New
Endpoint Engineer - Intune
TEKsystems | |
$65.00 - $70.00 / hr
| |
life insurance, sick time, 401(k), retirement plan
| |
United States, Illinois, North Chicago | |
Aug 08, 2026 | |
|
*Description*
Our client is seeking an Endpoint Management Engineer to design, automate, and operate the enterprise device management platform supporting our global workforce, laboratories, manufacturing sites, and commercial field organization. This role owns hands-on engineering and operations across Microsoft Intune and Microsoft Configuration Manager (SCCM/MECM) in a co-management architecture, with Hybrid Entra ID (Azure AD) joined, Active Directory domain-bound Windows endpoints and a multi-platform Intune estate spanning Windows, macOS, iOS/iPadOS, and Android - including Android-based teleconferencing and conference room systems. Automation is central to this role. The successful candidate writes production-quality PowerShell, Bash, and .NET code, builds Intune remediation and detection scripts, and uses the Microsoft Graph API to manage the estate programmatically rather than soley through the console. We also expect fluency with modern AI-assisted engineering tools - including Claude or CoPilot - to accelerate script development, log analysis, documentation, and reporting. Equally important is the discipline required in a regulated pharmaceutical environment. You will advance modern management objectives - Zero Trust, Conditional Access, cloud-first policy delivery, and progressive workload migration from Configuration Manager to Intune - while respecting the reliability requirements of standard corporate devices and the constraints of non-standard, purpose-built systems such as laboratory instrument controllers, manufacturing workstations, kiosks, and validated GxP endpoints. The role partners closely with Information Security, Identity, Networking, Infrastructure, Site IT, and Site Service Support teams. Key Responsibilities Automation, Scripting, and Development *Design, write, and maintain production-quality PowerShell for endpoint provisioning, configuration enforcement, bulk administration, reporting, and incident remediation across the Windows estate. *Write and maintain shell/Bash scripts for macOS configuration, compliance validation, and application delivery through Intune macOS shell scripting. *Build and manage Intune Remediations (proactive remediations) - paired detection and remediation script logic - to identify and self-heal configuration drift, failed agents, certificate issues, and compliance gaps without user impact. *Automate platform operations against the Microsoft Graph API, including device and policy inventory, assignment management, application lifecycle tasks, reporting extracts, and integration with adjacent systems. *Apply engineering discipline to automation assets: source control, code review, parameterization, error handling, logging, idempotency, and controlled release through test rings. *Convert recurring manual and Service Desk activities into automated or self-service capabilities. Core Device Management *Engineer and maintain Intune compliance policies across all platforms, including device health, OS version floors, and custom compliance scripts. *Build and maintain configuration profiles and settings catalog policies, administrative templates, and custom OMA-URI/configuration profiles for Windows, macOS, iOS/iPadOS, and Android. *Familiar with Windows Update for Business and update rings, feature and quality update deployments, driver and firmware update governance, macOS and iOS update policies. *Manage monthly and out-of-band patch operations in Configuration Manager through Software Update Groups, automatic deployment rules, and maintenance windows; drive patch compliance to defined service-level targets and remediate delinquent endpoints. *Package, test, and deploy applications across platforms - Win32 (.intunewin), MSI/MSIX, Microsoft Store, Microsoft 365 Apps, macOS PKG/DMG and shell-script apps, iOS/Android managed apps via volume purchasing - with correct detection rules, dependencies, supersedence, requirement rules, and assignment logic. *Implement and maintain security baselines and industry benchmarks - Microsoft security baselines for Windows, Edge, and Defender; CIS Benchmarks; DISA STIG-derived controls - including deviation tracking, exception documentation, and drift detection. *Administer the Configuration Manager hierarchy: site systems, distribution points, boundary groups, client health, content distribution, task sequences, OS deployment, and hardware/software inventory accuracy. *Manage non-standard Windows endpoints - laboratory instrument PCs, manufacturing and shop-floor workstations, kiosks, shared and standalone systems - with tailored collections, restricted patch windows, exception handling, and documented deviations. Identity, Conditional Access, and Endpoint Security *Manage device identity across Entra ID and on-premises Active Directory, including Hybrid Entra ID join, Entra ID join, AD domain-bound systems, and resolution of stale, duplicate, or mis-registered device objects. *Configure and maintain co-management settings, pilot collections, and the controlled transition of individual workloads (compliance policies, Windows Update, device configuration, client apps, Office Apps) from Configuration Manager to Intune. *Support Conditional Access in partnership with Identity and Information Security: device-based and compliance-based grant controls, filters for devices, app protection policy requirements, and safe rollout using report-only mode and exclusion groups. *Understand and support macOS Platform SSO with Entra ID - Secure Enclave authentication, local account creation and password sync, registration during Automated Device Enrollment - and the Microsoft Enterprise SSO plug-in for macOS and iOS/iPadOS. *Familiar with Zscaler Client Connector or comparable Zero Trust network access and secure web gateway agents across Windows and macOS. *Familiar with endpoint security controls, including Microsoft Defender for Endpoint, BitLocker and FileVault encryption with key escrow, application control, firewall policy, and Windows LAPS. *Deploy and maintain certificate profiles (SCEP/PKCS) and Wi-Fi (including 802.1X) across all supported platforms. Endpoint Analytics, KPIs, and Reporting *Define, publish, and maintain endpoint management KPIs - patch compliance rate and time-to-patch, policy and compliance conformance, application deployment success rate, agent and client health. *Build operational and executive dashboards using Intune reporting, Configuration Manager reporting and SQL, Log Analytics, Microsoft Graph data extracts, and PowerBI. *Use AI-assisted engineering tools - Claude Code, Cowork, GitHub Copilot, Microsoft Copilot, and comparable agentic tooling - to accelerate script and policy development, log and error triage, documentation authoring, data analysis, and report generation. Compliance, Quality, and Operational Support *Execute all platform and policy changes through the enterprise change management process, with documented impact assessment, test evidence, approvals, and rollback plans. *Support GxP-regulated endpoints by respecting validated system boundaries, coordinating with appropriate groups on change impact, and maintaining documentation sufficient to withstand internal audit and regulatory inspection. *Serve as escalation point for complex endpoint incidents from Endpoint Engineering Operations team and regional IT teams; perform root cause analysis and implement permanent corrective actions. *Maintain accurate technical documentation, standard operating procedures, work instructions, and knowledge base articles. *Participate in an on-call or extended-coverage rotation for critical endpoint incidents and scheduled maintenance activities. *Additional Skills & Qualifications* Required Qualifications *Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field; equivalent professional experience with relevant certifications will be considered. *Minimum of 3 years of hands-on experience administering Microsoft Configuration Manager (SCCM/MECM) in an enterprise environment, including application packaging, OS deployment, and software update management. *Minimum of 3 years of hands-on experience administering Microsoft Intune, including compliance policies, configuration profiles, security baselines, and application deployment. *Demonstrated proficiency writing and maintaining PowerShell for endpoint automation, remediation, and reporting - beyond running scripts written by others. *Practical experience with the Microsoft Graph API for endpoint management automation or reporting. *Working knowledge of Intune and Configuration Manager co-management, workload transition, Hybrid Entra ID join, and Active Directory domain-bound Windows endpoints. *Hands-on experience managing at least two non-Windows platforms in Intune (macOS, iOS/iPadOS, or Android), including scripting or shell-based configuration on macOS. *Working knowledge of Entra ID, Conditional Access, Group Policy, Active Directory, DNS/DHCP, PKI and certificate services, and Windows client architecture. *Experience deploying and troubleshooting endpoint security and network access agents (for example, Zscaler Client Connector, CrowdStrike). *Experience using endpoint reporting and analytics to measure and improve device health, compliance, or user experience (for example Intune report dashboards, Nexthink). *Working familiarity with AI-assisted development and productivity tools, and sound judgment about their appropriate use with enterprise data. *Experience operating within formal change management, incident management, and documentation standards. *Strong analytical and troubleshooting skills spanning identity, network, policy, and ap *Job Type & Location* This is a Contract position based out of North Chicago, IL. *Pay and Benefits*The pay range for this position is $65.00 - $70.00/hr. Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following: * Medical, dental & vision * Critical Illness, Accident, and Hospital * 401(k) Retirement Plan - Pre-tax and Roth post-tax contributions available * Life Insurance (Voluntary Life & AD&D for the employee and dependents) * Short and long-term disability * Health Spending Account (HSA) * Transportation benefits * Employee Assistance Program * Time Off/Leave (PTO, Vacation or Sick Leave) *Workplace Type*This is a hybrid position in North Chicago,IL. *Application Deadline*This position is anticipated to close on Aug 15, 2026. About TEKsystems We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services, and real-world application, we work with progressive leaders to drive change. That's the power of true partnership. TEKsystems is an Allegis Group company. The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law. About TEKsystems and TEKsystems Global Services We're a leading provider of business and technology services. We accelerate business transformation for our customers. Our expertise in strategy, design, execution and operations unlocks business value through a range of solutions. We're a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia, who partner with us for our scale, full-stack capabilities and speed. We're strategic thinkers, hands-on collaborators, helping customers capitalize on change and master the momentum of technology. We're building tomorrow by delivering business outcomes and making positive impacts in our global communities. TEKsystems and TEKsystems Global Services are Allegis Group companies. Learn more at TEKsystems.com. The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law. *San Francisco Fair Chance Ordinance:* Pursuant to the San Francisco Fair Chance Ordinance, for all positions located in the city and county of San Francisco, we will consider for employment qualified applicants with arrest and conviction records. *Massachusetts Lie Detector:* It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability. *Use of Artificial Intelligence (AI):* We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates. AI helps assess applications and qualifications, but final decisions are made by our hiring team. By applying, you acknowledge and agree that your application may be reviewed using AI tools. | |
$65.00 - $70.00 / hr
life insurance, sick time, 401(k), retirement plan
Aug 08, 2026