Job Description
Job Summary
We are seeking a skilled and detail-oriented Senior Employee Technology Configuration Engineer to join our End User Computing (EUC) team supporting a highly regulated financial services environment.
This role is responsible for architecting, configuring, and managing enterprise endpoint platforms across physical and virtual environments, including Microsoft Intune, Virtual Desktop Infrastructure (VDI), and specialized kiosk systems. The engineer will ensure secure, scalable, and compliant device management services while driving automation, operational excellence, and continuous platform optimization.
The ideal candidate brings deep expertise in modern endpoint management, virtual desktop technologies, security compliance, automation and thrives in a high-security, audit-intensive environment.
Key Responsibilities
- Design, deploy, and manage enterprise endpoint solutions utilizing Microsoft Intune and Microsoft Endpoint Manager.
- Configure and maintain:
- Device compliance policies
- Configuration profiles
- Security baselines
- Endpoint protection policies
- Manage Windows Autopilot provisioning and device lifecycle processes.
- Administer Azure AD / Entra ID integration for authentication and device management.
- Monitor endpoint health, compliance status, operational performance, and reporting metrics.
- Deploy, maintain, and optimize enterprise applications including:
- Win32 applications
- Microsoft Store applications
- Line-of-Business (LOB) applications
- Configure and manage:
- Conditional Access policies
- Windows Update for Business
- Device and user-based configuration policies
- Troubleshoot software deployment failures and policy application issues.
- Develop deployment standards and configuration baselines to improve platform consistency.
- Support enterprise Virtual Desktop Infrastructure environments, including Azure Virtual Desktop (AVD) & VMware Horizon
- Manage and maintain VDI golden images, including:
- Operating system updates
- Application lifecycle management
- Performance optimization
- Administer and troubleshoot FSLogix profile solutions.
- Investigate and resolve:
- Session performance issues
- Login delays
- Profile corruption
- Application compatibility issues
- Collaborate with infrastructure teams to optimize virtual desktop performance and availability.
- Design, deploy, and support single-app and multi-app kiosk solutions.
- Configure and maintain:
- Assigned Access
- Shell Launcher
- Auto-login configuration
- Endpoint lockdown policies
- Develop and maintain PowerShell automation for endpoint and VDI administration.
- Implement Intune remediation and proactive remediation solutions.
- Automate:
- Device provisioning
- Application deployment
- Policy enforcement
- Compliance monitoring
- Continuously improve operational efficiency through scripting and process optimization.
- Implement enterprise endpoint security controls aligned with corporate and regulatory requirements.
- Administer and support:
- BitLocker encryption
- Microsoft Defender for Endpoint
- Endpoint compliance and security reporting
- Ensure endpoint environments meet audit, risk, and compliance standards.
- Support compliance, risk, and security teams by providing logs, documentation, and audit evidence.
- Maintain secure configuration baselines in accordance with enterprise security policies.
- Provide advanced L2/L3 support for endpoint, kiosk, and VDI-related issues.
- Perform root cause analysis for recurring incidents and service disruptions.
- Participate in change management activities related to endpoint platforms.
- Work closely with Infrastructure, Security, Application, and Service Management teams to resolve complex issues.
- Develop and maintain operational documentation, SOPs, configuration standards, and knowledge articles.
Qualifications
Required Qualifications
- 5+ years of experience in enterprise endpoint management, EUC, VDI, or workplace technology engineering.
- 3+ years of hands-on experience administering Microsoft Intune in large-scale enterprise environments.
- Strong knowledge of:
- Microsoft Intune / Endpoint Manager
- Azure AD / Entra ID
- Windows 10 and Windows 11 administration
- Group Policy (GPO)
- Endpoint security controls
- Experience supporting enterprise VDI platforms such as Azure Virtual Desktop, VMware Horizon, or Citrix.
- Proficiency in PowerShell scripting and automation.
- Strong troubleshooting skills related to endpoint management, device provisioning, VDI performance, and application deployment.
- Experience supporting compliance and audit requirements within regulated environments.
Preferred Qualifications
- Experience with FSLogix profile management and optimization.
- Experience with Microsoft Defender for Endpoint.
- Knowledge of hybrid cloud endpoint management architectures.
- Familiarity with Zero Trust security principles and Conditional Access policies.
- Experience supporting kiosk or shared device environments.
- ITIL certification or practical experience with Incident, Problem, and Change Management processes.
- Relevant Microsoft certifications such as:
- Microsoft Certified: Endpoint Administrator Associate
- Microsoft Certified: Azure Administrator Associate
- Microsoft Certified: Modern Desktop Administrator
Morningstar is an equal opportunity employer.
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
