Staff Endpoint Engineer - Desktop

Marvell TechnologySanta Clara, CA
$88,110 - $132,000

About The Position

The Staff Endpoint Engineer is a seasoned endpoint expert who owns the design, deployment, and support of Marvell's endpoint estate, with Windows and mobile device management as co-primary responsibilities and macOS, enterprise print, VDI, and Linux as secondary responsibilities. Drawing on specialized depth and breadth of expertise, the professional sets endpoint standards and baselines, drives complex cross-platform initiatives, anticipates and prevents issues, and is recognized as a go-to expert within the endpoint engineering team or department. Beyond hands-on engineering, the professional applies innovative solutions to complex problems, mentors less-experienced staff, and partners with security, identity, networking, and service delivery to shape how endpoints are managed enterprise-wide. Works independently and receives guidance only in the most complex situations.

Requirements

  • Bachelor's degree in Business, Science, Arts, or a related field and 3-5 years of related professional experience; or a Master's degree and/or PhD with 2-3 years; including substantial hands-on endpoint engineering experience
  • Deep, hands-on Windows endpoint engineering with SCCM and Intune co-management (application deployment, OS imaging, patch management)
  • Deep, hands-on mobile device management with Intune across MDM and MAM (iOS and Android enrollment, app protection, compliance, lifecycle). Windows and mobile depth are both required; this is a co-primary role, not Windows with light mobile exposure
  • Experience with zero-touch provisioning: Windows Autopilot and mobile automated enrollment (Apple ADE, Android Enterprise)
  • Proficiency in PowerShell for automation, remediation, and reporting
  • Software packaging and deployment for Windows (MSI, MSIX, Win32) and mobile applications
  • Experience with Nexthink or a comparable DEX platform
  • Solid understanding of Active Directory, Group Policy, endpoint security baselines, and identity-aware access (Conditional Access)
  • Working knowledge across the secondary domains (macOS and Jamf, print, VDI, Linux) with the willingness to own them
  • Works independently and receives guidance only in the most complex situations; drives complex projects requiring an in-depth evaluation of variable factors to predict problems and recommend innovative solutions; acts as a team lead who coordinates the activities of other team members; leads major incidents; and mentors less-experienced engineers

Nice To Haves

  • Microsoft 365 Certified: Administrator Expert (Expert-tier; the senior target for this role), built on the Endpoint Administrator Associate (MD-102) foundation
  • Jamf certification (Jamf Certified Tech or Admin); enterprise mobility credentials (Apple Business Manager, Android Enterprise)
  • Experience managing a globally distributed Windows and mobile fleet at enterprise scale
  • Familiarity with the surrounding stack: ServiceNow (CMDB and ITSM), CrowdStrike Falcon, Okta and Entra, Qualys, and enterprise print (Printix)
  • Scripting and automation beyond PowerShell (Bash, Python); mobile threat defense (MTD); VDI (Citrix, VMware Horizon, or Azure Virtual Desktop); RHCSA; CompTIA Security+; ITIL Foundationv4
  • Experience supporting semiconductor, manufacturing, lab, or regulated-industry environments

Responsibilities

  • Design, configure, and maintain Windows endpoint management through SCCM and Intune co-management, including application deployment, OS imaging, and patch management
  • Own mobile device management through Intune (iOS and Android), covering MDM and MAM, app protection, enrollment programs (Apple Business Manager, Android Enterprise), and the full device lifecycle across corporate and BYOD
  • Lead zero-touch provisioning across the fleet: Windows Autopilot and mobile automated enrollment
  • Develop and maintain enterprise application packages (MSI, MSIX, Win32) and mobile application deployments
  • Support macOS management through Jamf Pro, including Apple Business Manager enrollment, configuration profiles, and security baselines
  • Support and help modernize enterprise print (Printix, MFP fleet, print servers), VDI provisioning and endpoint support, and the Linux endpoint estate (RHEL and Ubuntu; patching, hardening, 802.1x EAP-TLS)
  • Set endpoint standards, baselines, and OS lifecycle and patch strategy across platforms, leading with Windows and mobile
  • Manage device compliance, conditional access, and security baselines; integrate endpoint security tooling (CrowdStrike Falcon) and support vulnerability posture (Qualys); partner with identity on Okta and Entra
  • Use Nexthink (DEX) to proactively detect and resolve endpoint health issues, and define and report endpoint KPIs that drive continuous improvement
  • Automate configuration, remediation, and reporting with PowerShell, and with Bash or Python for macOS and Linux
  • Own runbooks, SOPs, and knowledge management; drive continuous service improvement and predict and prevent recurring issues
  • Serve as the senior escalation point for complex endpoint issues, and mentor earlier-career engineers as a recognized domain expert

Benefits

  • employee stock purchase plan with a 2-year look back
  • family support programs
  • robust mental health resources
  • recognition and service awards
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service