Senior Infrastructure Endpoint Engineer
EveropsRemoteFull Time2w ago
Job description
About the role
We are on the lookout for an experienced Endpoint Engineer to design and sustain sophisticated endpoint systems for our diverse clientele. This role will focus on creating secure and efficient environments across both macOS and Windows platforms while seamlessly integrating identity and security solutions.
Key facts
What you'll do
- Design, implement, and manage endpoint systems utilizing Microsoft Intune, Kandji (Iru), and Fleet for macOS and Windows devices.
- Oversee the entire lifecycle of devices, from initial deployment to decommissioning, ensuring adherence to compliance standards and facilitating smooth transitions.
- Automate the device deployment process leveraging tools such as Microsoft Autopilot and Apple Business Manager to enhance efficiency.
- Establish and enforce security hardening protocols for macOS and Windows environments using Intune, Kandji/Iru, and Fleet.
- Manage Endpoint Detection and Response (EDR) solutions, including CrowdStrike Falcon, SentinelOne, and Microsoft Defender for Endpoint, focusing on policy management and threat mitigation.
- Identify and remediate vulnerabilities by utilizing features from EDR platforms, adhering to established timelines for resolution.
- Lead the assessment, consolidation, and migration of endpoint and security tools, making informed decisions based on data analysis.
- Integrate endpoint systems with identity management solutions such as Okta and Entra ID for enhanced security.
- Automate endpoint configurations and application management through scripting languages like PowerShell, Bash, or Python.
- Diagnose and resolve complex issues that span operating systems, networks, and identity management layers.
- Collaborate with teams focused on Security, Identity and Access Management (IAM), and Cloud to ensure endpoint strategies align with the broader platform architecture.
- Prepare and present technical proposals and strategic roadmaps to stakeholders, supported by relevant metrics and data insights.
Requirements
- At least 6 years of experience in endpoint engineering or IT infrastructure, demonstrating a strong ability to manage roadmaps and influence technical direction.
- Comprehensive knowledge of Mobile Device Management (MDM) platforms, particularly Microsoft Intune, Kandji (Iru), and Fleet.
- Proficient in managing macOS and Windows at an enterprise level.
- Significant experience with EDR/XDR platforms, including CrowdStrike Falcon (policy adjustments, module management), SentinelOne (Singularity platform), and Microsoft Defender for Endpoint (integration with M365 Defender).
- Strong grasp of endpoint security fundamentals, covering patch management, compliance, EDR, vulnerability assessment, and alert analysis.
- Familiarity with identity management platforms such as Okta or Entra ID.
- Understanding of Zero Trust security frameworks and conditional access policies.
- Proficient in scripting languages such as PowerShell, Bash, or Python.
- Advanced troubleshooting skills across endpoint, identity, and network domains.
- Basic knowledge of cloud environments, including AWS or Azure.
- Experience with Microsoft Autopilot and Apple Business Manager is a plus.
- Familiarity with hybrid identity models, including Active Directory and Entra ID, as well as Group Policy Objects (GPOs).
- Proven ability to assess and recommend endpoint and security platform solutions based on objective data analysis.
- Experience in presenting technical strategies and trade-offs to leadership or clients is essential.
Nice to have
- Experience with configuration management tools like Ansible, Puppet, or Chef.
- Understanding of infrastructure as code principles, including the use of Terraform.
- Background in fast-paced, high-growth, or Software as a Service (SaaS) environments.
- Network troubleshooting expertise, including DNS, DHCP, and traffic flow analysis.
- Familiarity with endpoint analytics tools such as Nexthink.
- Demonstrated experience leading significant platform migrations or consolidations.
Skills & tools
- macOS
- Windows
- Microsoft Intune
- Kandji (Iru)
- Fleet
- CrowdStrike Falcon
- SentinelOne
- Microsoft Defender for Endpoint
- Okta
- Entra ID (Azure AD)
- PowerShell
- Bash
- Python
- Microsoft Autopilot
- Apple Business Manager
- AWS
- Azure
Practical notes
- This position is fully remote.
- Unlimited Paid Time Off is provided.
- Equity participation is included in the compensation package.
- A 401k plan with company contributions and sponsored healthcare benefits are available.
- Opportunities for professional growth, including training and certification programs, are offered to all employees.