ForgeApply · Job listing
Senior Windows Engineer, Endpoint Engineering
Aresmgmt
Tailor your resume for this Aresmgmt job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Aresmgmt's site. Free trial, no card required.
About this role
Over the last 20 years, Ares’ success has been driven by our people and our culture. Today, our team is guided by our core values – Collaborative, Responsible, Entrepreneurial, Self-Aware, Trustworthy – and our purpose to be a catalyst for shared prosperity and a better future. Through our recruitment, career development and employee-focused programming, we are committed to fostering a welcoming and inclusive work environment where high-performance talent of diverse backgrounds, experiences, and perspectives can build careers within this exciting and growing industry.
Job Description The Senior Windows/SCCM/Intune Engineer is responsible for the architecture, engineering, automation, security, and lifecycle management of the firm's global Windows endpoint environment. This role serves as a senior technical leader within End User Engineering, driving enterprise device management strategies across Microsoft Configuration Manager (SCCM/MECM), Microsoft Intune, Microsoft Entra ID, and Windows 11 platforms.
The engineer will design and maintain modern endpoint management solutions, software deployment frameworks, operating system lifecycle processes, compliance enforcement, and endpoint security configurations. This individual will collaborate closely with Information Security, Infrastructure, Service Desk, Unified Communications, and Application teams to deliver a secure, scalable, and highly automated digital workplace experience for employees worldwide.
Reporting relationships Reports to: Senior Manager, Digital Workplace Primary functions & responsibilities 1. Endpoint Engineering & Management • Design, implement, and support enterprise Windows endpoint management solutions. • Manage and optimize Microsoft Configuration Manager (SCCM/MECM) infrastructure. • Lead migration initiatives from traditional SCCM management toward cloud-native management using Microsoft Intune. • Engineer and maintain Microsoft Intune policies for device compliance, configuration, security baselines, endpoint protection, and application deployment. • Develop and maintain device provisioning strategies utilizing: • Windows Autopilot • Microsoft Intune • Hybrid Azure AD Join • Entra ID Join
• Establish endpoint configuration standards across global environments. • Drive hardware refresh and operating system modernization initiatives. • Maintain endpoint inventory, reporting, and lifecycle management processes.
2. Operating System Engineering • Lead Windows 11 deployment, maintenance, and upgrade programs. • Develop and maintain enterprise OS deployment task sequences and Autopilot provisioning packages. • Engineer standardized endpoint configuration profiles and provisioning methodologies. • Manage feature updates, quality updates, and servicing channels. • Perform application compatibility testing and remediation. • Develop rollback and contingency plans for large-scale deployment initiatives.
3. Application Packaging & Deployment • Package, test, deploy, and maintain enterprise software solutions. • Develop deployment methodologies utilizing: • Intune Win32 Applications • SCCM Applications • PowerShell • Winget
• Troubleshoot complex installation and application-related issues. • Create detection methods, superseding strategies, and deployment automation workflows. • Manage application lifecycle processes from onboarding through retirement.
4. Automation & Scripting • Develop automation solutions using: • PowerShell • PowerShell App Deployment Toolkit (PSADT) • Graph API • Azure Automation • Azure Functions
• Automate administrative tasks and operational processes. • Create self-healing and proactive remediation scripts. • Develop reporting, monitoring, and compliance automation solutions. • Reduce operational overhead through infrastructure-as-code methodologies.
5. Endpoint Security & Compliance • Partner with Information Security teams to implement endpoint security controls. • Engineer and maintain: • Intune Patch Management / Autopatch • SCCM/WSUS software updates • Attack Surface Reduction Rules • Device Control Policies • BitLocker Encryption • Security Baselines • Group Policy Management • Conditional Access integrations
• Ensure compliance with regulatory and corporate security requirements. • Evaluate vulnerabilities and coordinate remediation activities. • Support audit readiness and security reviews.
6. Microsoft Cloud Technologies • Support and integrate: • Microsoft Intune • Microsoft Entra ID • Microsoft Defender • Microsoft 365 Apps • Windows Update for Business • Microsoft Graph
• Develop modern management strategies aligned with Microsoft's cloud-first approach. • Manage co-management capabilities between SCCM and Intune. • Optimize device management through cloud-based services and automation.
7. Digital Employee Experience (DEX) • Utilize Digital Experience Monitoring tools such as: • Nexthink • Microsoft Endpoint Analytics • Lakeside SysTrack • ControlUp
• Analyze endpoint health and performance trends. • Develop initiatives to improve: • Device performance • Boot times • Reliability • Application experience • Employee productivity
• Create executive-level reporting and operational dashboards.
8. Documentation & Operational Excellence • Create and maintain: • Technical documentation • Standard operating procedures • Engineering standards • Runbooks • Knowledge articles
• Develop operational dashboards and reporting metrics. • Maintain architecture diagrams and platform documentation. • Drive continuous process improvement initiatives. • Serve as Tier 3/Level 4 escalation support for complex endpoint issues. • Perform root cause analysis for recurring incidents and service disruptions. • Participate in maintenance windows and critical incident response activities. • Establish monitoring and alerting strategies for endpoint services. • Maintain service reliability and performance targets.
Qualifications Education: Bachelor’s degree in Computer Science, Information Systems,
Salary insight
The midpoint of this range ($133k) is about 20% below the median disclosed salary for New York roles listed on ForgeApply ($166k across 6,609 jobs).
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Aresmgmt role before you apply.
Tailor my resume for this jobSimilar jobs
- Senior Security Engineer, Endpoint — Ramp · New York, NY (HQ)
- Staff Software Development Engineer - Windows Endpoint — Beyondtrust · Remote
- Senior Endpoint Security Engineer — Crusoe · San Francisco, CA - US
- Staff Software Engineer, Endpoint Escalations (C++, Windows/OS Internals) — Sentinellabs · Remote
- Information Security Engineer - Endpoint — Palantir · New York, NY
- Information Security Engineer - Endpoint — Palantir · Washington, D.C.
- IT Systems Engineer (Endpoint) — Spacex · Bastrop, TX
- IT Systems Engineer (Endpoint) — Spacex · Hawthorne, CA
More like this: More jobs at Aresmgmt · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)