Takeda logo

Windows Device Engineering Lead

Takeda
August 19, 2026
Remote friendly (Exton, PA)
United States
$137,000 - $215,270 USD yearly
IT
Position Summary
- Lead global endpoint management for ~50,000 Windows devices worldwide across the full lifecycle (provisioning/configuration, monthly patching, security hardening, decommission) while coordinating a distributed contractor team.

Key Responsibilities
Endpoint Management & Strategy
- Architect and improve Windows management using Microsoft Intune and SCCM/MEMCM (co-management/cloud-only).
- Own baselines, enrollment profiles, compliance policies, and conditional access.
- Drive modernization to Autopilot/Intune-only/co-management.
- Oversee provisioning, imaging/refresh, and decommissioning.
Patching & Vulnerability Management
- Run monthly Patch Tuesday cycles (planning, ring-based deployment, remediation tracking, reporting).
- Manage WSUS/SUP, Intune Update Rings, Windows Autopatch; ensure SLA/SLO compliance.
- Partner with Security Ops to remediate critical/high vulnerabilities within SLO windows.
Security Policy & Compliance (CIS & MDE)
- Implement/enforce CIS Windows benchmarks (Level 1/2) via Intune/SCCM.
- Deploy/configure Microsoft Defender for Endpoint (onboarding, ASR rules, tamper protection, TVM).
- Report CIS compliance and remediate drift; tune Intune compliance/conditional access for Zero Trust.
PowerShell & Application Packaging
- Develop/peer-review automation PowerShell (Intune/Graph, reporting, inventory, drift detection).
- Lead Win32 app packaging (Intune), MSI/MSIX transforms, SCCM packages/task sequences.
Team Leadership & Governance
- Lead offshore contractors (planning, SLAs/runbooks, mentorship), maintain documentation, produce KPI reporting, participate in CAB, and represent endpoint team cross-functionally.

Required Qualifications
- 7+ years enterprise Windows endpoint management (10,000+ endpoints).
- Experience managing global multi-geo Windows fleet.
- 3+ years leading/coordinating technical teams (offshore/nearshore).
- 24/7 global IT operations experience preferred.

Must-Have Technical Skills
- Microsoft Intune, SCCM/MEMCM, advanced PowerShell, application packaging, CIS benchmarks, Microsoft Defender for Endpoint.

Strong Plus / Preferred
- Autopatch/Autopilot scenarios; Entra ID/Conditional Access; IT analytics reporting; ITSM (ServiceNow); Sentinel/Defender XDR; ITIL; MD-102/SC-200; regulated-industry compliance; other EDR tools.

Benefits (if eligible)
- Medical/dental/vision, 401(k) match, disability/life insurance, tuition reimbursement, paid volunteer time off, holidays, sick time (up to 80 hrs/yr), paid vacation (up to 120 hrs for new hires).