Endpoint Engineer, Technology & Security

Oaktree Capital Management, L.P.Los Angeles, CA
$125,000 - $160,000Hybrid

About The Position

Oaktree is seeking a highly motivated and technical Endpoint Engineer to support the Information Security team at Oaktree. This role involves owning and continuously improving the modern endpoint management platform, managing the full Windows endpoint lifecycle, and leading the transition from SCCM/MECM and Group Policy–based management to modern, cloud-native endpoint management. The engineer will leverage AI-assisted tools and automation to enhance endpoint engineering, monitoring, troubleshooting, reporting, and operational consistency. Key responsibilities include designing and implementing Intune configurations, supporting various Microsoft Entra joined device scenarios, developing standardized processes for device management, implementing endpoint security controls, packaging and deploying applications, and planning OS migrations. The role also involves acting as an escalation point for complex endpoint issues, participating in incident response, and maintaining documentation. Collaboration with various internal teams is essential for delivering endpoint initiatives and supporting audits and modernization projects.

Requirements

  • 5+ years of relevant experience
  • Strong troubleshooting skills across Windows OS, device enrollment, endpoint policy, application deployment, network connectivity, certificates, user profiles, and endpoint security controls.
  • Ability to write clear technical documentation and communicate effectively with technical and non-technical stakeholders.

Nice To Haves

  • Microsoft certifications such as Microsoft 365 Certified: Endpoint Administrator Associate, Azure Administrator Associate, or related Microsoft security and identity certifications.
  • Experience migrating from SCCM/GPO-based environments to Microsoft Intune and modern endpoint management.
  • Experience with Microsoft Entra Conditional Access, device compliance, Zero Trust, and Microsoft Defender for Endpoint.
  • Experience managing Apple Business Manager, macOS, iOS/iPadOS, and Android devices through Intune.
  • Experience with enterprise application packaging and deployment, including Win32, MSI/MSIX, detection rules, dependencies, and deployment rings.
  • Experience supporting Windows Hello for Business, Cloud Kerberos Trust, Universal Print, VPN, virtual desktop/Citrix environments, and line-of-business applications.
  • Experience using AI-assisted tools (e.g., Microsoft Copilot or Security Copilot) to improve endpoint automation, troubleshooting, reporting, and documentation.
  • Strong endpoint engineering mindset with the ability to design for scale, reliability, security, and operational simplicity.
  • Ability to modernize legacy endpoint practices while maintaining business continuity.
  • Strong analytical and troubleshooting skills.
  • Security-first mindset with practical understanding of user experience and operational supportability.
  • Ability to work independently while collaborating across multiple technical teams.
  • Strong documentation discipline and process orientation.

Responsibilities

  • Own and continuously improve the modern endpoint management platform, including Microsoft Intune, Windows Autopilot, Microsoft Entra ID, and related technologies.
  • Manage the full Windows endpoint lifecycle, including provisioning, enrollment, configuration, compliance, application deployment, patching, OS upgrades, troubleshooting, and retirement.
  • Lead the transition from SCCM/MECM and Group Policy–based management to modern, cloud-native endpoint management, including decommissioning legacy infrastructure.
  • Leverage AI-assisted tools and automation to improve endpoint engineering, monitoring, troubleshooting, reporting, and operational consistency.
  • Design, implement, and optimize Intune configuration profiles, compliance and security policies, application deployments, update rings, remediation scripts, and enrollment profiles.
  • Support Microsoft Entra joined, hybrid-joined, co-managed, and cloud-native device management scenarios.
  • Develop standardized processes for device provisioning, refresh, rebuilds, feature updates, and hardware lifecycle management.
  • Implement and maintain endpoint security controls, including BitLocker, Microsoft Defender, Windows LAPS, Windows Hello for Business, firewall policies, attack surface reduction rules, and security baselines.
  • Configure and monitor compliance policies to ensure devices meet organizational security requirements.
  • Package, deploy, test, and support applications using Intune, Win32 app deployment, Microsoft Store, PowerShell, and enterprise software distribution tools.
  • Plan and execute Windows feature updates and OS migrations, including readiness assessments, pilot deployments, issue remediation, reporting, and production rollouts.
  • Develop scripts, detection rules, remediation packages, and automation to improve operational efficiency.
  • Act as the escalation point for complex endpoint issues involving Windows, Intune, Autopilot, SCCM, application deployment, compliance, authentication, and device management.
  • Diagnose and resolve issues using endpoint logs, Intune reporting, Autopilot diagnostics, PowerShell, Event Viewer, SCCM client logs, and Entra device records.
  • Participate in incident response, change management, root cause analysis, and continuous service improvement.
  • Maintain documentation for endpoint architecture, standards, policies, deployment processes, application packaging, and support procedures.
  • Partner with Security, Identity, Infrastructure, Networking, Procurement, and Service Desk teams to deliver endpoint initiatives.
  • Support audits, compliance efforts, risk assessments, and endpoint modernization projects.

Benefits

  • discretionary bonus incentives
  • comprehensive benefits package
  • flexible work arrangement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service