Position Summary
Lead global Windows endpoint management for ~50,000 devices, owning the full lifecycle (provisioning/configuration, monthly patching, security hardening, decommission) and coordinating offshore contractors.
Responsibilities
- Architect and continuously improve global Windows device management using Microsoft Intune and SCCM/MEMCM (co-management, cloud-only).
- Define baselines, enrollment profiles, compliance policies, and conditional access; drive modernization (Autopilot, Intune-only, co-management).
- Oversee lifecycle activities: provisioning, imaging, refresh cycles, decommission.
- Own monthly Patch Tuesday planning (ring-based deployment, remediation tracking, reporting) and update servicing (WSUS/SUP, Intune Update Rings, Windows Autopatch) with SLA compliance.
- Partner with Security to remediate critical/high vulns within SLOs; maintain patch runbooks/escalations.
- Enforce CIS Windows Benchmark controls (Level 1/2) via Intune/SCCM; deploy/configure/monitor Microsoft Defender for Endpoint (ASR, onboarding, tamper protection, TVM) and support EDR posture.
- Develop PowerShell automation; use Graph API/Intune SDK; maintain CI/CD-ready script repos (Git).
- Lead application packaging (Intune Win32, MSI/MSIX transforms, SCCM packages/task sequences) and manage the app catalog.
- Lead offshore contractor delivery (SLAs/runbooks, mentorship, sprint planning) and produce governance reporting.
Required Qualifications
- 7+ years enterprise Windows endpoint management (10,000+ endpoints)
- Experience managing globally distributed fleets
- 3+ years leading/coordinating technical teams (offshore/nearshore)
Must-Have Skills
- Microsoft Intune, SCCM/MEMCM, advanced PowerShell, app packaging (Intune Win32/SCCM), CIS Benchmarks, Microsoft Defender for Endpoint.
Benefits (explicitly stated)
Medical/dental/vision, 401(k), short/long-term disability, life insurance, tuition reimbursement, paid time off (sick up to 80 hrs/yr; vacation up to 120 hrs for new hires), holidays, and well-being benefits.