Job Description
Job DescriptionWe are looking for an experienced Systems Engineer - Endpoint Management to support enterprise Windows device strategy and operations for a defense software environment in Atlanta, Georgia. This Long-term Contract position focuses on modern endpoint management, secure device configuration, large-scale Windows lifecycle planning, and dependable execution within established governance standards. The role is well suited for someone who can balance hands-on technical work, automation, and documentation while supporting both standard business users and developer workstations.
Responsibilities:
• Lead administration of Windows endpoint management services using Microsoft Intune, including Autopilot provisioning, application delivery, compliance enforcement, and configuration policy management.
• Manage identity and device access controls through Microsoft Entra ID, with emphasis on Conditional Access integration and device compliance alignment.
• Oversee Windows Update for Business operations by defining deployment rings, coordinating remediation efforts, and guiding staged release strategies for enterprise endpoints.
• Direct driver and firmware governance for Dell and Lenovo systems, including troubleshooting feature update issues, controlling update sequencing, and reducing hardware-related regressions.
• Plan and execute enterprise-scale Windows operating system upgrades, including compatibility validation, pilot testing, phased rollouts, and post-deployment support.
• Develop and maintain advanced PowerShell automation to streamline endpoint administration, improve consistency, and reduce manual operational effort.
• Support developer workstation needs by implementing managed certificate trust approaches for inspected web traffic environments and maintaining reliable endpoint usability.
• Create and maintain Endpoint Privilege Management policies in CyberArk/Idira for Windows devices while aligning configurations with security requirements and operational needs.
• Produce clear operational documentation, standard procedures, and technical decision records so ongoing support can be transferred effectively across teams.
• Participate in formal change control activities by preparing implementation plans, assessing risk, documenting rollback steps, and executing changes in accordance with enterprise governance processes.• At least 7 years of experience managing Windows endpoints in large enterprise environments with the ability to work independently and make sound technical decisions.
• Hands-on expertise with Microsoft Intune in Windows-focused deployments, including Autopilot, compliance policies, application rollout, and configuration profile administration.
• Strong experience with Microsoft Entra ID, Windows Update for Business, and BitLocker management in secure enterprise settings.
• Proven background managing Dell and Lenovo driver and firmware updates, including investigation of feature update driver conflicts and rollout prioritization.
• Advanced PowerShell scripting skills with a track record of building automation for endpoint operations and administration.
• Experience delivering major Windows OS version upgrades at scale using structured testing, deployment waves, and compatibility planning.
• Familiarity with formal IT change management practices, including change documentation, risk evaluation, approval processes, and rollback preparation.
• Strong troubleshooting, analytical, and documentation skills; experience with WSL2, CrowdStrike, CyberArk Endpoint Privilege Management, Windows 365, osQuery, Palo Alto GlobalProtect, or managed certificate trust methods is preferred.
