Lead Engineer - Endpoint

Frontier AirlinesDenver, CO
$110,114 - $150,000Hybrid

About The Position

The Lead Endpoint, Identity & Microsoft 365 Administrator is responsible for the architecture, engineering, security, administration, and continuous improvement of the enterprise endpoint, identity, and Microsoft 365 ecosystems. This role provides technical leadership for endpoint management, identity services, collaboration platforms, and cybersecurity initiatives that support a secure, resilient, and compliant hybrid (Cloud & On-prem) technology environment. The position serves as the subject matter expert for endpoint device management, Microsoft 365 administration, Entra ID (Azure AD), identity governance, authentication technologies, device security, and endpoint security architecture. Additionally, the role is responsible for identifying, recommending, and implementing cybersecurity best practices that strengthen the organization’s overall security posture and reduce operational risk. The Lead Engineer partners closely with Cybersecurity, Infrastructure, Service Desk, Cloud Engineering, and business stakeholders to ensure enterprise technologies align with security standards, regulatory requirements, and business objectives. This role is responsible for administering Active Directory, Microsoft Entra ID, Microsoft Intune, ManageEngine Endpoint Central, Zscaler ZIA/ZPA, Microsoft 365, and Exchange Online. The successful candidate will support user identity lifecycle processes, endpoint enrollment and compliance, device patching, application deployment, secure internet and private application access, mail administration, and Microsoft 365 services. This position requires strong troubleshooting skills, security awareness, documentation discipline, and the ability to collaborate effectively with infrastructure, cybersecurity, networking, and service desk teams.

Requirements

  • Bachelor’s degree in Computer Science, Information Technology, or related field or equivalent combination of education and experience required.
  • At least 7 years of experience in enterprise endpoint management, identity administration, Microsoft 365 administration, or related infrastructure operations.
  • Hands-on experience supporting hybrid identity environments using Active Directory and Microsoft Entra ID.
  • Experience configuring and supporting Microsoft Intune, endpoint compliance, device enrollment, application deployment, and patch management.
  • Experience with ManageEngine Endpoint Central or similar endpoint patching and device management platforms strongly preferred.
  • Experience supporting Zscaler ZIA/ZPA, client connectors, secure internet access, and private application access preferred.
  • Experience administering Microsoft 365 services and Exchange Online, including mailbox management, mail flow, permissions, and collaboration services.
  • PowerShell scripting experience for administration, reporting, troubleshooting, and process automation strongly preferred.
  • Relevant certifications such as Microsoft Certified: Endpoint Administrator Associate, Microsoft 365 Certified Administrator, Microsoft Certified: Identity and Access Administrator Associate, JAMF Certified Admin, or similar are a plus.
  • Excellent troubleshooting and problem-solving skills.
  • Strong verbal and written communication skills.
  • Ability to work effectively in a team-oriented environment and collaborate with infrastructure, cybersecurity, networking, and service desk teams.
  • Strong understanding of Active Directory and Microsoft Entra ID administration, including users, groups, service accounts, synchronization concepts, and hybrid identity operations.
  • Knowledge of Conditional Access, Multi-Factor Authentication, identity protection, and secure access best practices.
  • Advanced skills in configuring and managing Microsoft Intune, endpoint enrollment, compliance policies, configuration profiles, and application policies.
  • Proficiency with ManageEngine Endpoint Central or similar tools for patch deployment, software updates, endpoint inventory, and remediation.
  • Knowledge of desktop and mobile operating systems such as Windows, iOS, Android, and macOS.
  • Knowledge of Zscaler ZIA/ZPA, client connector behavior, secure internet access, private application access, and policy troubleshooting.
  • Ability to administer Microsoft 365 services, licensing, collaboration features, service health, and user support processes.
  • Knowledge of mailbox administration, mail flow, shared mailboxes, distribution groups, permissions, and Exchange Online troubleshooting.
  • Familiarity with zero trust principles, endpoint security, identity security, and secure configuration standards.
  • Basic knowledge of networking principles and how they relate to endpoint connectivity, cloud services, VPN-less access, and secure web access.
  • Understanding of compliance standards and regulations related to endpoint, identity, and access management.
  • Ability to use PowerShell for administration, automation, reporting, troubleshooting, and operational support.
  • Strong troubleshooting skills to diagnose and resolve identity, endpoint, secure access, Microsoft 365, and Exchange Online issues.
  • Ability to develop, implement, and maintain endpoint, identity, access, and application policies.
  • Proficiency in deploying software, updates, and patches through Intune, ManageEngine Endpoint Central, or similar platforms.
  • Excellent documentation skills to maintain detailed records of configurations, policies, procedures, and support processes.
  • Strong verbal and written communication skills for effective collaboration and user support.
  • Ability to train and support end users and IT teams on endpoint, identity, secure access, and Microsoft 365 best practices.
  • Ability to analyze complex technical issues and develop effective solutions.
  • High attention to detail to ensure accurate configuration and compliance with policies.
  • Ability to adapt to new technologies and changing environments.
  • Strong ability to work collaboratively with infrastructure, cybersecurity, networking, service desk, and other departments.
  • Effective time management skills to prioritize tasks and meet deadlines.
  • Ability to provide excellent customer service and support to end users.

Nice To Haves

  • Experience with ManageEngine Endpoint Central or similar endpoint patching and device management platforms
  • Experience supporting Zscaler ZIA/ZPA, client connectors, secure internet access, and private application access
  • PowerShell scripting experience for administration, reporting, troubleshooting, and process automation
  • Relevant certifications such as Microsoft Certified: Endpoint Administrator Associate, Microsoft 365 Certified Administrator, Microsoft Certified: Identity and Access Administrator Associate, JAMF Certified Admin, or similar

Responsibilities

  • Manage and support Active Directory and Microsoft Entra ID objects, including users, groups, service accounts, organizational units, attributes, and identity lifecycle processes.
  • Administer and support Conditional Access, Multi-Factor Authentication (MFA), and related identity security controls aligned to zero trust and company security standards.
  • Configure, deploy, and maintain endpoint management capabilities using Microsoft Intune and related MDM/MAM platforms.
  • Manage endpoint enrollment, provisioning, compliance policies, configuration profiles, and device lifecycle processes for Windows, mobile, and other supported platforms.
  • Configure and support Defender for Endpoint.
  • Manage device patching, software updates, and remediation activities using ManageEngine Endpoint Central and Microsoft endpoint management tools.
  • Package, deploy, update, and troubleshoot applications across managed endpoints using Intune, ManageEngine Endpoint Central, and other approved tools.
  • Support Zscaler ZIA/ZPA access policies, client connector deployment, secure internet access, and private application access troubleshooting.
  • Administer Microsoft 365 services, including licensing, collaboration services, service health monitoring, and user support.
  • Support mailbox administration, mail flow, distribution groups, shared mailboxes, permissions, and troubleshooting of Exchange Online issues.
  • Provide advanced technical support for identity, endpoint, secure access, mail, and Microsoft 365 service issues while minimizing business disruption.
  • Implement and maintain endpoint and identity security controls to protect users, devices, applications, and data from threats and vulnerabilities.
  • Use PowerShell and other approved automation methods to improve administration, reporting, remediation, and operational efficiency.
  • Maintain comprehensive documentation of identity, endpoint, access, Microsoft 365, Exchange Online, and operational procedures.
  • Work closely with infrastructure, cybersecurity, networking, service desk, and business teams to align platform administration with organizational goals.
  • Provide guidance and support to IT teams and end users on endpoint, identity, secure access, and Microsoft 365 best practices.
  • Maintain accurate records for endpoint configurations, identity objects, access policies, mail administration, and Microsoft 365 service changes.
  • Adhere to documented Change Management processes to protect the integrity of the production environment.
  • Manage ticket loads and ensure response time SLAs are met for identity, endpoint, access, Microsoft 365, and Exchange Online support requests.
  • Develop and maintain procedures that support consistent, secure, and process-driven resolution of operational issues.

Benefits

  • Flight benefits for you and your family to fly on Frontier Airlines
  • Buddy passes for your friends so they can experience what makes us so great
  • Discounts throughout the travel industry on hotels, car rentals, cruises and vacation packages
  • Discounts on cell phone plans, movie tickets, restaurants, luggage and over 2,000 other vendors
  • Enjoy a ‘Dress for your Day’ business casual environment
  • Flexible work schedules that support work/life balance
  • Total Rewards program including a competitive base salary, short term incentives, long-term incentives, paid holidays, 401(k) plan, vacation/sick time and medical/dental/vision insurance that begins the 1st of the month following your hire date.
  • The HOPE League, Frontier Airlines’ non-profit organization, is dedicated to providing employees financial assistance during catastrophic hardship
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service