Lead Desktop Engineer

T. Rowe PriceOwings Mills, MD
Hybrid

About The Position

At T. Rowe Price, we identify and actively invest in opportunities to help people thrive in an evolving world. As a premier global asset management organization with more than 85 years of experience, we provide investment solutions and a broad range of equity, fixed income, and multi-asset capabilities to individuals, advisors, institutions, and retirement plan sponsors. We take an active, independent approach to investing, offering our dynamic perspective and meaningful partnership so our clients can feel more confident. We believe doing the right thing for our clients and our associates is good business. With a career at the firm, you can expect opportunities to create real impact at work and in your community. You’ll enjoy resources to support your career path, as well as compensation, benefits, and flexibility to enrich your life. Here, you’ll find a collaborative culture that respects and values differences and colleagues who share a spirit of generosity. Join us for the opportunity to grow and make a difference in ways that matter to you. Role Summary We are seeking a Lead Desktop Engineer to own the technical direction, operational health, and security posture of our endpoint environment across approximately 14,000 managed devices. This role serves as the senior technical authority for endpoint engineering, operations, and security, ensuring a secure, stable, and well-governed end-user computing platform in a regulated enterprise environment. The Lead Desktop Engineer is accountable for endpoint compliance, vulnerability remediation, configuration standards, and high-risk technical decision-making. This role partners closely with Security, Infrastructure, Risk, and Audit teams to reduce operational risk, maintain audit readiness, and ensure consistent execution of endpoint controls.

Requirements

  • BS/MS degree or equivalent experience, with 8+ years in endpoint engineering, EUC, or desktop platform management in a large enterprise.
  • Deep hands-on expertise with Intune, MECM/SCCM, Microsoft Defender, Entra ID, and Windows endpoint security controls.
  • Strong experience in regulated environments such as financial services, healthcare, or similar industries.
  • Proven ownership of endpoint patching, vulnerability remediation, OS lifecycle, and compliance controls at scale.
  • Demonstrated experience serving as the technical decision-maker for high-risk or high-impact changes.
  • Strong understanding of Zero Trust, device posture, and conditional access.
  • Excellent troubleshooting and root cause analysis skills.

Nice To Haves

  • Experience supporting environments with 10,000+ endpoints.
  • Familiarity with audit, risk, and compliance frameworks related to endpoint controls.
  • Experience driving automation and standardization through PowerShell, policy-as-code, reporting, or similar capabilities.
  • Strong communication skills with the ability to engage security, audit, and senior leadership stakeholders.

Responsibilities

  • Lead endpoint engineering, operations, and security across ~14,000 devices.
  • Own the endpoint management ecosystem, including Intune, MECM/SCCM, Microsoft Defender, Entra ID, and related tools.
  • Define and maintain endpoint architecture, configuration baselines, and OS lifecycle standards aligned to security and regulatory requirements.
  • Own endpoint health and compliance, including patching, OS upgrades, configuration baselines, device posture, and conditional access.
  • Serve as the decision authority for high-risk endpoint changes, including patching, policy updates, and security remediations.
  • Ensure timely vulnerability remediation in line with firm SLAs and maintain audit readiness.
  • Enforce secure baseline configurations and compliance controls across managed endpoints.
  • Partner with Security and Vulnerability Management teams to plan and execute remediation activities.
  • Ensure endpoint controls and processes are measurable, auditable, and defensible.
  • Act as the escalation point for complex or high-impact endpoint incidents, driving root cause analysis and corrective action.
  • Improve operational efficiency through automation, standardization, and reduction of manual processes.
  • Drive consistency, reliability, and scale through policy-driven management and modern endpoint practices.
  • Identify opportunities to modernize endpoint engineering tools and processes while maintaining compliance.
  • Provide technical leadership and mentorship within the endpoint engineering team.
  • Partner with support, infrastructure, identity, security, risk, and audit teams to ensure clear ownership and effective execution.
  • Translate technical risks and trade-offs into actionable recommendations for leadership.

Benefits

  • Competitive compensation
  • Annual bonus eligibility
  • A generous retirement plan
  • Hybrid work schedule
  • Health and wellness benefits, including online therapy
  • Paid time off for vacation, illness, medical appointments, and volunteering days
  • Family care resources, including fertility and adoption benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service