Systems Engineer – Endpoint & Cloud Integration

Apex Fintech SolutionsAustin, TX
Hybrid

About The Position

Apex Fintech Solutions is seeking a Systems/Integration Engineer to manage the connections between their endpoints, identity platform, and cloud infrastructure. This role involves designing and implementing integrations across AWS WorkSpaces, Microsoft Intune, Kandji, Apple Business Manager, Entra ID, and Conditional Access. The primary goal is to replace outdated Group Policy dependencies with modern, cloud-native, policy-as-code management, ensuring all processes are automated and reproducible.

Requirements

  • Bachelor’s degree in Computer Science or related technical discipline (or equivalent work experience) required
  • 2+ years in systems/endpoint engineering, including hands-on administration of both a modern MDM (Intune, plus Kandji or Jamf Pro) and AWS infrastructure.
  • Deep, hands-on Microsoft Intune expertise: compliance policies, configuration profiles, app protection/app config policies, Autopilot, Scope Tags, RBAC (built-in and custom roles).
  • Kandji or Jamf Pro administration (Blueprints/policies, Library Items/config profiles, Liftoff or equivalent zero-touch enrollment).
  • Apple Business Manager (ABM): DEP, VPP, device assignment, MDM server integration.
  • Hands-on Group Policy (GPO) experience and proven experience migrating GPO logic to cloud-native MDM/compliance policy equivalents.
  • Entra ID (Azure AD) administration: users/groups, dynamic groups, app registrations, enterprise apps, hybrid identity.
  • Conditional Access policy design and troubleshooting (sign-in logs, what-if tool, break-glass account practices).
  • RBAC design across Microsoft and AWS environments — custom roles, least privilege, scoped administration.
  • AWS WorkSpaces provisioning, directory integration (AWS Directory Service / AD Connector), and related networking.
  • Infrastructure as Code: Terraform, Ansible, and/or AWS CloudFormation, used for all provisioned infrastructure.
  • Git-based version control and CI/CD pipeline familiarity (GitHub Actions, Azure DevOps, or similar).
  • Scripting proficiency: PowerShell, Python, Shell, Microsoft Graph API.
  • Solid understanding of Windows and macOS device architecture, authentication protocols (Kerberos, SAML, OAuth/OIDC), and certificate-based auth (SCEP/PKCS).
  • Strong documentation habits and ability to communicate technical tradeoffs to both engineering and non-technical stakeholders.
  • Linux and macOS administration expertise — command-line fluency, shell scripting, and system-level troubleshooting beyond GUI-based management.

Nice To Haves

  • Microsoft certifications (MS-102 Endpoint Administrator, SC-300 Identity and Access Administrator, AZ-500).
  • Apple certifications (Apple Certified Support Professional / Apple Deployment and Management).
  • AWS certifications (Solutions Architect, SysOps Administrator).
  • Experience with Okta or other third-party IdPs alongside Entra ID.
  • Experience with security frameworks/benchmarks (CIS, NIST) as applied to endpoint compliance baselines.
  • ServiceNow or similar ITSM tooling for change management and automation triggers.

Responsibilities

  • Own and maintain integrations between AWS WorkSpaces and on-prem/cloud identity (Entra ID, AD Connect/Cloud Sync).
  • End-to-end Intune administration, including compliance policies, configuration profiles, app deployment, Autopilot/Windows enrollment, Scope Tags, and RBAC design across business units.
  • Manage the Apple device lifecycle via Kandji + Apple Business Manager (ABM), covering DEP enrollment, supervised device policies, app deployment, and zero-touch provisioning.
  • Design and enforce Conditional Access policies in Entra ID (device compliance, location, risk-based sign-in, session controls) in collaboration with security/identity teams.
  • Collaborate with the team on migrating legacy Group Policy Objects (GPOs) to Intune/Entra-based configuration and compliance policies, including translating GPO logic and documenting gaps.
  • Build and maintain RBAC models across Intune, Entra ID, and AWS (least-privilege scoped admin roles, custom roles, Scope Tag-based delegation).
  • Write and maintain AWS Lambda functions to automate device lifecycle events, cross-platform sync (e.g., Kandji ↔ Intune ↔ Entra ↔ WorkSpaces), reporting, and remediation workflows.
  • Build all infrastructure using Infrastructure as Code (Terraform, Ansible, and/or CloudFormation), ensuring no manual console changes for reproducible elements, managed through version control with peer review.
  • Develop automation/scripting for endpoint and identity workflows (PowerShell, Python, Microsoft Graph API).
  • Implement and maintain MDM solutions for BYOD devices for Windows/Mac/Linux/Android devices.

Benefits

  • healthcare benefits (medical, dental and vision, EAP)
  • competitive PTO
  • 401k match
  • parental leave
  • HSA contribution match
  • paid subscription to the Calm app
  • generous external learning and tuition reimbursement benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service