Auf einen Blick
- Aufgaben: Entwickle und automatisiere die Verwaltung von Endgeräten für ein globales Team.
- Unternehmen: Innovatives Unternehmen mit einer kollaborativen Kultur.
- Vorteile: Wettbewerbsfähiges Gehalt, Gesundheitsleistungen und flexible Arbeitsmöglichkeiten.
- Weitere Informationen: Dynamisches Umfeld mit großartigen Karrieremöglichkeiten.
- Warum dieser Job: Gestalte die Zukunft der Technologie und arbeite an spannenden Projekten.
- Qualifikationen: Erfahrung in der Softwareentwicklung und Teamarbeit erforderlich.
Das prognostizierte Gehalt liegt zwischen 70 - 70 € pro Stunde.
Description
Our client is seeking an Endpoint Management Engineer to design, automate, and operate the enterprise device management platform supporting a global workforce.
This role owns hands‑on engineering and operations across Microsoft Intune and Microsoft Configuration Manager (SCCM/MECM) in a co‑management architecture, with Hybrid Entra ID (Azure AD) joined, Active Directory domain‑bound Windows endpoints and a multi‑platform Intune estate spanning Windows, mac OS, i OS/i Pad OS, and Android — including Android‑based teleconferencing and conference room systems.
Automation is central to this role.
The successful candidate writes production‑quality Power Shell, Bash, and .
NET code, builds Intune remediation and detection scripts, and uses the Microsoft Graph API to manage the estate programmatically rather than solely through the console.
Fluency with modern AI‑assisted engineering tools is expected — including Claude or Co Pilot — to accelerate script development, log analysis, documentation, and reporting.
Equally important is the discipline required in a regulated environment.
You will advance modern management objectives — Zero Trust, Conditional Access, cloud‑first policy delivery, and progressive workload migration from Configuration Manager to Intune — while respecting the reliability requirements of standard corporate devices and the constraints of non‑standard, purpose‑built systems, manufacturing workstations, kiosks, and validated Gx P endpoints.
The role partners closely with Information Security, Identity, Networking, Infrastructure, Site IT, and Site Service Support teams.
Key Responsibilities
- Automation, Scripting, and Development
- Design, write, and maintain production‑quality Power Shell for endpoint provisioning, configuration enforcement, bulk administration, reporting, and incident remediation across the Windows estate.
- Write and maintain shell/Bash scripts for mac OS configuration, compliance validation, and application delivery through Intune mac OS shell scripting.
- Build and manage Intune Remediations (proactive remediations) — paired detection and remediation script logic — to identify and self‑heal configuration drift, failed agents, certificate issues, and compliance gaps without user impact.
- Automate platform operations against the Microsoft Graph API, including device and policy inventory, assignment management, application lifecycle tasks, reporting extracts, and integration with adjacent systems.
- Apply engineering discipline to automation assets: source control, code review, parameterization, error handling, logging, idempotency, and controlled release through test rings.
- Convert recurring manual and Service Desk activities into automated or self‑service capabilities.
- Core Device Management
- Engineer and maintain Intune compliance policies across all platforms, including device health, OS version floors, and custom compliance scripts.
- Build and maintain configuration profiles and settings catalog policies, administrative templates, and custom OMA-URI/configuration profiles for Windows, mac OS, i OS/i Pad OS, and Android.
- Familiar with Windows Update for Business and update rings, feature and quality update deployments, driver and firmware update governance, mac OS and i OS update policies.
- Manage monthly and out‑of‑band patch operations in Configuration Manager through Software Update Groups, automatic deployment rules, and maintenance windows; drive patch compliance to defined service‑level targets and remediate delinquent endpoints.
- Package, test, and deploy applications across platforms — Win32 (. intunewin), MSI/MSIX, Microsoft Store, Microsoft 365 Apps, mac OS PKG/DMG and shell‑script apps, i OS/Android managed apps via volume purchasing — with correct detection rules, dependencies, supersedence, requirement rules, and assignment logic.
- Implement and maintain security baselines and industry benchmarks — Microsoft security baselines for Windows, Edge, and Defender; CIS Benchmarks; DISA STIG‑derived controls — including deviation tracking, exception documentation, and drift detection.
- Administer the Configuration Manager hierarchy: site systems, distribution points, boundary groups, client health, content distribution, task sequences, OS deployment, and hardware/software inventory accuracy.
- Manage non‑standard Windows endpoints — manufacturing and shop‑floor workstations, kiosks, shared and standalone systems — with tailored collections, restricted patch windows, exception handling, and documented deviations.
- Identity, Conditional Access, and Endpoint Security
- Manage device identity across Entra ID and on‑premises Active Directory, including Hybrid Entra ID join, Entra ID join, AD domain‑bound systems, and resolution of stale, duplicate, or mis‑registered device objects.
- Configure and maintain co‑management settings, pilot collections, and the controlled transition of individual workloads (compliance policies, Windows Update, device configuration, client apps, Office Apps) from Configuration Manager to Intune.
- Support Conditional Access in partnership with Identity and
- Information
Security: device‑based and compliance‑based grant controls, filters for devices, app protection policy requirements, and safe rollout using report‑only mode and exclusion groups.
- Understand and support mac OS Platform SSO with Entra ID — Secure Enclave authentication, local account creation and password sync, registration during Automated Device Enrollment — and the Microsoft Enterprise SSO plug‑in for mac OS and i OS/i Pad OS.
- Familiar with Zscaler Client Connector or comparable Zero Trust network access and secure web gateway agents across Windows and mac OS.
- Familiar with endpoint security controls, including Microsoft Defender for Endpoint, Bit Locker and File Vault encryption with key escrow, application control, firewall policy, and Windows LAPS.
- Deploy and maintain certificate profiles (SCEP/PKCS) and Wi‑Fi (including 802.1X) across all supported platforms.
- Endpoint Analytics, KPIs, and Reporting
- Define, publish, and maintain endpoint management KPIs — patch compliance rate and time‑to‑patch, policy and compliance conformance, application deployment success rate, agent and client health.
- Build operational and executive dashboards using Intune reporting, Configuration Manager reporting and SQL, Log Analytics, Microsoft Graph data extracts, and Power BI.
- Use AI‑assisted engineering tools — Claude Code, Cowork, Git Hub Copilot, Microsoft Copilot, and comparable agentic tooling — to accelerate script and policy development, log and error triage, documentation authoring, data analysis, and report generation.
- Compliance, Quality, and Operational Support
- Execute all platform and policy changes through the enterprise change management process, with documented impact assessment, test evidence, approvals, and rollback plans.
- Support Gx P‑regulated endpoints by respecting validated system boundaries, coordinating with appropriate groups on change impact, and maintaining documentation sufficient to withstand internal audit and regulatory inspection.
- Serve as escalation point for complex endpoint incidents from Endpoint Engineering Operations team and regional IT teams; perform root cause analysis and implement permanent corrective actions.
- Maintain accurate technical documentation, standard operating procedures, work instructions, and knowledge base articles.
- Participate in an on‑call or extended‑coverage rotation for critical endpoint incidents and scheduled maintenance activities.
- Additional Skills & Qualifications
- Bachelor's degree in Computer Science, Information Technology, Engineering, or a related field; equivalent professional experience with relevant certifications will be considered.
- Minimum of 3 years of hands‑on experience administering Microsoft Configuration Manager (SCCM/MECM) in an enterprise environment, including application packaging, OS deployment, and software update management.
- Minimum of 3 years of hands‑on experience administering Microsoft Intune, including compliance policies, configuration profiles, security baselines, and application deployment.
- Demonstrated proficiency writing and maintaining Power Shell for endpoint automation, remediation, and reporting — beyond running scripts written by others.
- Practical experience with the Microsoft Graph API for endpoint management automation or reporting.
- Working knowledge of Intune and Configuration Manager co‑management, workload transition, Hybrid Entra ID join, and Active Directory domain‑bound Windows endpoints.
- Hands‑on experience managing at least two non‑Windows platforms in Intune (mac OS, i OS/i Pad OS, or Android), including scripting or shell‑based configuration on mac OS.
- Working knowledge of Entra ID, Conditional Access, Group Policy, Active Directory, DNS/DHCP, PKI and certificate services, and Windows client architecture.
- Experience deploying and troubleshooting endpoint security and network access agents (for example, Zscaler Client Connector, Crowd Strike).
- Experience using endpoint reporting and analytics to measure and improve device health, compliance, or user experience (for example Intune report dashboards, Nexthink).
- Working familiarity with AI‑assisted development and productivity tools, and sound judgment about their appropriate use with enterprise data.
- Experience operating within formal change management, incident management, and documentation standards.
- Strong analytical and troubleshooting skills spanning identity, network, policy, and ap
Experience Level
- Expert Level
- Job Type & Location
This is a Contract position based out of North Chicago, IL.
Pay and Benefits
The pay range for this position is $65.00 - $70.00/hr.
Individual compensation offered for this position within this range will depend on many factors, including qualifications, skills, relevant experience, job knowledge, geographic location, internal equity, and other pertinent job‑related factors.
Eligibility requirements apply to some benefits and may depend on your jobclassification and length of employment.
Benefits are subject to change and may besubject to specific elections, plan, or program terms.
If eligible, the benefitsavailable for this temporary role may include the following: Medical, dental & vision Critical Illness, Accident, and Hospital 401(k) Retirement Plan – Pre‑tax and Roth post‑tax contributions available Life Insurance (Voluntary Life & AD&D for the employee and dependents) Short and long‑term disability Health Spending Account (HSA) Transportation benefits Employee Assistance Program Time Off/Leave (PTO, Vacation or Sick Leave)
Workplace Type
This is a hybrid position in North Chicago, IL.
Application Deadline
This position is anticipated to close on Sep 1, 2026.
About TEKsystems
We're partners in transformation.
We help clients activate ideas and solutions to take advantage of a new world of opportunity.
We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia.
As an industry leader in Full‑Stack Technology Services, Talent Services, and real‑world application, we work with progressive leaders to drive change.
That's the power of true partnership.
TEKsystems is an Allegis Group company.
The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
About TEKsystems and TEKsystems Global Services
We’re a leading provider of business and technology services.
We accelerate business transformation for our customers.
Our expertise in strategy, design, execution and operations unlocks business value through a range of solutions.
We’re a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia, who partner with us for our scale, full‑stack capabilities and speed.
We’re strategic thinkers, hands‑on collaborators, helping customers capitalize on change and master the momentum of technology.
We’re building tomorrow by delivering business outcomes and making positive impacts in our global communities.
TEKsystems and TEKsystems Global Services are Allegis Group companies.
Learn more at TEKsystems. com.
The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
San Francisco Fair Chance Ordinance
Pursuant to the San Francisco Fair Chance Ordinance, for all positions located in the city and county of San Francisco, we will consider for employment qualified applicants with arrest and conviction records.
Massachusetts Lie Detector
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment.
An employer who violates this law shall be subject to criminal penalties and civil liability.
Use of Artificial Intelligence (AI)
We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates.
AI helps assess applications and qualifications, but final decisions are made by our hiring team.
By applying, you acknowledge and agree that your application may be reviewed using AI tools.
#J-18808-Ljbffr
End Point Management Engineer Arbeitgeber: TEKsystems
Als SharePoint Technical Product Support Specialist in Saint Paul, MN, profitieren Sie von einer dynamischen Arbeitsumgebung, die auf Zusammenarbeit und Innovation ausgerichtet ist. Das Unternehmen bietet umfassende Vorteile wie medizinische Versorgung, 401(k)-Rentenplan und flexible Arbeitszeiten, während es gleichzeitig Möglichkeiten zur beruflichen Weiterentwicklung und Schulung in modernen Technologien fördert. Hier haben Sie die Chance, in einem unterstützenden Team zu arbeiten, das Vielfalt schätzt und sich für eine inklusive Unternehmenskultur einsetzt.
StudySmarter Expertenrat🤫
Wir sind der Meinung, dass du so End Point Management Engineer erhalten könntest
✨Netzwerken in der IT-Community
In der IT-Consulting-Welt sollten wir regelmäßig auf Veranstaltungen wie Tech-Meetups oder Konferenzen gehen. Hier können wir nicht nur unser Netzwerk erweitern, sondern auch direkt mit potenziellen Arbeitgebern ins Gespräch kommen und unser Interesse an einer Vollzeitstelle zeigen.
✨Online-Foren und Gruppen nutzen
Sich in Online-Foren und Communities wie Stack Overflow oder LinkedIn-Gruppen umzusehen, kann uns helfen, Insider-Tipps zu erhalten und Informationen über offene Stellen in der IT-Beratung zu sammeln. Vergiss nicht, aktiv zu werden und Fragen zu stellen oder dein Wissen zu teilen – das erhöht unsere Sichtbarkeit!
✨Direkt bei TEKsystems bewerben
Viele Unternehmen, wie TEKsystems, stemmen ihre Vollzeitstellen bevorzugt über ihre eigenen Karriere-Webseiten. Also, lass uns regelmäßig auf deren Seite vorbeischauen und uns direkt bewerben, statt nur die üblichen Jobportale zu nutzen.
✨Überzeugende Projekte zeigen
Wir sollten unser Portfolio oder relevante Projekte gut sichtbar machen, egal ob das auf Github, persönlich oder auf LinkedIn ist. Bei IT-Consulting-Stellen kommt es oft auf praktische Erfahrungen an, also lass uns zeigen, was wir können!
Wir glauben, dass du diese Fähigkeiten brauchst, um End Point Management Engineer mit Bravour zu bestehen
Einige Tipps für deine Bewerbung 🫡
Zeige deine technischen Skills!:In der IT-Beratung zählen deine technischen Kenntnisse und Fähigkeiten. Achte darauf, relevante Programmiersprachen, Tools und Systeme in deinem Lebenslauf aufzulisten. Zeig auch, wenn du Zertifikate hast, die deine Kompetenz unterstützen – das könnte dir einen echten Vorteil verschaffen!
Verstehe die Branche!:Unterstreiche in deinem Anschreiben, dass du ein gutes Verständnis für aktuelle Trends und Herausforderungen in der IT-Branche hast. Zeig, dass du nicht nur die technischen Aspekte beherrschst, sondern auch die Bedürfnisse der Kunden erkennen und lösen kannst!
Deine Projekte zählen!:Falls du bereits an IT-Projekten gearbeitet hast, verlinke diese oder beschreibe sie in deinem Lebenslauf. Praktische Erfahrungen – sei es in Form von Praktika oder privaten Projekten – sind besonders wertvoll in der IT-Beratung. Zeige uns, was du kannst!
Individuelle Bewerbung ist der Schlüssel!:Jede Bewerbung sollte individuell auf TEKsystems und die ausgeschriebene Position End Point Management Engineer zugeschnitten sein. Teile uns mit, warum gerade du eine gute Wahl für unser Team bist. Das zeigt dein Engagement und deine Motivation, die über eine Standardbewerbung hinausgeht.
Wie man sich auf ein Vorstellungsgespräch bei TEKsystems vorbereitet
✨Technische Vorbereitung ist alles!
Da du dich auf eine Vollzeitstelle in der IT-Beratung bewirbst, solltest du dir wirklich einen Überblick über die wichtigsten Tools und Technologien verschaffen, die in der Branche verwendet werden. Sei bereit, technische Fragen zu beantworten, die sich auf Software-Architektur oder Systemintegration beziehen könnten.
✨Praxisbeispiele parat haben
In der IT-Beratung ist es wichtig, konkrete Beispiele aus deiner bisherigen Erfahrung zu bringen. Überlege dir Projekte, bei denen du erfolgreich einen Kunden beraten hast oder Herausforderungen gelöst hast. Das zeigt, dass du nicht nur theoretisches Wissen hast, sondern auch in der Praxis erfolgreich sein kannst.
✨Soft Skills betonen
Ein großer Teil der IT-Beratung ist die Kommunikation mit Kunden und das Verständnis ihrer Bedürfnisse. Bereite dich darauf vor, über deine zwischenmenschlichen Fähigkeiten zu sprechen, wie du mit herausfordernden Kunden umgehst oder wie du in Teams arbeitest. Das wird den Interviewern zeigen, dass du mehr als nur technisches Wissen mitbringst!
✨Fragen zum Unternehmen vorbereiten
Schau dir spezifisch die Projekte von TEKsystems an und überlege dir, welche Fragen du dazu stellen möchtest. Zeig Interesse an den aktuellen Herausforderungen, vor denen das Unternehmen steht, und wie du dazu beitragen könntest. Das hebt dich von anderen Bewerbern ab und zeigt, dass du wirklich motiviert bist.