M365 Endpoint and Identity Administrator

SOLV EnergySan Diego, CA
$110,703 - $132,843Hybrid

About The Position

The M365 Endpoint & Identity Administrator is responsible for managing and maintaining the design, configuration, and operational integrity of SOLV Energy’s Microsoft Intune environment and the broader Microsoft 365 platform (Entra ID, Teams, SharePoint, OneDrive). This role owns Mobile Device Management (MDM), endpoint patch management, and configuration policy authoring across the Windows and macOS and is accountable for executing all endpoint changes through SOLV Energy’s formal IT change management process. This role is hybrid with regular in office presence in San Diego, CA, Edison, NJ or Bend, OR. Specific location details and expectations will be discussed during the interview process.

Requirements

  • Bachelor’s degree in Information Technology, Computer Science, or equivalent experience
  • 5 years minimum experience as a M365 System Administrator or equivalent combination of experience and education
  • Knowledge of major Microsoft cloudbased systems including Entra ID, M365, InTune, AutoPilot, Enterprise Mobility + Security, Defender ATP, etc.
  • Powershell scripting and automation
  • Hands-on experience with endpoint patch management, including Windows Autopatch, Intune update policies, and third-party patching tools (e.g., Patch My PC)
  • Familiarity with ITIL-based change management processes, including CAB submissions, risk assessments, and rollback planning
  • Experience with Freshservice for incident, change, and request management
  • Experience supporting M&A or tenant migration projects in a Microsoft 365 environment is a plus
  • Customer escalation and conflict resolution skills required
  • Resource planning and mitigation management
  • Excellent verbal and written communication skills
  • Energetic, enthusiastic, charismatic
  • Entrepreneurial spirit
  • Applicants must be legally authorized to work in the U.S. without requiring employer sponsorship now or in the future.

Responsibilities

  • Own the configuration, health, and roadmap of Microsoft Intune as SOLV Energy’s primary MDM platform, including device enrollment, compliance policies, configuration profiles, and endpoint security baselines across Windows and macOS
  • Author and maintain Intune configuration profiles, security baselines, and Settings Catalog policies, including Defender for Endpoint, BitLocker, FileVault, Attack Surface Reduction rules, tamper protection, and account lockout
  • Design and operate Windows Autopilot deployment profiles, Enrollment Status Page configuration, Autopilot device groups, and Entra-joined provisioning workflows for new and re-provisioned endpoints
  • Manage macOS enrollment, configuration, and compliance through Intune, including FileVault and device-pinned Conditional Access scenarios for managed and contractor-owned hardware
  • Build and maintain Intune application deployment packages, including detection rules, requirement rules, assignment scoping, and supersedence relationships
  • Own the enterprise endpoint patch management program across Windows (Microsoft Autopatch / Intune update rings) and macOS (Intune update policies), including ring design, pilot testing, production rollouts, deferral policies, and compliance reporting
  • Manage third-party application patching through Patch My PC (PMPC) Cloud, including publishing critical applications, enforcing automatic updates, configuring user-context vs system-context deployments, and triaging/remediating patch failures
  • Lead Conditional Access policy design and operation in partnership with Cybersecurity, including device-compliance, app-protection, sign-in risk, and named-location policies
  • Drive CVE remediation efforts for endpoints, including OS, driver, and firmware updates (e.g., Dell ControlVault, Dell Command Update, Apple Rapid Security Response), in coordination with Cybersecurity on vulnerability prioritization
  • Build and maintain executive-level patch compliance, device posture, and Intune health dashboards to support leadership visibility, SOX ITGC evidence, and audit readiness
  • Author and submit change management requests in Freshservice for all endpoint configuration, policy, and patching changes, including risk assessment, test evidence, rollback plan, and communication plan
  • Participate in the Change Advisory Board (CAB), presenting changes for review and securing approval prior to any production deployment.
  • Pilot all Intune policy, Autopilot profile, and patch ring changes against a defined test group before broad release; validate rollback procedures
  • Develop and maintain PowerShell and Microsoft Graph automation for Intune reporting, policy auditing, bulk device operations, and lifecycle tasks
  • Collaborate with Cybersecurity, Infrastructure, and Service Desk teams to maintain a secure, compliant, and supportable end-user computing environment
  • Develop and maintain SOPs and runbooks for recurring operational processes such as Windows feature updates, monthly patch cycles, Autopilot onboarding, macOS enrollment, and incident response for endpoint outages
  • Support M&A integration activities for the Microsoft 365 and endpoint workstream, including tenant migrations, Intune policy alignment, and Autopilot onboarding for acquired entities
  • Monitor and respond to outages, trends, and global issues affecting the Microsoft 365 stack and managed endpoint fleet
  • Stay current on Microsoft Intune, Entra ID, Defender for Endpoint, and modern endpoint management roadmaps, evaluating new capabilities for fit within SOLV Energy’s environment

Benefits

  • medical
  • dental
  • vision
  • basic life and disability insurance
  • 401(k) plan
  • vacation
  • sick and holiday pay
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service