Position Overview
We are seeking a hands-on Endpoint Engineering Architect to design, engineer, automate, secure, and optimize end-user computing platforms across the enterprise. This is not a strategy-only role. The right candidate is an architect who still builds, scripts, deploys, and troubleshoots.
You will serve as a technical lead within the Endpoint Engineering function, owning endpoint lifecycle processes including imaging, provisioning, patching, configuration, compliance, monitoring, and modernization across Windows, Linux, virtual desktops (AVD), and mobile platforms.
This role is fully remote. Candidates must be available during Eastern Time business hours. Contract-to-permanent arrangements are available.
Key Responsibilities
Endpoint Engineering & Architecture
- Architect, deploy, and support endpoint platforms across Windows, Linux, macOS, thin clients, virtual desktops (AVD), and mobile devices
- Design, maintain, and optimize standardized OS images for multiple device types and deployment scenarios
- Own endpoint lifecycle engineering including imaging, provisioning, patching, configuration, compliance, and monitoring
- Act as a hands-on technical architect—designing solutions and validating implementations through direct engineering involvement
Provisioning, Imaging & Virtual Desktop
- Engineer automated provisioning workflows using tools equivalent to Autopilot, Intune, Tanium Provisioning, Windows 365, Azure Virtual Desktop (AVD), PXE-based imaging, and similar technologies
- Administer and optimize Azure Virtual Desktop environments for scale, performance, security, and user experience
- Improve onboarding speed and reliability through automation-first deployment strategies
Automation, Security & Integration
- Develop automation scripts and workflows using PowerShell, Bash, APIs, or similar tooling
- Integrate endpoint platforms with Azure services, identity platforms (Azure AD / Entra ID), certificate services, and security tooling
- Partner with security teams to enforce compliance baselines, conditional access, hardening standards, and device trust models
Technical Leadership & Collaboration
- Serve as subject matter expert (SME) for endpoint technologies, supporting operations, service desk, and engineering teams
- Contribute to endpoint modernization roadmaps including cloud provisioning and hybrid AD to Azure AD transitions
- Participate in hardware standards, vendor evaluations, and lifecycle planning
- Document architecture designs, engineering standards, and operational procedures
Required Qualifications
- 8–10+ years of experience in endpoint engineering, endpoint architecture, or senior systems engineering roles
- Deep hands-on expertise in Windows OS engineering (imaging, Intune/MDM, GPO, patching, troubleshooting)
- Strong experience managing Linux endpoints (Ubuntu, RHEL, or similar)
- Hands-on experience with MDM/UEM platforms (Intune, Workspace ONE / AirWatch, SOTI, or equivalent)
- Proven experience engineering Azure Virtual Desktop (AVD) environments
- Strong automation skills using PowerShell or equivalent scripting languages
- Solid understanding of endpoint security, identity, networking, DNS, DHCP, VPN clients, and cloud identity platforms
Preferred Qualifications
- Experience with hybrid AD → Azure AD modernization
- Experience with enterprise monitoring, DEX, or self-healing platforms (e.g., Tanium, Nexthink, similar)
- Familiarity with large-scale enterprise hardware lifecycle processes
- Azure certifications (AZ-104, AZ-305, or related) are a plus
What This Role Offers
- Architect-level role with real hands-on engineering ownership
- Salary range of $135K–$160K depending on experience
- Fully remote (EST-aligned schedule required)
- Contract-to-perm option available
- Opportunity to modernize and standardize enterprise endpoint environments at scale