Senior Endpoint Engineer

ASM Research•Washington, DC
•Hybrid

About The Position

This role defines the target state for how FERC devices are provisioned, managed, secured, and supported, and leads the engineering work to get there. The central mission is modernization: moving the fleet from a ConfigMgr-centric, on-premises model to a cloud-native model built on Microsoft Intune, Entra ID, Windows Autopilot, and Windows Autopatch, aligned to federal Zero Trust requirements. The architect owns the roadmap, the design decisions, and the reference standards for that transition, while remaining hands-on with ConfigMgr, Intune, Dell enterprise tooling, and BeyondTrust. The position is an individual contributor with no supervisory duties. It leads through technical direction: setting standards, reviewing designs and changes, guiding engineers, and advising program leadership on endpoint risk, investment, and sequencing. Work is tracked in ServiceNow (operations and change) and Azure DevOps (ADO) Boards (roadmap, epics, and engineering backlog).

Requirements

  • Bachelor's degree in Information Technology, Computer Science, or a related field, or 12+ years of relevant experience in lieu of a degree
  • 8+ years of enterprise Windows endpoint management experience, including 2+ years leading the design of significant endpoint initiatives.
  • Ability to obtain and maintain a Public Trust determination; CompTIA Security+ held at start or earned within 90 days; on site in Washington, DC, at least 2 days per week.
  • Hands-on experience with both ConfigMgr and Microsoft Intune, including co-management, and has moved at least one workload or device population from ConfigMgr to Intune.
  • Has designed and deployed Windows Autopilot for production users in at least one deployment mode.
  • PowerShell scripting skills for automation; able to read and adapt scripts that use the Microsoft Graph API.
  • Ability to write clear design documents, diagrams, and SOPs that other engineers can carry out.
  • Experience with incidents, problems, and change requests in ServiceNow or a comparable ITSM tool.

Nice To Haves

  • Experience with Windows Update for Business or Windows Autopatch, Intune Remediations, and Endpoint Analytics.
  • Working knowledge of Entra ID, Conditional Access, and device compliance in a Zero Trust model.
  • SQL and KQL skills for querying ConfigMgr, Intune, and endpoint telemetry data.
  • Experience delivering endpoint work in a federal environment under FISMA, NIST SP 800-53, and CISA directives, including Microsoft government cloud environments.
  • Hands-on experience with Dell enterprise tooling, such as Dell Command | Update, Dell Command | Configure, and BIOS and Secure Boot management.
  • Experience with BeyondTrust or a comparable privileged access or remote support platform.
  • Experience with Microsoft Defender for Endpoint, Windows LAPS, or Azure DevOps Boards.
  • Certifications such as Microsoft MD-102, MS-102, SC-300, or ITIL 4 Foundation (not required).

Responsibilities

  • Define and maintain the endpoint target-state architecture covering identity, provisioning, configuration, application delivery, update management, security, and support tooling.
  • Own the multi-year endpoint modernization roadmap, with phases, dependencies, entry and exit criteria, and risk for each phase.
  • Produce architecture artifacts: current- and target-state diagrams, design documents, architecture decision records (ADRs), and reference configurations.
  • Evaluate new Microsoft and vendor capabilities, run proofs of concept, and recommend adoption, deferral, or retirement with cost, risk, and effort analysis.
  • Define the user persona model, and set endpoint engineering standards for naming, policy design, assignment and filtering, app packaging, and baseline management, and enforce them through design and change review.
  • Advise program leadership on endpoint risk, technical debt, licensing, and investment priorities.
  • Lead the transition from ConfigMgr to Intune, moving co-management workloads to Intune in planned waves using pilot groups and defined success criteria.
  • Design and drive the move from hybrid join toward Entra ID join and zero-touch provisioning with Windows Autopilot, as described in the Windows Autopilot section.
  • Modernize update management with Windows Update for Business and Windows Autopatch, including ring design, quality and feature update policy, and driver and firmware update policy.
  • Move application delivery to Intune Win32 apps and catalog-based app management, and retire legacy packages and deployment methods.
  • Replace on-premises dependencies with cloud services where approved, such as Windows LAPS, cloud-based certificate delivery, and Intune Remediations in place of ConfigMgr scripts and baselines.
  • Plan the reduction and eventual decommissioning of ConfigMgr infrastructure, keeping only the services the roadmap still requires.
  • Coordinate cutovers with the imaging, identity, network, security, and service desk teams, with tested rollback plans for each wave.
  • Act as senior escalation point for ConfigMgr, Intune, co-management, Autopilot, and Windows 11 client issues; resolve complex problems end to end.
  • Design endpoint security configuration to meet NIST SP 800-53 controls, Microsoft security baselines, and applicable DISA STIG or CIS benchmarks.
  • Support the program's Zero Trust work by defining device compliance signals for Entra Conditional Access, in partnership with the identity and security teams who own those policies.
  • Build automation in PowerShell and the Microsoft Graph API for provisioning, configuration, compliance checks, and reporting.
  • Develop KQL queries, SQL queries, and dashboards (SSRS, Power BI, or Intune and Endpoint Analytics reports) for operations, compliance, and leadership audiences.
  • Define and report modernization metrics, such as share of devices on the target-state model, workloads moved, and legacy components retired.
  • Analyze endpoint data to find trends, compliance gaps, and recurring failures, and turn findings into engineering fixes.
  • Author and present change requests at the Change Advisory Board (CAB) for architecture-level and high-risk endpoint changes, and review changes submitted by other engineers.
  • Plan and track roadmap work in ADO Boards as epics, features, and stories, linked to related ServiceNow records.
  • Write and maintain SOPs, runbooks, and ServiceNow knowledge articles for new target-state processes, and hand off steady-state operations to the support teams.
  • Mentor engineers through design reviews, pairing, and walkthroughs, and build the team's skills in Intune, Graph, and cloud-native endpoint management.
  • Other duties as assigned within endpoint management.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service