, operating system management and endpoint security using platforms such as Microsoft Intune and Apple Business Manager. You will help provide users with a consistent and secure device experience while improving automation, supportability and lifecycle management across the endpoint estate.

You’ll thrive in this role if…
  • You believe a well-built device is invisible to the user, and you take pride in making that true at scale
  • You're comfortably OS-agnostic; you respect both Windows and macOS and enjoy the quirks of each
  • You'd rather fix the root cause once than reset the same device ten times; good baselines and automation are your default
  • You troubleshoot methodically: reproduce, check the logs, isolate, fix, document
  • You keep a fleet in order without losing the plot; patch cycles, compliance and inventory don't slip on your watch
  • You have empathy for the person behind the ticket and can explain a policy without sounding like one
  • You like enabling first-line teams so common issues never reach you twice
What You Will Do
Endpoint Provisioning and Lifecycle Management
  • Provision and configure Windows and macOS devices using automated deployment methods.
  • Manage Windows Autopilot, Apple Business Manager and zero-touch provisioning processes.
  • Maintain standard device builds, configuration profiles and provisioning documentation.
  • Coordinate device replacement, decommissioning, secure wiping and disposal.
Endpoint Configuration and Compliance
  • Configure and maintain device policies through Microsoft Intune and related management platforms.
  • Implement security baselines aligned with organisational and CIS requirements.
  • Monitor device compliance and address configuration or enrolment failures.
  • Maintain device compliance signals that feed Conditional Access, working with the Microsoft 365 & Identity Engineer.
  • Manage encryption controls, including BitLocker and FileVault.
Application and Update Management
  • Package, test and deploy business applications to managed endpoints.
  • Manage operating system upgrades, security updates and feature releases.
  • Coordinate third-party software patching and application lifecycle activities.
  • Monitor deployment results and resolve update or installation failures.
  • Configure and maintain endpoint controls within the Microsoft Defender stack.
  • Manage local administrative access and endpoint privilege controls, including LAPS.
  • Work with the Security Operations Analyst to remediate endpoint vulnerabilities.
  • Support containment and remediation activities during endpoint security incidents.
Technical Support and Troubleshooting
  • Provide second-line support for endpoint, operating system and application issues.
  • Investigate recurring device problems and implement permanent corrective actions.
  • Coordinate warranty repairs, vendor support and hardware escalations.
  • Develop support documentation and enable first-line support teams to resolve common issues.
Asset and Endpoint Service Management
  • Maintain accurate hardware and software inventory records.
  • Support asset lifecycle processes from procurement through deployment and disposal.
  • Monitor endpoint health, configuration status and software compliance.
  • Identify opportunities to improve device reliability, user experience and deployment automation.
What You’ll Need to Succeed
  • Strong knowledge of Windows endpoint administration, with practical exposure to macOS management.
  • Experience with Microsoft Intune, Windows Autopilot and modern device-management practices.
  • Understanding of endpoint security, compliance policies, encryption and security baselines.
  • Experience packaging and deploying applications, operating-system updates and third-party patches.
  • Strong troubleshooting skills across devices, operating systems, applications and user configurations.
  • An automation-focused approach to device provisioning, configuration and lifecycle management.
  • Good knowledge of hardware asset management, device support and secure decommissioning practices.
  • The ability to work with support teams, security personnel and external vendors to resolve technical issues.
Skills and Knowledge
  • Windows 11 administration and practical knowledge of macOS device management.
  • Microsoft Intune for device enrolment, configuration, compliance and application deployment.
  • Windows Autopilot, Apple Business Manager and zero-touch device provisioning.
  • Endpoint security controls, including Microsoft Defender for Endpoint, BitLocker, FileVault and Windows LAPS.
  • Security baselines and endpoint-hardening standards, including CIS-aligned configuration.
  • Application packaging, testing and deployment using modern endpoint-management platforms.
  • Operating-system servicing, feature upgrades, security updates and third-party patch management.
  • Endpoint troubleshooting, hardware and software inventory, asset lifecycle management and secure device decommissioning.
Qualifications and Experience
  • A relevant diploma or degree in Information Technology, Computer Science or a related field, or equivalent practical experience.
  • Approximately 4–6 years’ experience managing and supporting enterprise endpoint environments.
  • Hands-on experience with Microsoft Intune, Windows Autopilot and modern Windows device management.
  • Practical experience with device configuration, compliance policies, application deployment and operating-system servicing.
  • Experience implementing endpoint security controls such as Defender for Endpoint, BitLocker, FileVault or Windows LAPS.
  • Exposure to macOS management, Apple Business Manager and mobile-device management would be beneficial.
  • Experience providing second-line technical support and coordinating hardware, software and vendor escalations.
  • Microsoft Endpoint Administrator Associate certification is required or strongly preferred; other endpoint-management certifications would be beneficial.
Other Requirements
  • Hybrid working model with regular in-office presence in Stellenbosch, based on team rhythms, collaboration needs and business requirements.
  • Ability to attend key planning sessions, stakeholder workshops and in-person team collaboration when required.
  • Reliable internet connectivity and a suitable remote-working setup for work-from-home days.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Desktop Engineer
Senior Desktop Engineer

Tiger Brands • Randburg

On-site
ZAR 550,000 - 850,000
Senior Workspace Engineer
Senior Workspace Engineer

Hire Resolve • Oos-Kaap

On-site
ZAR 60,000 - 80,000
Competitive salary based on experience
IT Technichian
IT Technichian

ARCS • Wes-Kaap

On-site
ZAR 180,000 - 300,000
IT Technician
IT Technician

Cecile Personnel (Pty) Ltd • Wes-Kaap

On-site
ZAR 180,000 - 280,000
Security Operations Analyst
Security Operations Analyst

Shop2Shop • Stellenbosch

Hybrid
ZAR 480,000 - 720,000
IT Manager
IT Manager

AtripleA recruitment & temps • Pretoria

On-site
ZAR 900,000 - 1,300,000
Intermediate IT Support Engineer
Intermediate IT Support Engineer

Belay Talent Solutions • Cape Town

On-site
ZAR 240,000 - 360,000
Systems Administrator (Montagu - Route 62, Western Cape)
Systems Administrator (Montagu - Route 62, Western Cape)

Cyberlogic • Montagu

On-site
ZAR 420,000 - 660,000
Expert Infrastructure Engineer
Expert Infrastructure Engineer

Sabenza IT & Recruitment • Pretoria

On-site
ZAR 600,000 - 800,000
Systems Administrator (Ceres & Surroundings)
Systems Administrator (Ceres & Surroundings)

Hyperclear Tech • Ceres

On-site