Windows Device Engineering Lead
Takeda
August 29, 2026
Remote friendly (Cambridge, MA)
United States
$137,000 - $215,270 USD yearly
IT
Position Summary
- Lead global Windows endpoint management for ~50,000 devices worldwide, owning the full lifecycle (provisioning/config, monthly patching, security hardening, decommission) and coordinating offshore contractors.
Key Responsibilities
- Architect and continuously improve endpoint management using Microsoft Intune and SCCM/MEMCM (co-management/cloud-only).
- Define baselines, enrollment profiles, compliance policies, and conditional access rules; drive Autopilot/Intune-only/co-management modernization.
- Own Patch Tuesday planning and ring-based deployment; manage WSUS/SUP, Intune Update Rings, Windows Autopatch; remediate critical/high vulnerabilities within SLO windows; maintain patch runbooks/escalation.
- Enforce CIS Benchmark Level 1/2 via Intune/SCCM; deploy/configure Microsoft Defender for Endpoint (onboarding, ASR, tamper protection, TVM) and report/track compliance drift; tune Intune compliance/conditional access for Zero Trust.
- Develop and peer-review PowerShell automation; use Graph API/Intune PowerShell SDK; maintain Git-based repositories and testing/documentation.
- Lead application packaging (Intune Win32, MSI/EXE/MSIX repackaging, SCCM packages/task sequences), standards, testing, catalog hygiene, and vendor coordination.
- Lead/QA offshore contractors (tasking, sprint planning, mentorship), SLAs/runbooks, stand-ups/KT, and backlog prioritization.
Required Qualifications
- 7+ years Windows endpoint management at enterprise scale (10,000+ endpoints).
- Experience managing globally distributed fleets.
- 3+ years leading/ coordinating technical teams (offshore/nearshore).
Must-Have Skills
- Microsoft Intune (enrollment, profiles, compliance, app deployment, update rings; co-management/tenant attach).
- SCCM/MEMCM (site design, deployment, task sequences, OSD, software update mgmt, SSRS; Intune migration preferred).
- Advanced PowerShell (Microsoft.Graph, AD, Windows mgmt; error handling/logging).
- App packaging (IntuneWinAppUtil, repackaging, silent installs, detection/dependencies).
- CIS Benchmarks.
- Microsoft Defender for Endpoint (deployment at scale; Sentinel/SIEM integration).
Strong Plus
- Autopatch/Autopilot pre-provisioning; Entra ID conditional access.
- Endpoint Analytics reporting workbooks; ITSM (ServiceNow); Sentinel/Defender XDR; ITIL.
Preferred
- MD-102, SC-200; regulated-industry compliance; other endpoint security tools; mixed-OS exposure; license/asset management.
- Lead global Windows endpoint management for ~50,000 devices worldwide, owning the full lifecycle (provisioning/config, monthly patching, security hardening, decommission) and coordinating offshore contractors.
Key Responsibilities
- Architect and continuously improve endpoint management using Microsoft Intune and SCCM/MEMCM (co-management/cloud-only).
- Define baselines, enrollment profiles, compliance policies, and conditional access rules; drive Autopilot/Intune-only/co-management modernization.
- Own Patch Tuesday planning and ring-based deployment; manage WSUS/SUP, Intune Update Rings, Windows Autopatch; remediate critical/high vulnerabilities within SLO windows; maintain patch runbooks/escalation.
- Enforce CIS Benchmark Level 1/2 via Intune/SCCM; deploy/configure Microsoft Defender for Endpoint (onboarding, ASR, tamper protection, TVM) and report/track compliance drift; tune Intune compliance/conditional access for Zero Trust.
- Develop and peer-review PowerShell automation; use Graph API/Intune PowerShell SDK; maintain Git-based repositories and testing/documentation.
- Lead application packaging (Intune Win32, MSI/EXE/MSIX repackaging, SCCM packages/task sequences), standards, testing, catalog hygiene, and vendor coordination.
- Lead/QA offshore contractors (tasking, sprint planning, mentorship), SLAs/runbooks, stand-ups/KT, and backlog prioritization.
Required Qualifications
- 7+ years Windows endpoint management at enterprise scale (10,000+ endpoints).
- Experience managing globally distributed fleets.
- 3+ years leading/ coordinating technical teams (offshore/nearshore).
Must-Have Skills
- Microsoft Intune (enrollment, profiles, compliance, app deployment, update rings; co-management/tenant attach).
- SCCM/MEMCM (site design, deployment, task sequences, OSD, software update mgmt, SSRS; Intune migration preferred).
- Advanced PowerShell (Microsoft.Graph, AD, Windows mgmt; error handling/logging).
- App packaging (IntuneWinAppUtil, repackaging, silent installs, detection/dependencies).
- CIS Benchmarks.
- Microsoft Defender for Endpoint (deployment at scale; Sentinel/SIEM integration).
Strong Plus
- Autopatch/Autopilot pre-provisioning; Entra ID conditional access.
- Endpoint Analytics reporting workbooks; ITSM (ServiceNow); Sentinel/Defender XDR; ITIL.
Preferred
- MD-102, SC-200; regulated-industry compliance; other endpoint security tools; mixed-OS exposure; license/asset management.