Windows Endpoint Automation Engineer

The Vanguard GroupWayne, PA
Hybrid

About The Position

Vanguard is seeking a Windows Endpoint Automation Engineer to lead endpoint automation for provisioning, compliance, remediation, and standard configuration across the Windows fleet. This role involves engineering and modernizing deployment workflows using Microsoft Intune, SCCM/MECM, and Windows Autopilot, with a focus on repeatability, safety, and scale. The engineer will build reusable PowerShell-based frameworks and supporting tooling for device configuration, drift detection, self-healing remediation, and operational consistency. They will also define and evolve Windows endpoint standards, including OS baseline configuration, security baselines, and lifecycle practices aligned with enterprise requirements. Collaboration with QA and release governance to improve validation practices for patches, feature updates, policy changes, security configuration, and application rollouts is key. The role also includes implementing and expanding CI/CD practices for endpoint engineering content using Git-based workflows and integrating with identity and security platforms like Microsoft Entra ID. The goal is to reduce operational toil, improve reliability, and enhance observability and troubleshooting signals. Collaboration across Workplace Engineering teams is essential to standardize engineering patterns and share automation approaches.

Requirements

  • Strong experience with Windows endpoint engineering in an enterprise environment (OS configuration, policy management, troubleshooting, and lifecycle management).
  • Hands-on experience with Microsoft Intune and SCCM/MECM for application delivery, device management, and endpoint configuration.
  • Experience with Windows Autopilot and modern provisioning patterns.
  • Proficiency in PowerShell for automation, packaging, and remediation workflows.
  • Working knowledge of CI/CD concepts and Git-based workflows (code reviews, branching strategies, reusable templates/modules).
  • Familiarity with Microsoft Entra ID and endpoint identity/compliance patterns.
  • Understanding of enterprise endpoint security concepts (security baselines, hardening, least privilege, patching/updates).
  • Undergraduate degree in a related field or equivalent experience.
  • 3–5+ years of relevant experience in Windows endpoint engineering, automation, or platform engineering roles.
  • Strong analytical, problem-solving, and troubleshooting skills.
  • Strong written and verbal communication skills, with the ability to document standards and enable others.
  • Ability to work across teams, influence standards, and drive automation-first engineering practices.
  • Strong planning, organization, and delivery discipline.

Nice To Haves

  • Experience with Desired State concepts (e.g., Desired State Configuration or similar) is a plus.
  • Familiarity with monitoring/telemetry and operational observability concepts is a plus.
  • Minimum of eight years related work experience.
  • Undergraduate degree in a related field or the equivalent combination of training and experience.

Responsibilities

  • Lead endpoint automation for provisioning, compliance, remediation, and standard configuration across the Windows fleet.
  • Engineer and modernize deployment workflows using Microsoft Intune, SCCM/MECM, and Windows Autopilot, with a focus on repeatability, safety, and scale.
  • Build reusable PowerShell-based frameworks (and supporting tooling) for device configuration, drift detection, self-healing remediation, and operational consistency.
  • Define and evolve Windows endpoint standards including OS baseline configuration, security baselines, and lifecycle practices aligned with enterprise requirements.
  • Partner with QA and release governance to improve validation practices for patches, feature updates, policy changes, security configuration, and application rollouts.
  • Implement and expand CI/CD practices for endpoint engineering content (scripts, configuration, packaging, policy-as-code where applicable), using Git-based workflows, reviews, and promotion patterns.
  • Integrate with identity and security platforms (e.g., Microsoft Entra ID) to support secure provisioning, access, and device compliance patterns.
  • Reduce operational toil and improve reliability by automating routine work, codifying repeatable runbooks, and improving observability and troubleshooting signals.
  • Collaborate across Workplace Engineering (Windows, VDI, macOS/mobility, Digital Workplace) to standardize engineering patterns and share automation approaches.

Benefits

  • Hybrid working model
  • Enhanced flexibility
  • In-person learning, collaboration, and connection
  • Mission-driven and highly collaborative culture
  • Long-term financial wellbeing for clients
  • Product and services that transform clients' lives
  • Opportunities to learn and develop skills as individuals and as a team
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service