ForgeApply · Job listing
Senior End Point Engineer
HUB International
See all 240 open roles at HUB International →
Tailor your resume for this HUB International job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for HUB International's site. Free trial, no card required.
About this role
Job Description
ABOUT US At HUB International, we are a team of entrepreneurs. We believe in protecting and supporting the aspirations of individuals, families, and businesses. We help our clients evaluate their risks and develop solutions tailored to their needs. We believe in empowering our employees to learn, grow, and make a difference. Our structure enables our teams to maintain their own unique, regional culture while leveraging support and resources from our corporate centers of excellence. HUB is a global insurance and employee benefits broker, providing a boundaryless array of business insurance, employee benefits, risk services, personal insurance, retirement, and private wealth management products and services. With over $5 billion in revenue and almost 20,000 employees in 600 offices throughout North America, HUB has grown substantially, in part due to our industry leading success in mergers and acquisitions
Responsibilities Platform Administration and Fleet Operations • Own the day-to-day operation of NinjaOne across approximately 25,000 Windows endpoints on Lenovo standard hardware, covering HUB's 600-plus locations across the United States and Canada • Maintain NinjaOne agent health, version currency, policy assignments, and organization structure across the full fleet • Manage the application catalog, application lifecycle, and deployment assignments, ensuring each application has exactly one primary owner across NinjaOne and Intune with no overlap • Configure and maintain Autopilot orchestration and provisioning workflows within NinjaOne • Perform quarterly coexistence reviews with EUC, SecOps, and the Tanium platform team to validate agent versions, policy exclusions, Zscaler bypass entries, and catalog ownership • Resolve coexistence issues across the stack including Zscaler SSL bypass, SentinelOne exclusion configuration, Tanium Threat Response exclusions, and Intune Management Extension conflicts
Capability Expansion and Approval Program • Own the technical documentation and capability justification for each of the six pending NinjaOne capability approvals, working with Engineering leadership and Security • Drive capability activation, policy build, and rollout for each approved module once cleared • Build and maintain the application-layer patching program using NinjaOne's 200-plus application patch engine once the Automated Patch Management capability is approved • Maintain a clean, properly structured NinjaOne environment as the hard pre-requisite for production fleet rollout
Scripting, Automation, and Runbooks • Build and maintain a library of NinjaOne automation scripts in PowerShell, covering routine maintenance, provisioning, remediation, and compliance enforcement • Author and maintain monitoring policies and alert configurations that surface actionable signal without false-positive noise, in coordination with the Nexthink team • Collaborate with the DEX team on Amplify remote actions that leverage NinjaOne scripting and remote action capabilities as part of the L1 ticket deflection program • Document all scripts, policies, and runbooks to SOC 2 standard, ensuring every automated action has an associated KB article before scale deployment
Data Lake Integration • Design, build, and maintain the NinjaOne extraction pipeline to HUB's Microsoft Fabric data lake using the NinjaOne REST API v2 with OAuth 2.0 client-credentials (monitoring scope only), cursor-based pagination, and updatedAfter incremental filters • Coordinate on entity resolution, joining NinjaOne records to Nexthink records via hardware serial number, hostname, and logged-on user UPN to build the unified golden device record • Monitor pipeline health, handle API version changes, implement backoff on rate limits, and maintain extraction schema documentation • Maintain monitoring-scope-only credential posture with secrets managed in Azure Key Vault and following SOC 2 credential rotation standards
CMDB and ServiceNow Integration • Own the NinjaOne to ServiceNow CMDB bidirectional sync, ensuring device state, software inventory, and operational changes flow automatically between platforms • Resolve CMDB drift and data quality issues in coordination with the ServiceNow platform team • Maintain IAM compliance on device deletion rights and role-based access controls within the NinjaOne console
Governance, Compliance, and Documentation • Maintain NinjaOne documentation to SOC 2 audit standard including access controls, change records, policy history, and exception tracking • Support quarterly and annual coexistence audits including end-to-end installation walkthroughs, exclusion accuracy verification, and tabletop troubleshooting exercises • Participate in the patching governance RACI contributing EUC endpoint perspective on patch ring design, advancement criteria, and compliance reporting
Requirements • Four or more years of hands-on experience administering NinjaOne or a comparable enterprise RMM platform such as Datto RMM, N-able, or Kaseya at scale • Deep experience with NinjaOne specifically — policy configuration, monitoring and alerting, scripting and automation, application catalog management, and console administration • Strong PowerShell scripting including production automation, error handling, logging, and integration with external APIs • Working knowledge of the Windows endpoint security and management stack with hands-on experience across at least two of the following: Microsoft Intune, SentinelOne, Zscaler, Tanium, or equivalent platform • Experience with REST API integration including OAuth 2.0 client-credentials flows, cursor-based pagination, incremental filters, and webhook handling • Understanding of enterprise patch management principles including ring-based deployment, compliance reporting, and controlled rollback • Ability to operate in an enterprise governance environment including change management, RACI-aligned accountability, and audit-facing documentation
Nice to Have
Salary insight
The midpoint of this range ($143k) is about 11% above the median disclosed salary for Chicago roles listed on ForgeApply ($128k across 2,187 jobs).
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this HUB International role before you apply.
Tailor my resume for this jobSimilar jobs
- End Point Systems Engineer — U.S. Bank · Remote
- Senior Endpoint Security Engineer — Crusoe · San Francisco, CA - US
- Lead Endpoint Engineer — Aloyoga · Beverly Hills, California, United States
- Senior Enterprise Engineer — Branch · Remote
- Senior Infrastructure Endpoint Engineer — Everops · Remote
- Senior Performance Engineer — Ellipsislabs · New York, New York
- Senior Performance Engineer — Crusoe · San Francisco, CA - US
- Senior Performance Engineer — SECU · Operations - Raleigh - Creedmoor Rd
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)