Fortive Logo

Fortive

Endpoint Engineer

Posted One Month Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in India
Senior level
In-Office or Remote
Hiring Remotely in India
Senior level
Designs, secures, automates, and manages enterprise Windows and Apple endpoints using Intune, SCCM/MECM, Autopilot, and Jamf Pro. Leads SCCM-to-cloud modernization, zero-touch provisioning, endpoint security, application packaging, compliance, remediation, and lifecycle automation. Provides Level 3 support, resolves complex endpoint issues, establishes engineering standards, documents architecture and procedures, collaborates with technology teams, and mentors junior engineers.
The summary above was generated by AI
Endpoint Engineer Role Overview

The Endpoint Engineer is responsible for the design, engineering, security, automation, and lifecycle management of enterprise Windows and Apple endpoints. This role serves as a technical subject matter expert for Microsoft Intune, SCCM/MECM, Windows Autopilot, Jamf Pro, endpoint provisioning, security configuration, and Endpoint Privilege Management (EPM).

The engineer will lead initiatives to modernize endpoint management, transition legacy management capabilities toward cloud-native solutions, improve endpoint security, automate provisioning and remediation, and establish scalable endpoint engineering standards across the enterprise.

Key Responsibilities
  • Design, engineer, and maintain enterprise endpoint management solutions using Microsoft Intune, SCCM/MECM, Jamf Pro, and Windows Autopilot.
  • Serve as a technical SME for Windows and macOS endpoint architecture, management, provisioning, security, and troubleshooting.
  • Lead the modernization and migration of traditional SCCM workloads toward Intune and cloud-native endpoint management.
  • Design and maintain Intune configuration profiles, compliance policies, security baselines, device restrictions, and remediation solutions.
  • Architect and optimize Windows Autopilot and Apple Automated Device Enrollment to provide standardized zero-touch provisioning.
  • Engineer SCCM/Intune co-management solutions and determine appropriate workload migration strategies.
  • Administer and engineer Jamf Pro for enterprise macOS management, including configuration, application deployment, FileVault, security policies, scripting, and automated provisioning.
  • Design endpoint security standards using technologies including Microsoft Defender for Endpoint, BitLocker, FileVault, Attack Surface Reduction, Windows Firewall, device control, application control, and security baselines.
  • Design and implement Microsoft Intune Endpoint Privilege Management (EPM) to reduce permanent local administrator access and enforce least-privilege principles.
  • Develop and maintain application packaging and deployment solutions across Intune, SCCM, and Jamf.
  • Develop automation using PowerShell, Microsoft Graph API, Graph PowerShell SDK, REST APIs, and shell scripting.
  • Automate device provisioning, application deployment, configuration validation, compliance reporting, security remediation, inventory, and endpoint lifecycle activities.
  • Integrate endpoint compliance and security controls with Microsoft Entra ID and Conditional Access.
  • Establish engineering standards for endpoint provisioning, configuration, security, patching, application deployment, and lifecycle management.
  • Provide Level 3 engineering support and root-cause analysis for complex Windows, macOS, enrollment, provisioning, application, and security issues.
  • Partner with Cybersecurity, IAM, Infrastructure, Service Desk, and other technology teams to align endpoint architecture with enterprise security and operational requirements.
  • Create technical standards, architecture documentation, SOPs, implementation plans, and operational procedures.
  • Mentor junior engineers and support teams while providing technical leadership for endpoint initiatives.
Required Qualifications
  • 6+ years of experience in endpoint engineering, desktop engineering, endpoint security, or enterprise device management.
  • Advanced experience with Microsoft Intune and SCCM/MECM.
  • Strong experience with Windows Autopilot and modern Windows provisioning.
  • Experience administering and engineering Jamf Pro and enterprise macOS environments.
  • Strong knowledge of Windows 10/11, macOS, Entra ID, device identity, and Conditional Access.
  • Strong PowerShell scripting and automation experience.
  • Experience with application packaging, deployment, patching, and remediation.
  • Strong understanding of endpoint security, least privilege, device compliance, and configuration management.
  • Experience designing and implementing enterprise-scale endpoint solutions.
  • Demonstrated ability to troubleshoot complex endpoint and provisioning issues.
Preferred Qualifications

Experience with Intune Endpoint Privilege Management, Microsoft Defender for Endpoint, Microsoft Graph API, Windows Hello for Business, Apple Business Manager, enterprise PKI/certificate-based authentication, CIS/Microsoft security benchmarks, vulnerability management, and large-scale SCCM-to-Intune modernization initiatives is highly desirable.

Similar Jobs

4 Days Ago
Remote
India
Senior level
Senior level
Information Technology • Software
Build Go-based endpoint agents and backend services for AI and LLM security across Windows, macOS, and Linux. Responsibilities include endpoint detection, policy enforcement, fleet management, telemetry ingestion, health monitoring, performance optimization, cross-platform testing, code signing, release engineering, and production readiness. The role requires systems programming, concurrency, networking, distributed-service development, and effective use of AI-assisted coding tools.
Top Skills: Apple Endpoint Security FrameworkClaude CodeCodexCursorDockerEbpfEtwGithub CopilotGoGrpcKubernetesLinuxmacOSPythonRest ApisWindows
10 Days Ago
In-Office or Remote
Senior level
Senior level
Information Technology
Lead the migration of enterprise iOS and iPadOS device management from Ivanti EPMM/MobileIron to Microsoft Intune. Design endpoint automation using Graph API, PowerShell, REST APIs, and Azure services; manage enrollment, compliance, applications, Apple integrations, reporting, and remediation. Provide advanced Level 3 support and collaborate with security, identity, network, and application teams to deliver secure, scalable endpoint solutions.
Top Skills: Apple Business ManagerApps & BooksAutomated Device EnrollmentAzure AutomationAzure DevopsAzure FunctionsAzure MonitorC#Conditional AccessGitiOSIpadosIvanti EpmmJSONLog AnalyticsLogic AppsLookoutMicrosoft DefenderMicrosoft Entra IdMicrosoft Graph ApiMicrosoft IntuneMobileironOauth 2.0PkiPower AutomatePower BIPowershellPythonRest ApisServicenowZimperiumZscaler
One Month Ago
Remote
India
Senior level
Senior level
Machine Learning • Mobile • Security
Provide technical support and troubleshooting for Zimperium's mobile threat defense product, owning customer issues through resolution, validating fixes with QA, creating JIRAs for engineering, and collaborating with product, devops, and customer success teams to maintain high customer satisfaction.
Top Skills: AdbAirwatchAmazon Web ServicesAndroid StudioArcsightCitrixDockerJavaJIRAJunitKafkaMobileironMs-IntuneOpenstackPostgresPythonSplunkSQLUnixXcode

What you need to know about the Pune Tech Scene

Once a far-out concept, AI is now a tangible force reshaping industries and economies worldwide. While its adoption will automate some roles, AI has created more jobs than it has displaced, with an expected 97 million new roles to be created in the coming years. This is especially true in cities like Pune, which is emerging as a hub for companies eager to leverage this technology to develop solutions that simplify and improve lives in sectors such as education, healthcare, finance, e-commerce and more.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account