Microsoft Intune System Administrator

Govcio LLCUNAVAILABLE, UNAVAILABLE
Remote

About The Position

We are looking for an experienced Microsoft Intune Systems Administrator to manage and modernize our multi-platform endpoint ecosystem for our HUD contract. In this role, you will design, deploy, and maintain zero-touch device enrollment, configuration profiles, compliance policies, and app packaging across Windows, macOS, and iOS/iPadOS devices. The ideal candidate has hands-on technical expertise in unified endpoint management (UEM), Apple Business Manager (ABM), Windows Autopilot, and cloud-first security baselines. This position will be located within the United States and is fully remote.

Requirements

  • Bachelor's with 12+ years of system administration experience (or commensurate experience)
  • 3–5+ years in Enterprise Endpoint Management, with at least 2+ years dedicated to Microsoft Intune / Endpoint Manager
  • Hands-on experience integrating Apple Business Manager (ABM) with Intune, VPP app management, FileVault management, and running Bash scripts on macOS.
  • Experience with Windows Autopilot, BitLocker, PowerShell scripting, Win32 app packaging (IntuneWin App Prep Tool), and AD/Entra ID integration
  • Strong knowledge of Microsoft Entra ID (Azure AD), Conditional Access, RBAC, and Endpoint Security baselines
  • Experience configuring iOS/iPadOS devices, Supervision, App Protection Policies (MAM without enrollment), and Company Portal deployment
  • Ability to maintain a HUD Public Trust clearance

Nice To Haves

  • JAMF knowledge preferred

Responsibilities

  • Configure and maintain zero-touch onboarding for all platforms: Windows Autopilot, Apple Automated Device Enrollment (ADE) via Apple Business Manager (ABM), and iOS/iPadOS enrollment
  • Manage macOS configuration profiles, mobile device management (MDM) payloads, and shell scripts (Bash) for custom settings and elevated controls
  • Define and manage Windows baseline policies, administrative templates, PowerShell scripts, and Remediation scripts
  • Package, test, and deploy applications across all platforms (Win32, LOB, Microsoft Store, macOS PKG/DMG files, and iOS App Store / VPP volume licensing)
  • Maintain patching schedules and automated software update workflows for Windows, macOS, and mobile apps
  • Implement Conditional Access policies, App Protection Policies (MAM), and Compliance Policies linked with Microsoft Defender for Endpoint
  • Manage disk encryption standards across platforms (BitLocker for Windows, FileVault for macOS)
  • Configure identity integrations, Single Sign-On (SSO), and Platform SSO for macOS endpoints
  • Act as Tier 3 escalation for endpoint-related technical issues across Windows, Mac, and mobile fleets
  • Monitor tenant health, device compliance failures, sync errors, and security vulnerabilities; remediate non-compliant assets promptly
  • Maintain accurate technical documentation, enrollment guides, and end-user self-service instructions
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service